Configure PCS certificates after installation
- Last UpdatedNov 13, 2025
- 2 minute read
- PI System
- PI Server 2024 R2
- PI Server
You can also configure Platform Common Services (PCS) certificates for TLS communications after installation using the OIDC Configuration tool. PCS certificates apply to all PI System components selected at installation, and handle automatic certificate rotation for these components and services.
Prerequisites:
Complete the following task before configuring PCS certificates:
-
Install and configure AVEVA PCS 8.2.1 for the PI System. See Install and configure the AVEVA™ Identity Manager.
-
Install PI Server services on nodes separate from the System Management Server (SMS) machine.
Configure automatic PCS certificate renewal after installation
Follow these steps to configure automatic certificate renewal for all PI Server components after installation:
-
To ensure that certificates are received and applied from SMS, install and configure PCS on all PI Server nodes to enable connections to the SMS machine. In this setup, PI Server nodes act as SMS client nodes. See Connect a machine to a System Management Server.
-
Run the following command from the %PIServer%adm folder (for node with Data Archive installed) or from the %pihome% folder (for node with only AF Server or any of its services installed), omitting any of the services flags that do not exist on that node:
Aveva.PI.OIDCConfigurationTool.exe /CERTIFICATETHUMBPRINT:Platform /AFSERVER /PIDATAARCHIVE /PINOTIFICATIONS /PIANALYTICS
Enables AF Server, Data Archive, PI Notifications Service, and PI Analysis Service to use the same PCS certificate on the node.
-
Restart all PI System services for this change to take effect.
-
When certificates are rotated by PCS, AF Server, PI Notifications Service, and PI Analysis Service will need to be restarted in order for the new certificate to take effect.
Important: Configuring PCS certificates for PI Server services is required for automatic certificate renewal. If PCS is not configured, you will need to follow the custom certificate renewal process.