Glossary · OT cybersecurity
PKI in OT
Also known as: OT PKI, Industrial PKI
German: PKI (Public-Key-Infrastruktur) in der OT
In OT cybersecurity, PKI in OT is the use of a public key infrastructure to issue, distribute, renew and revoke certificates for industrial devices, controllers, servers and engineering tools, adapted to long device lifecycles, limited connectivity and the need for uninterrupted operation.
- OT security
In one sentence
PKI in OT manages certificates for controllers, devices and servers, adapted to long lifecycles, limited connectivity and continuous operation.
Example
A plant's OT PKI issues device certificates to OPC UA servers on the lines, renews them automatically before expiry and keeps an offline root CA in a safe.
How it applies
- Engineering: Certificates are used for OPC UA, secure industrial Ethernet variants, HTTPS on device web servers, VPNs for remote access and signed firmware. The design decides who operates the CA (operator, integrator, vendor), which trust lists devices hold and how devices without internet access get certificates.
- Operation: Expiring certificates can stop communication in the middle of production. Monitoring expiry dates and automating renewal, where devices support standardized enrollment protocols, prevents outages.
- Maintenance: When a device is replaced, its certificate must be revoked and a new one issued. Devices returned for repair should have their private keys removed or invalidated.
- Documentation: Product documentation should describe certificate handling step by step: generating keys, installing certificates and trust lists, renewal, and the device's behavior on expiry or revocation. Commissioning checklists should include certificate setup.
PKI in OT vs. enterprise PKI
An enterprise PKI serves users and IT servers with frequent connectivity. OT PKI must cope with devices that run for decades, stay offline and cannot be restarted at will, so certificate lifetimes and renewal processes differ.