Connection Security Tab (for Server-to-Server Communications)

The Partners section of the Server Configuration Tool includes a Connection Security tab. Use the Connection Security tab to specify the security settings that apply to outgoing server-to-server connections. The settings on the tab apply when the Geo SCADA Expert server on which you are configuring the settings acts as a client that is connecting to another Geo SCADA Expert server. The other server with which this server communicates is known as the 'partner' server.

The Connection Security tab is only available for use on multi-server Geo SCADA Expert systems (whereby the server is set to a Type other than Lone Server (see Set the Type of Server)).

Use the Connection Security tab to configure these settings for the local server:

WARNING

inability to synchronize databases and take over as main

With Geo SCADA Expert 2020 onwards, take care to ensure that Main and Standby servers all have compatible Connection Security configuration and valid certificates. We recommend that you renew certificates well in advance of their expiry dates. If the Main server is unable to connect to a Standby server due to differences in TLS (Transport Layer Security) configuration, then the Standby server will appear to attempt to synchronize endlessly with the Main server. Should a changeover occur in this situation, the Standby server will not be able to become Main. This is because it will have an invalid database due to the synchronization not having completed.
Failure to follow these instructions can result in death, serious injury, or equipment damage. If a changeover occurs with no Standby available to take over as Main, the system will be offline until a server with a valid database is brought back online.

If a Standby server is unable to connect to the Main server due to a TLS configuration conflict, the Server Icon on the Standby server will go magenta to indicate that an issue has been detected. The Server icon's context-sensitive menu will indicate that there is Invalid Standby Configuration and the dialog box will provide further information about the issue (see The Server Icon). If this is due to a TLS configuration conflict, you should check both sets of Connection Security settings on both servers and ensure that there are no issues with the certificates that either server is using. For example, a conflict will occur if the Standby server is configured to validate partner certificates, but is not able to do so because the Main server is using a temporary certificate. Do not perform any manual changeovers until the TLS configuration conflict has been resolved.

If the Main server goes offline before the Standby server has been able to complete the synchronization process, that Standby server will not be able to take over as Main. If no other Standby servers exist or have fully synchronized databases and a changeover occurs, this could result in the system going offline. To bring the system back online, restart the server that was Main. If that is not possible, contact Schneider Electric for assistance. You might be advised to restore the database on one of the servers that has an invalid database, using the most up-to-date backup in order to minimize data loss. Following this, ensure that all of the servers have compatible Connection Security configuration to enable successful synchronization to occur, and that any other issues that might be preventing synchronization have been resolved (see Check that Standby Servers are Synchronized with the Main Server).

Further Information

Configure the Connection Security settings for when this server communicates with client machines: see Configure the Connection Security Settings.

Configure the Connection Security settings on client machines: see Configure the Client Connection Security Settings in the Geo SCADA Expert Guide to Client Administration.


Disclaimer

Geo SCADA Expert 2020