{"id":1256,"date":"2022-12-07T12:08:58","date_gmt":"2022-12-07T10:08:58","guid":{"rendered":"https:\/\/www.rocworks.at\/wordpress\/?p=1256"},"modified":"2022-12-07T12:15:09","modified_gmt":"2022-12-07T10:15:09","slug":"wincc-unified-v18-exposed-to-the-internet","status":"publish","type":"post","link":"https:\/\/www.rocworks.at\/wordpress\/?p=1256","title":{"rendered":"WinCC Unified V18 exposed to the Internet&#8230;"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This article will show how <strong>WinCC Unified<\/strong> can be accessed through a public available server in the internet. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Disclaimer: I only did this for testing and demo purposes!!!<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"513\" src=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8-1024x513.png\" alt=\"\" class=\"wp-image-1274\" srcset=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8-1024x513.png 1024w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8-300x150.png 300w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8-768x385.png 768w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-8.png 1080w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">First you need to have a <strong>public domain name<\/strong> and a public accessible host. Or a host running somewhere in the cloud and you will get a IP and\/or an URL, which will point to your host. In my case I have a public IP address from my internet provider and my public sub domain name points to my server at home.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My registered <strong>public domain name <\/strong>is rocworks.at. Additionally I have used a sub-domain name <strong>unified.rocworks.at<\/strong>. Because I have multiple services running on my machine at home. With the subdomain the service can be easily be distinguished.  At my internet provider I have configured a <strong>DDNS <\/strong>services, so that my subdomain unified.rocworks.at points to my IP at home. You can also use other DDNS services (noip.com) , also if you have a dynamic IP address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have it running at home, then you have to setup a port forwarding from your modem to your web server IP at home. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"147\" src=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5-1024x147.png\" alt=\"\" class=\"wp-image-1265\" srcset=\"https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5-1024x147.png 1024w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5-300x43.png 300w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5-768x110.png 768w, https:\/\/www.rocworks.at\/wordpress\/wp-content\/uploads\/2022\/12\/image-5.png 1100w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">At the <strong>WinCC Unified Runtime Host<\/strong> we have to change some settings in files, to set the right public URL for the identity provider (UMC). After doing this, you should reboot the computer. <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Config.level (C:\\Program Files\\Siemens\\Automation\\WinCCUnified\\config)\n\n\t&#91;IdentityProvider]\n\tUrl = \"https:\/\/unified.rocworks.at\/umc-sso\/\"\n\t\nWeb.config (C:\\Program Files\\Siemens\\Automation\\WinCCUnified\\WebRH)\n\n\t&lt;appSettings&gt;\n\t    &lt;add key=\"appvirtdir\" value=\"\/WebRH\" \/&gt;\n\t    &lt;add key=\"origins\" value=\"https:\/\/unified.rocworks.at\" \/&gt;\n\t  &lt;\/appSettings&gt;\n\nConfig.json (C:\\Program Files\\Siemens\\Automation\\WinCCUnified\\SimaticUA)\n\n        \"dnsname\": \"unified.rocworks.at\"\n\nUmcd.cfg (C:\\Program Files\\Siemens\\LocalUserManagement\\etc)\n\n\tSearch and replace hostnames\n\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Siemens\\User Management\\WebUI\\Settings\n\n        ipaddress = \"https:\/\/unified.rocworks.at\/umc-sso\/\"\n\n<strong>Note: instead of \"unified.rocworks.at\" use your public domain name. \n<\/strong>    <\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">At the web server at home I have <strong><a href=\"https:\/\/www.nginx.com\/\">NGINX <\/a><\/strong>running in a Docker Container together with <strong><a href=\"https:\/\/letsencrypt.org\/\">Let&#8217;s Encrypt<\/a><\/strong>. With Let&#8217;s Encrypt and <a href=\"https:\/\/letsencrypt.org\/de\/getting-started\/\">Certbot<\/a> we can get valid Certificates for our Webserver. But that&#8217;s another story. Here is a docker-compose.yml file for NGINX and Let&#8217;s Encrypt:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>version: '3'\nservices:\n  nginx:\n    image: nginx\n    restart: unless-stopped\n    ports:\n      - 80:80\n      - 443:443\n    volumes:\n      - .\/data\/www:\/var\/www\n      - .\/data\/letsencrypt:\/etc\/letsencrypt\n      - .\/config:\/etc\/nginx\/conf.d\n       \n    command: \"\/bin\/sh -c 'while :; do sleep 6h &amp; wait $${!}; nginx -s reload; done &amp; nginx -g \\\"daemon off;\\\"'\"\n\n  certbot:\n    image: certbot\/certbot\n    restart: unless-stopped\n    volumes:\n      - .\/data\/www:\/var\/www\n      - .\/data\/letsencrypt:\/etc\/letsencrypt\n    entrypoint: \"\/bin\/sh -c 'trap exit TERM; while :; date; do certbot renew --webroot -w \/var\/www\/certbot; sleep 12h &amp; wait $${1}; done;'\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Before you start with a new sub domain you have to initially get a certificate: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>docker run --rm -ti -v $PWD\/data\/www:\/var\/www -v $PWD\/data\/letsencrypt:\/etc\/letsencrypt certbot\/certbot certonly --webroot -w \/var\/www\/certbot -d <\/code>&lt;your-public-domain-name&gt;<code> --email &lt;your-email-address&gt;<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NGINX Configuration: default.conf :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n        listen 80;\n        server_name unified.rocworks.at;\n        location \/.well-known\/acme-challenge\/ {\n            root \/var\/www\/certbot;\n        }\n        location \/ {\n            root \/var\/www\/html;\n        }\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">NGINX Configuration: unified.conf:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n        server_name unified.rocworks.at;\n\n        root \/var\/www\/html;\n        index index.html index.htm;\n\n        location \/ {\n            proxy_pass https:\/\/&lt;ip-of-wincc-unified-host&gt;\/;\n            proxy_http_version 1.1;\n            proxy_set_header Upgrade $http_upgrade;\n            proxy_set_header Connection 'upgrade';\n            proxy_set_header Host $host;\n            proxy_cache_bypass $http_upgrade;\n        }\n\n        location \/umc-sso {\n            proxy_pass https:\/\/&lt;ip-of-wincc-unified-host&gt;\/umc-sso;\n            proxy_http_version 1.1;\n            proxy_set_header Upgrade $http_upgrade;\n            proxy_set_header Connection 'upgrade';\n            proxy_set_header Host $host;\n            proxy_cache_bypass $http_upgrade;\n            proxy_buffer_size 128k;\n            proxy_buffers 4 256k;\n            proxy_busy_buffers_size 256k;\n        }\n\n        #location \/graphql { # Optionally you can also publish GraphQL\n        #    proxy_pass http:\/\/&lt;ip-of-wincc-unified-host&gt;:4000\/graphql;\n        #    proxy_http_version 1.1;\n        #    proxy_set_header Upgrade $http_upgrade;\n        #    proxy_set_header Connection 'upgrade';\n        #    proxy_set_header Host $host;\n        #    proxy_cache_bypass $http_upgrade;\n        #}\n        \n\n        listen 443 ssl; # managed by Certbot\n        ssl_certificate \/etc\/letsencrypt\/live\/unified.rocworks.at\/fullchain.pem; # managed by Certbot\n        ssl_certificate_key \/etc\/letsencrypt\/live\/unified.rocworks.at\/privkey.pem; # managed by Certbot\n        include \/etc\/letsencrypt\/options-ssl-nginx.conf; # managed by Certbot\n        ssl_dhparam \/etc\/letsencrypt\/ssl-dhparams.pem; # managed by Certbot\n}<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>This article will show how WinCC Unified can be accessed through a public available server in the internet. Disclaimer: I only did this for testing and demo purposes!!! First you need to have a public domain name and a public &hellip; <a href=\"https:\/\/www.rocworks.at\/wordpress\/?p=1256\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,33],"tags":[],"class_list":["post-1256","post","type-post","status-publish","format-standard","hentry","category-allgemein","category-wincc-unified"],"_links":{"self":[{"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/1256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1256"}],"version-history":[{"count":15,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/1256\/revisions"}],"predecessor-version":[{"id":1275,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/1256\/revisions\/1275"}],"wp:attachment":[{"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rocworks.at\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}