Certificate Folders

This screen area is only ready for input if you have chosen client certificate authentication.

You make the settings here for how the client certificate is to be validated. During runtime, the client sends the certificate to the PCo server. PCo checks the submitted certificate against the settings that you have made here.

Settings for Certificate Folders

Field

Description

Store Type

Here you select the store for the certificate that you want to be validated. The following types are supported:

  • Microsoft certificate store

    When a connection is being established, with this setting, PCo automatically searches in the Microsoft certificate store folder for a server certificate.

  • File system certificate store

    With this option, you can specify the store location for the certificates, which PCo is to trust, in the file system.

Trusted Certificates

Here you can specify the folder in which the trusted certificates are stored.

If you have selected the Microsoft certificate store, this is the folder for the trusted root certification authorities. The system proposes this automatically.

Issuer Certificates

Here you can specify the folder in which the certificates of a trusted issuer are stored.

If you selected the Microsoft certificate store, this is the folder for the intermediate certificate authorities. This is proposed automatically.

If you have selected the file system certificate store, a directory is proposed in the file system with the subfolder certs. This folder is used to complete the certificate chain if the server does not send the complete certificate chain.

Rejected Certificates

Here you can specify the folder in which the rejected certificates are stored.

If you are using the Microsoft certificate store, select Untrusted Certificates here.

If you have selected the file system certificate store, use a directory in the file system with the subfolder certs (folder for rejected certificates).

Revocation Check

In this field you define how the revocation check of the server certificate is to be performed. You have the following options:

  • No Check on Revoked Certificates

    No check is carried out.

  • Check Online Revocation Lists

    The online check is a secure procedure but it can have a negative impact on performance.
  • Check Offline Revocation Lists

    • If you are using the Microsoft certificate store, you need to copy all the relevant certificate revocation lists into the Trusted Root Certification Authorities directory.

    • If you have selected the file system certificate store, you need to copy all related certificate revocation lists as .crl files into the revocation list folder.