Creating the "OEM Certificate Request File"

Creating the "OEM Certificate Request File" 1:

TwinCAT OEM certificates are only issued for existing Beckhoff customers.

Please get in touch with your Beckhoff sales contact for further information.

Creating the "OEM Certificate Request File" 2:

System requirements

- Min. TwinCAT 3.1 Build 4024
- Min. Windows 10 or TwinCAT/BSD (on the target system)

Creating the "OEM Certificate Request File" 3:

Do not use special characters (ä, é, ...) for company name and password!

The algorithm for processing the OEM certificate in TwinCAT cannot process special characters.

Order numbers for TwinCAT OEM certificates

TC0007: TwinCAT OEM Certificate Standard (TwinCAT Software Protection)

TC0008: TwinCAT OEM Certificate Extended Validation (like TC0007, additionally signing of TwinCAT driver software created with TwinCAT 3 in C++)

The Software protection configurator has been opened.
1. Select the Certificates tab.
2. Click Create New….
Creating the "OEM Certificate Request File" 4:
The Create OEM Certificate input window opens.
Creating the "OEM Certificate Request File" 5:
3. Enter the required data for an "OEM Certificate Request File":
Creating the "OEM Certificate Request File" 6:

Do not use special characters (ä, é, ...) for company name and password!

The algorithm for processing the OEM certificate in TwinCAT cannot process special characters.

Creating the "OEM Certificate Request File" 9:

Only valid for TwinCAT 3.1 Build 4024.0: creation of a User DB requires Crypto Version 1

In the TwinCAT version Build 4024.0, a user database for the TwinCAT Software Protection may only be created with an OEM certificate with Crypto version 1!

1. Once you have entered the data, click Start and select a directory to save the file. Important: You can simply accept the suggested directory "c:\twincat\3.1\customconfig\certificates". You need the newly created file in this directory in order to be able to read out the file fingerprint for this file in a subsequent step.
A dialog for selecting a password for the OEM Private Key opens.
2. Issue a password for the OEM Private Key.
Creating the "OEM Certificate Request File" 11:

Do not use special characters (ä, é, ...) for company name and password!

The algorithm for processing the OEM certificate in TwinCAT cannot process special characters.

Creating the "OEM Certificate Request File" 12:

Important: Password security!

Be sure to use a strong password for your OEM certificate!
Protect your password with appropriate measures so that it cannot fall into the wrong hands!

Creating the "OEM Certificate Request File" 13:

Password cannot be restored if lost

Beckhoff is unable to recover or reset your password. If you forget or lose the password for your OEM certificate, you can no longer use it and have to request a new OEM certificate.

1. Confirm the password by entering it again and close the dialog with OK.
Creating the "OEM Certificate Request File" 14:
The file is saved.

The "OEM Certificate Request File" generated in this way must now be signed by the Beckhoff certificate section in order to be valid. The procedure is described in chapter "Requesting an OEM certificate".