CONNECT URL and certificate requirements
- Last UpdatedJan 30, 2026
- 2 minute read
This document details the requirements for connecting to CONNECT, including allowed URLs, domain rules, and certificate validation.
Domain rules
CONNECT enforces strict domain validation. CONNECT supports both wildcard and explicit domain configurations. Additional CONNECT applications may use subdomains under *.connect.aveva.com. Wildcard domain configuration is recommended to ensure easier configuration and more flexible coverage. Explicit domains offer more granular control.
-
Wildcard domains (recommended): If a domain is listed with a wildcard (like *.connect.aveva.com), all subdomains are permitted.
-
Explicit domains: Only listed domains are permitted; wildcards are not allowed unless explicitly stated.
-
Domain matching: All connections must match the listed domains exactly or conform to the specified wildcard pattern.
Allowed URLs
If your organization uses a proxy server or firewall configured with least-privileged access, specific domains must be allowed to enable successful authentication and access to CONNECT services.
does not provide IP addresses for allow listing. Instead, we recommend using DNS-based firewall rules to manage domain-level access. This approach ensures flexibility and compatibility with certificate validation and dynamic service endpoints.
The following URLs must be accessible for CONNECT and its features to function correctly.
|
Category |
URL/Endpoint |
|---|---|
|
Global endpoint |
|
|
Product: Insight |
|
|
Feature: Insight browsing |
|
|
Feature: Insight publishing |
|
Certificate requirements
CONNECT services rely on certificates issued by trusted authorities to secure communications. Your network must allow access to certificate validation endpoints to avoid authentication failures or service disruptions.
Each domain within CONNECT may use certificates from different issuers. Below is a breakdown of certificate usage and the corresponding validation URLs.
|
Issuer |
Used by |
Validation URLs |
|---|---|---|
|
Let's Encrypt (Authority X3) |
|
|
|
Amazon |
|
|
|
DigiCert (SHA2 secure server CA) |
|
|