Configure security for the controller
Use the settings on the
Security
tab of the Controller Properties
dialog box to configure security, trusted slots, and change detection for the controller. The settings on the
Security
tab are unavailable when:- The user does not have security permissions to edit the controller settings.
- The controller is operating inHard Runmode.TIP:OnlyFactoryTalk Services Platform2.50 or later supports associating a project with a specific security authority. TheFactoryTalk Securitysettings are configured in theFactoryTalk Administration Consolein theFactoryTalkNetwork Directory. This setting is enabled when permission is set toAllowfor Product Policy.Logix Designer\Controller: Secure
- In theController Organizer, right-click the controller name and selectPropertiesto open theController Propertiesdialog box.
- Click theSecuritytab.
- In theSecurity Authoritybox, select.FactoryTalk Security
- To associate this project with a specific Security Authority, select theUse only the selected Security Authority for Authentication and Authorizationcheck box. When this check box is selected, users interacting with this project must be authenticated and authorized by either the primary or the secondary Security Authority.IMPORTANT:Before associating this project with a specific Security Authority,Rockwell Automationrecommends backing up theFactoryTalk Directoryand save unsecured versions of this project file in (. ACD) or (.L5X or .L5K) formats. For details about backing up aFactoryTalk Directory, seeFactoryTalkHelp:Start > Programs > Rockwell Software >.FactoryTalkTools >FactoryTalkHelp
TIP:The secondary Security Authority can only further deny permissions that are allowed by the cached Guest User permissions. The secondary Security Authority cannot grant permissions that are denied by the cached Guest User permissions.Select aSecure Withoption:- To associate the project with a Logical Name inFactoryTalk Services Platform, selectLogical Name<Controller Name>. If there is no existing Logical Name that matches the controller name, theLogix Designercreates a new Logical Name with the controller's name and it inherits permissions from its parent resource.
- To associate the project with a Permission Set configured inFactoryTalk Services Platform, selectPermission Setand select a permission set from the list.
- Select theRestrict Communications Except Through Selected Slotscheck box to require communication through trusted slots. Only the slots selected underSelect Slotsare trusted communication paths for communication fromLogix Designer,RSLinx Classic, andFactoryTalk Linx.
- UnderSelect Slots, click slot numbers in the grid to trust them for use with this controller.TIP:Trusted slots are only available onControlLogix5570 and 5580 controllers.
For more information about communication paths and trusted slots, see
Failed to go online with the controller > Communications path not trusted by the controller
. Failed to go online with the controller > Communications path not trusted by the controller
- To open theConfigure Changes to Detectdialog box, clickConfigureand then select the check box for the events in the list that you want to monitor. Change detection is unavailable on theStudio 5000 Logix EmulateController.
- ClickOK.
Provide Feedback