Please ensure Javascript is enabled for purposes of website accessibility
Powered by Zoomin Software. For more details please contactZoomin

AVEVA™ Plant SCADA

Encrypted Communications

  • Last UpdatedJul 02, 2026
  • 2 minute read

Communications between Plant SCADA processes, computers and CtAPI can be encrypted. To use encryption, a System Management Server is required to manage the certificates that enable trusted communications.

The components required to enable encryption are included with every installation of Plant SCADA.

Only one of the computers in a Plant SCADA system needs to be configured as the System Management Server. You use Configurator to configure the computer that will perform this role (see Configure a System Management Server).

The certificates required to establish trust can be generated automatically on the System Management Server or provided by your IT department.

Computers running AVEVA products can then use a certificate to connect to the System Management Server across an encrypted connection (see Connect a Computer to a System Management Server).

Embedded Image (65% Scaling) (LIVE)

Encryption is a requirement for some Plant SCADA components, such as a Deployment Server, an Industrial Graphics Server or an OPC UA Server. To enable encryption, you need to set Runtime Manager to run as a service on any computers that host a server process. See Enable Encryption.

In a typical Plant SCADA system that is also using deployment, it is recommended that the System Management Server is configured on the same computer as the Deployment Server.

A System Management Server can also be installed in a large, multi-site environment running multiple AVEVA products. In such systems, the location of the System Management Server may be governed by one or more products. However, all AVEVA products should be able to connect to the System Management Server at all times so that certificates can be renewed when it is required.

Note: Plant SCADA runtime will use the most secure version of the Transport Layer Security (TLS) protocol that is available, based on the Windows version running on client and server computers. This is currently TLS 1.2 and 1.3. In the event support for a new version of TLS is added to Windows, Plant SCADA will automatically start using that version with no update of Plant SCADA required. Similarly, if a current version of TLS is deprecated by Windows, Plant SCADA will automatically stop using that version. CtAPI applications need to be built in a specific way to facilitate this behavior. For more information, see Enable Automatic Updates of TLS Versions for CtAPI Applications.

See Also

Use Externally Provided Certificates for Encryption

Use SMS Certificates with Web Applications

Troubleshooting - Certificate Error Messages