OSIsoft: Upgrade an Interface Node to PI API 2016 for Windows Integrated Security [v2.0.1.35]

Опубликовано: 06 Октябрь 2024
на канале: AVEVA PI System Learning
4,423
22

Learn how to increase the security of your PI System by upgrading a simple interface node to use PI API 2016 for Windows Integrated Security (WIS) [2.0.1.35] while also implementing minimum permissions for your interface and buffer.

[00:15] Will be upgrading existing interface node to use PI API 2016 for Windows Integrated Security.
[00:42] DISCUSS EXISTING INTERFACE NODE
[00:52] Two interfaces running on interface node PIINT01, sending data to PISRV01
[01:16] Verify health of PI Buffer Subsystem, version of PI API before upgrade
[02:18] Confirm interfaces, buffer, and ICU are authenticating to PI Data Archive using PI trusts before upgrade, confirm data flow
[03:18] DISCUSS DESIRED ENDING SETUP AND STEPS
[03:39] To use mappings with PI API requires upgrading to PI API 2016 for WIS
[03:46] Will also setup mapping for PI Buffer Subsystem, which is an SDK application, since this is a best practice. Note: this does not require PI API 2016 for WIS to implement mappings for SDK connections.
[03:50] Will setup minimum permissions for interfaces and buffering
[04:08] Steps to implement interface minimum permissions and install PI API 2016 for WIS
[05:02] STEP 1: IDENTIFY AND CREATE REQUIRED IDENTITIES
[05:18] Interface with no buffering but no output points: interface and buffer have different required permissions on the PI Data Archive
[05:38] Create PI Interfaces and PI Buffers Identities
[06:03] Disable PI World as best practice if no users are currently using PI World to receive their permissions
[06:28] STEP 2: PROVIDE IDENTITIES WITH MINIMUM PERMISSIONS
[06:37] Interface identity requires read permission on the PIPOINT Table
[07:01] Interface identity requires read access on Point Security
[07:40] Buffering identity require write access on Data Security
[08:17] Change security settings on other tags using PI Builder in Excel
[10:09] STEP 3: MAP IDENTITIES TO SERVICE ACCOUNTS
[10:42] Map windows service accounts to PI Data Archive Identities
[11:24] Create mapping for student01
[11:53] STEP 4: CHANGE INTERFACE AND BUFFER TO RUN AS SERVICE ACCOUNTS
[12:09] Before changing an interface service account, refer to interface-specific documentation
[13:16] Before changing PI Buffer Subsystem service account, refer to Buffering User Guide since additional security changes are required
[14:20] STEP 5: INSTALL PI API for WINDOWS INTEGRATED SECURITY 2.0.1.35 on PIINT01
[14:32] Execute install kit as Administrator
[14:47] Acknowledge that you understand this kit will disable the use of trusts for ALL PI API connections authenticating from this node
[15:45] Disable open trusts from PIINT01
[16:02] STEP 6: VERIFY INTERFACES AND BUFFER CONNECTIONS AND DATAFLOW
[16:13] Verify health of PI Buffer Subsystem on PIINT01
[16:32] Confirm interfaces and buffer authenticated using mappings after installation, if PI Buffer Subsystem (SDK connection) had authenticated using the PIINT01 Trust before deleting the open trust, the buffer and interfaces would need to be restarted again at this time
[17:12] Confirm dataflow
[17:31] After configuring ALL connections to the PI Data Archive to use WIS, you can consider raising the security slider to the highest level. This will also disable the loopback trust, and PI Interfaces and custom API applications local to the PI Data Archive will require PI API 2016 for WIS to be installed locally on the PI Data Archive.

This video was created using the Cloud Environment of UC 2017 Hands-on Lab: Locking Your PI System Without Locking Down Your PI System. To learn more about OSIsoft Cloud Environments and try upgrading an interface node to PI API 2016 for WIS for yourself, visit https://learning.osisoft.com/Course/S...

Additional resources:
AL00309 - Windows Integrated Security (WIS) replaces PI trusts and explicit logins in PI API 2016
https://techsupport.osisoft.com/Troub...

KB01583 - Why OSIsoft developed the PI API 2016 and PI SDK 2016 updates
https://techsupport.osisoft.com/Troub...

KB00833 - Seven best practices for securing your PI Server
https://techsupport.osisoft.com/Troub...

PI Data Archive Security Configuration Guide
https://techsupport.osisoft.com/Downl...

Buffering User Guide
https://techsupport.osisoft.com/Downl...

Video content is copyright of OSIsoft, LLC © 2017. All rights reserved. Any redistribution or reproduction of part or all of the contents in any form is prohibited other than for your personal and non-commercial use.