D Certicate Management and
Maintenance
Precongured Certicate Risk Disclaimer
The Huawei-issued certicates precongured on Huawei devices during
manufacturing are mandatory identity credentials for Huawei devices. The
disclaimer statements for using the 
certicates are as follows:
1. Precongured Huawei-issued certicates are used only in the deployment
phase, for establishing initial security channels between devices and the
customer's network. Huawei does not promise or guarantee the security of
precongured certicates.
2. The customer shall bear consequences of all security risks and security
incidents arising from using precongured Huawei-issued certicates as
service 
certicates.
3. A precongured Huawei-issued certicate is valid from the manufacturing
date until October 2041.
4. Services using a 
precongured Huawei-issued certicate will be interrupted
when the certicate expires.
5. It is recommended that customers deploy a PKI system to issue 
certicates for
devices and software on the live network and manage the lifecycle of the
certicates. To ensure security, certicates with short validity periods are
recommended.
Application Scenarios of Precongured Certicates
File Path and Name
Application Scenario Replacement
f:/ca.crt (Root certicate) When the PCS
communicates with the
SACU through Modbus-
TCP, the certicate two-
way authentication is
performed.
For details about how to
replace a certicate,
contact technical support
engineers to obtain the
corresponding security
maintenance manual.
f:/tomcat_client.crt
(Local Certicate)
f:/tomcat_client.key
(Private key le)
LUNA2000-100KTL-M1 Smart Power Control System
User Manual D Certicate Management and Maintenance
Issue 02 (2023-01-10) Copyright © Huawei Technologies Co., Ltd. 105