Release Notes

This download includes FactoryTalk Services Platform, FactoryTalk Linx, and FactoryTalk Alarms & Events. Additional keywords:
Version 6.40.00 (released 11/2023)

Catalog Number FactoryTalk Services 

These release notes describe version information for FactoryTalk Services, version 6.40.00 (released 11/2023).

Requirements

This release has the following requirements.

FactoryTalk Services Platform version 6.40.00 (CPR 9 SR 14)

To run FactoryTalk Services Platform, the host computer must meet the hardware, software, and firmware requirements. For the latest compatibility information, refer to the Product Compatibility and Download Center.

Hardware requirements

FactoryTalk Services Platform requires the following hardware:

Software requirements

FactoryTalk Services Platform has been tested on the following operating systems:

High Resolution Display Support

Windows 10 v1803 or later is the recommended operating system if running this software with a 2K or 4K High Resolution Display with scaling up to 125%.
Rockwell Automation Test Environment

Rockwell Automation tests software products under a standard configuration of operating systems and antivirus software. For additional information, see the Knowledgebase Document ID: PN24 - Rockwell Software Products and Antivirus Software.

Security requirements

To help meet secure system design requirements, review these publications:

To learn about implementing CIP Security, see CIP Security with Rockwell Automation Products Application Technique (publication SECURE-AT001).

Firmware requirements

FactoryTalk Services Platform does not have any firmware requirements. Hardware and software products that use FactoryTalk Services Platform might place limits on firmware versions. Read release notes for each product in the FactoryTalk system to determine firmware requirements.

Features

This release includes the following system features.

FactoryTalk Services Platform version 6.40.00 has the following new and enhanced features:

New features

Enhanced features

Corrected Anomalies in This Release

This release corrects the following anomalies.

Known Anomalies in This Release

This release has the following known anomalies.

Known Anomalies from Previous Releases

These anomalies are from previous releases but are still known in this release.

Functional Changes

This release has the following functional changes from the previous release.

FactoryTalk Services Platform version 6.40.00 has the following changes in functionality since the last release.

Application Notes

This release has the following application notes.

These application notes apply to FactoryTalk Services Platform version 6.40.00.

CIS Benchmarks test results

Rockwell Automation conducts tests using domain-joined computers configured according to the Center for Internet Security (CIS) operating system benchmarks to help assure that software products perform as expected on computers that are hardened following industry best practices.

For more information about the guidelines, see the Knowledgebase Document ID: QA63609 - Recommended guidelines for hardening software, computer, device, and network systems and infrastructure (CIS Benchmarks).
FactoryTalk Services Platform version 6.40.00 has been tested on CIS Microsoft Windows 10 Enterprise (Release 22H2) Benchmark v2.0.0, CIS Microsoft Windows 11 Enterprise (Release 22H2) Benchmark v2.0.0, CIS Microsoft Windows Server 2019 Benchmark v2.0.0, and CIS Microsoft Windows Server 2022 Benchmark v2.0.0.
Exceptions settings for FactoryTalk Services Platform version 6.40.00 are listed.
FactoryTalk Directory Server
CIS Microsoft Windows 10 Enterprise (Release 22H2) Benchmark v2.0.0
CIS Microsoft Windows 11 Enterprise (Release 22H2) Benchmark v2.0.0
CIS Microsoft Windows Server 2019 Benchmark v2.0.0
CIS Microsoft Windows Server 2022 Benchmark v2.0.0
FactoryTalk Directory Client
CIS Microsoft Windows 10 Enterprise (Release 22H2) Benchmark v2.0.0
CIS Microsoft Windows 11 Enterprise (Release 22H2) Benchmark v2.0.0
CIS Microsoft Windows Server 2019 Benchmark v2.0.0
CIS Microsoft Windows Server 2022 Benchmark v2.0.0

Full OS backup

Rockwell Automation does not test any third-party software to perform the full Windows operating system backup, for example, Veritas Backup Exec. When performing a computer backup on a running virtualized system, it is recommended the system is stopped before performing a backup.
Application(client) Secret
If you want to use the web applications and Azure AD authentication, you must provide a Client Secret from the Azure AD App Registration when configuring the Azure AD Authenticate Site in FactoryTalk Administration Console.

Application(client) Secret

If you want to use the web applications and Azure AD authentication, you must provide a Client Secret from the Azure AD App Registration when configuring the Azure AD Authenticate Site in FactoryTalk Administration Console.

Installation

The system will modify the access control list (ACL) of RNAServer’s subfolders, including Global, Local, and Backups, and give the Write permission to the administrator and services only during the FactoryTalk Services Platform installation. After installation, if you need the Write permission to these subfolders in ProgramData\Rockwell\RNAServer in the installation drive, go to C:\Program Files (x86)\Common Files
\Rockwell and then run ChangeACE.exe as administrator to modify permissions. The command-line parameters and their meanings are as follows:
  • \a

    Add the Write permission to all users.

  • \r

    Remove the Write permission of all users except for the administrator and services.

FactoryTalk Diagnostics
FactoryTalk Diagnostics cannot log to a remote database using Microsoft Access. You can only log to a local database using Microsoft Access.

Product Updates and Patches

For the latest Product Updates and Patches, refer to Knowledgebase Document ID: IN1983 - Firmware and Software Updates. To be notified when new Product Updates or Patches are released, click the ADD TO FAVORITES link at the top of the Knowledgebase Answer.

For additional information about changes to communications software after the writing of these Release Notes, refer to Knowledgebase Document ID: IN7550 - FactoryTalk Linx Patch and Release Information.

To download software updates, firmware updates, or patch roll-ups, refer to the Product Compatibility and Download Center.

Mitigation for Microsoft DCOM Hardening patch

In response to Microsoft Distributed Component Object Model (DCOM) Hardening patch (MS KB5004442), the minimum DCOM authentication level used by Rockwell Automation products was raised to Packet Integrity.

IMPORTANT

Installing this product’s latest version with earlier unpatched versions of other FactoryTalk products or products using Classic OPC DA connections may cause a loss of connectivity due to the difference in DCOM authentication level used. For additional information, see the Knowledgebase Document ID: IN39461 - Microsoft DCOM Hardening Information TOC.



Microsoft releases the DCOM Hardening patch in response to CVE-2021-26414. This patch elevates the minimum DCOM authentication level that is required to establish a DCOM connection. DCOM is used by many Rockwell Automation products and may be affected by the change that is made by the Microsoft patch. For additional information about the affected Rockwell Automation products, see the Knowledgebase Document ID: PN1581 - Product Notification 2022-01-001 - Rockwell Automation products unable to establish proper DCOM connection after installing Microsoft DCOM Hardening patch (MS KB5004442).

Windows Administrator permissions

When performing some actions with a user account that is not a member of the Windows Administrators group, Windows prompts for the username and password of a Windows administrator. This Windows administrator credentials prompt cannot be disabled. This prompt appears even when User Account Control (UAC) is disabled.

The actions that require Windows administrator actions are:

This action
Commonly started this way
Requires administrator access before running this program
Viewing or changing the name of the computer hosting the FactoryTalk Directory Server in FactoryTalk Administration Console
or
Running the FactoryTalk Directory Server Location Utility
In FactoryTalk Administration Console, Tools > FactoryTalk Directory Server Options
or
Start > All Programs > Rockwell Software > FactoryTalk Tools > Specify FactoryTalk Directory Location
FTSetDirSrv.exe
Setting up or changing settings related to FactoryTalk Diagnostics
In FactoryTalk Administration Console, Tools > FactoryTalk Diagnostics > Setup
DiagnosticsSetup.exe
Running the Windows Firewall Configuration Utility
Start > All Programs > Rockwell Software > FactoryTalk Tools > Windows Firewall Configuration Utility
WFCU.exe
Installing FactoryTalk Services Platform, which silently runs the FactoryTalk Directory Configuration Wizard
or
Running the FactoryTalk Directory Configuration Wizard
Installation
or
Start > All Programs > Rockwell Software > FactoryTalk Tools > FactoryTalk Directory Configuration Wizard
FTDConfigurationUtility.exe
Installing the RSSecurity Emulator to allow existing RSSecurity Server clients to access FactoryTalk Security
Start > All Programs > Rockwell Software > FactoryTalk Tools > RSSecurity Emulator Install
RSSecurity Emulator 6.30 (CPR 9 Service Release 13).msi

Server Status display

If the FactoryTalk Linx server service is explicitly stopped using the Windows Services control panel the service will automatically restart to respond to client requests. If using redundant servers, stopping the service will cause a switchover to the secondary server.

In both situations, a standalone server and a redundant server configuration, if the Server Status dialog box is open when the service is stopped the status of the server displays Ready to provide service instead of Active.

Closing the Server Status dialog box and reopening it updates the status displayed accordingly.

Unattended or silent install

Use command-line parameters to perform an unattended or silent installation of the software.

Installation Command-line parameters

The following table identifies the installation command-line parameters. Command-line parameters are case-insensitive. However, if a specified value includes a space, be sure to enclose the value in quotation marks (for example, "value with spaces").

Parameter
Description
/?
Displays the usage options for installation parameters.
/Q
Silent Install, install runs in a quiet mode without any user interface.
This parameter is recommended when deploying the software installation using an IT tool or script, and don’t expect any error or restart messages. When using this parameter, check the error codes, and respond as needed. For example, if the installation returns error code 1641, then the IT tool or script should restart the computer and relaunch the installation after restart.
This parameter is required if /QS is not specified.
/QS
Unattended Install, install runs in a quiet simple mode and shows progress through the UI, it does not accept any input but still shows errors or restart messages.
When using this parameter, the installation will stop and display a prompt if there are errors or restart messages. For example, if an immediate restart is required to complete the install, a restart message will be displayed to confirm the restart. Installation resumes automatically from the point of interruption after restart.
This parameter is required if /Q is not specified.
/IAcceptAllLicenseTerms
Acknowledges acceptance of the license terms.
This parameter is required for /Q or /QS parameters.
/AutoRestart
Automatically restarts the computer after the installation is complete. Used when a restart is required to complete the installation.
This parameter is optional. If this parameter is not used silent install (/Q) will return either error code 1641 or 3010 if a restart is required, and unattended install (/QS) will result in a confirmation prompt that must be agreed to before the installation is completed.
/Record
Records the installation options chosen to a recording file.
This parameter is optional.
/Playback
Plays back a recording file to specify the installation options.
This parameter is optional.
/SetupLanguage="value"
Specifies which language will be displayed during the install process.
The value must be one of the following:
  • ENU
  • CHS
  • DEU
  • ESP
  • FRA
  • ITA
  • JPN
  • KOR
  • PTB
This parameter is optional. If this parameter is not used, the default language is the current user or operating system user interface language.
/IgnoreWarning
Specifies that the setup ignores warnings and continues.
This parameter is optional. If it is not specified, the setup exits when a warning occurs.
/ftsp-s
Specifies the FactoryTalk directory scope for restore. Only "Global" and "Local" scopes are supported.
This parameter is optional.
/ftsp-bak
Specifies the location where the restore file can be found.
This parameter is optional.
/ftsp-pp
Specifies the plain text used to decrypt the backup file.
This parameter is optional.
/ftsp-value=enable/disable
Specifies to enable or disable the option Require computer accounts for all client machines in Security Policy. The option is used to determine whether or not a client computer account must exist in the directory to log in.
This parameter is optional.
/FTSPWebAuth="value"
Specifies that the installation includes the FactoryTalk Web Authentication Server.
This parameter is optional.
The value must be one of the following:
  • Yes
    If the value is Yes, the FactoryTalk Web Authentication Server will be installed. The FactoryTalk Reverse Proxy will also be installed as it is required for operation of the FactoryTalk Web Authentication Server.
  • No
    If the value is No, the FactoryTalk Web Authentication Server will not be installed.
/ReverseProxy="value"
Specifies that the installation includes the FactoryTalk Reverse Proxy.
This parameter is optional.
The value must be one of the following:
  • Yes
    If the value is Yes, the FactoryTalk Reverse Proxy will be installed.
  • No
    If the value is No, the FactoryTalk Reverse Proxy will not be installed.
/FTSPWebEventServer="value"
Specifies that the installation includes the FactoryTalk Web Event Server.
This parameter is optional.
The value must be one of the following:
  • Yes
    If the value is Yes, the FactoryTalk Web Event Server will be installed.
  • No
    If the value is No, the FactoryTalk Web Event Server will not be installed.
/SystemStatusPortal="value"
Specifies that the installation includes the FactoryTalk System Status Portal.
This parameter is optional.
The value must be one of the following:
  • Yes
    If the value is Yes, the FactoryTalk System Status Portal will be installed. The FactoryTalk Reverse Proxy and FactoryTalk Web Authentication Server will also be installed as it is required for operation of the FactoryTalk System Status Portal.
  • No
    If the value is No, the FactoryTalk System Status Portal will not be installed.
/DirectoryServer
Specifies the directory server name.
This parameter is optional. If it is not specified, the setup turns on HTTPS for communication, and a TLS certificate must be configured after installation.
/NoHTTPS
Specifies that the setup turns off HTTPS.
This parameter is optional. If it is not specified, the setup turns on HTTPS for communication, and a TLS certificate must be configured after installation.
/Repair
Runs a repair operation on the installed products.
This parameter is optional.
/InstallDrive="value"
Specifies the install drive.
This parameter is optional. If this parameter is not used, the default install location is "C:\Program Files (x86)\Rockwell Software".
Some software restricts the installer to only change the drive the software is installed on. Use /? to determine which parameter is supported.
/Uninstall
Use to uninstall the product. This parameter is optional.

Examples

The following examples show how to use the installation commands.

  • To install the software with no user interface using the default settings during the installation process. (Silent install)
  • Setup.exe /Q /IAcceptAllLicenseTerms
  • To install the software with Chinese displayed during the install process and restart the computer if necessary. (Unattended install)
  • Setup.exe /QS /IAcceptAllLicenseTerms /AutoRestart /SetupLanguage=CHS
  • To install the software with FactoryTalk security policy value specified.
  • Setup.exe /Q /IAcceptAllLicenseTerms /ftsp-value=enable
  • To perform a restore during the install process.
  • Setup.exe /Q /IAcceptAllLicenseTerms /ftsp-bak="C:\aa.bak"
  • To specify the FactoryTalk Directory machine.
  • Setup.exe /Q /IAcceptAllLicenseTerms /DirectorySever=severname

Error codes

The following table identifies the error codes that can be returned by an installation.

Error Code
Value
Description
ERROR_SUCCESS
0
The installation completed successfully.
ERROR_INVALID_PARAMETER
87
One of the parameters was invalid.
ERROR_INSTALL_USEREXIT
1602
The installation was canceled by the user.
ERROR_INSTALL_FAILURE
1603
A fatal error occurred during installation.
ERROR_BAD_CONFIGURATION
1610
The configuration data for this product is corrupt. Contact your support personnel.
ERROR_REBOOT_CONTINUE
1641
A restart is required to continue the installation.
ERROR_SUCCESS_REBOOT_REQUIRED
3010
A restart is required to complete the installation. After restarting, the product is successfully installed.
ERROR_REBOOT_PENDING
3012
Restart is pending. Restart the computer to continue the installation.
ERROR_SUCCESS_NOT_APPLICABLE
3013
The installation cannot proceed because the products are already installed.
ERROR_SUCCESS_WARNING_REBOOT
3014
The installation succeeded with warnings. Check the installation log file for details. To complete the installation, restart the computer.

Certificates

The following certificates are installed when installing Rockwell Automation software.

  • Use Microsoft Management Console (MMC) to view the certificates in Console Root > Certificates (Local Computer) > Trusted Root Certification Authorities > Certificates.
    • 2016-Rockwell-Driver-SHA1.cer
    • 2016-Rockwell-SHA256.cer
    • DriverCodeSigning2012-1.cer
    • Drivers-10-10-2018.cer
    • Drivers-11-03-2017.cer
    • Drivers-12-06-2016.cer
    • DriversSHA1-10-10-2018.cer
    • Drivers-SHA1-11-27-2017.cer
    • Logix-11-04-2016.cer
    • Rockwell_2013.cer
    • Rockwell_2014.cer
    • Rockwell_2015.cer
    • rockwellcert2010.cer
    • rockwellcert2013.cer
    • VeriSign Class 3 Public Primary Certification Authority -G5 2036.cer
  • Use Microsoft Management Console (MMC) to view the certificates in Console Root > Certificates (Local Computer) > Trusted Publishers > Certificates.
    • MicRooCerAut2011_2011_03_22.cer
    • RA - Enterprise Root Certification Authority.cer
    • VeriSign Universal Root Certification Authority.cer

FactoryTalk Services Platform and Sophos Anti-Virus

Rockwell Automation® does not formally test with Sophos Anti-Virus®, but has received reported issues with it and the FactoryTalk Services Platform. Specifically, Sophos Anti-Virus functionality has resulted in FactoryTalk process crashes due to the loading of Sophos Anti-Virus DLLs in the RSVCHOST process space. The resolution to these reported issues was to disable Sophos Anti-Virus, which allowed for proper functionality of the FactoryTalk Services Platform. Other workarounds may have resolved the problem, such as allowing FactoryTalk Services Platform within the Sophos Anti-Virus application, but these were not tested. Only a small number of these cases have been reported, meaning it is not clear if all Sophos Anti-Virus deployments will experience issues.

FactoryTalk Services Platform and Microsoft XML Core Services (MSXML)

Due to the end of the Microsoft product support lifecycle, all Microsoft XML Core Services (MSXML) 3.0 and 4.0 libraries have been removed from FactoryTalk Services Platform. These libraries may be installed or used by other applications but are not installed or used by FactoryTalk Services Platform.

Network security

For the latest network security considerations when using Rockwell Automation products, visit the Rockwell Automation Knowledgebase.

For information about:

Password Policy compatibility

FactoryTalk Services Platform version 3.00 or earlier used the MD5 cryptographic hashing algorithm to encode passwords. If compatibility with FactoryTalk Services Platform version 3.00 or earlier is required the MD5 password encryption method must be selected. MD5 is an older algorithm that has known security vulnerabilities. Using the SHA-256 encryption method is recommended.

IMPORTANT

After changing the password encryption method, all existing FactoryTalk user accounts' password will be removed and must be re-entered by the user.


To modify the Password encryption method

  1. In FactoryTalk Administration Console Explorer, expand System > Policies > System Policies.
  2. Right-click Security Policy and select Properties.
  3. In Security Policy Properties, select > to expand Password Policy Settings.
  4. In Password encryption method select the down arrow and select SHA-256 or MD5.

    Changing the password encryption method invalidates current user passwords.

  5. Select OK or Apply to apply the new settings.
  6. Choose how to apply the password encryption method change to all of the current FactoryTalk user accounts.
    • Select Disable all FactoryTalk user accounts to review each user account and select unique passwords for each.
    • Select Reset all FactoryTalk user passwords immediately to set a new password on all user accounts and require users to specify a new password the next time they log on.

System login method

Please be aware that selecting Badge Only as system login method allows access to the system without authenticating the native FactoryTalk user. The system grants access solely on the identity of the badge. To maintain a strong security posture, we recommend that you select Password and Badge as the system login method to provide passwords in addition to presenting the badge.

Note: The Badge Only system login method cannot be used with Windows-linked users.



Rockwell Automation recognizes that some of the terms that are currently used in our industry and in this publication are not in alignment with the movement toward inclusive language in technology. We are proactively collaborating with industry peers to find alternatives to such terms and making changes to our products and content. Please excuse the use of such terms in our content while we implement these changes.

Copyright © 2025 Rockwell Automation, Inc. All rights reserved.
Rockwell Automation, Allen-Bradley, and FactoryTalk are trademarks of Rockwell Automation, Inc.
To view a complete list of Rockwell Automation trademarks please click here.
Trademarks not belonging to Rockwell Automation are property of their respective companies.