Please ensure Javascript is enabled for purposes of website accessibility
Powered by Zoomin Software. For more details please contactZoomin

PI System Connector 3

Configure the communication certificate

  • Last UpdatedMay 20, 2026
  • 3 minute read

To send data securely to a broker, configure a communication certificate on the connector and the broker. The certificate authenticates both components and encrypts data in transit.

Before you begin, the connector must be configured with a valid communication certificate to establish a secure, trusted connection between both components. AVEVA PI System Connector 3 (PSC3) uses these certificates to authenticate the connector and broker, encrypt data in transit, and ensure that each system trusts the other’s identity.

Preparing this certificate involves generating or selecting an appropriate certificate, verifying the required key usage extensions, and installing the certificate in the correct trust stores on both machines.

Configure a connector to broker certificate

Complete the following steps to configure a connector to broker communication certificate:

  1. After selecting Configure communication certificate in the Destination: Broker page, the Certificate Configuration window displays.

  2. Select Create to generate a self signed certificate or Change Certificate to select an existing self made certificate.

    Note: Generated certificates can be found in the Trusted Root Certification Authorities Store.

  3. After selecting or creating the certificate, close the window to return to the Destination: Broker page.

  4. After identifying a host name for the Broker and providing a valid port number, select Apply Changes.

  5. Export or install the certificate from a connector machine into the Trusted Root Certificate Authorities Store of the broker.

  6. Move to the Broker and open the General page.

  7. Select Configure Communication Certificate.

  8. Select Create to generate a self signed certificate or Change Certificate to select an existing self made certificate.

  9. After selecting or creating the certificate, close the window to return to the Broker: General window and select Apply Changes.

    If the connector is supplying data to the node, export or install the certificate from the broker into the Trusted Root Certificate Authorities Store of the connector.

Broker to Broker

If the broker is supplying the data, transfer and install the certificate to the opposite broker using the following instructions:

  1. In the destination Broker machine that requires the certificate, open the General page.

  2. Select Configure Communication Certificate.

  3. Select Create to generate a self signed certificate or Change Certificate to select an existing self made certificate.

  4. After selecting or creating the certificate, close the window to return to the Broker: General window and select Apply Changes.

    • If the connector is supplying data to the node, export or install the certificate from the broker into the Trusted Root Certificate Authorities Store of the connector.

    • If the broker is supplying the data, transfer and install the certificate to the opposite broker.

  5. In the source Broker machine where the certificate resides, open the Destination page and select Broker.

  6. Select Configure Communication Certificate on the Destination page.

  7. Select Create to generate a self signed certificate or Change Certificate to modify an existing self made certificate.

    You can use the same certificate generated in Step 3.

  8. After selecting or creating certificate, close window and select Apply Changes.

  9. Export or install the certificate from the source machine into the Trusted Root Certificate Authorities Store of the destination machine.

    In This Topic