Fix WinCC Unified Secure Download Password Errors on TIA V20

David Krause10 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

Engineers commissioning SIMATIC MTP1500 Unified Comfort Panels (and the wider MTP/MTP Unified Comfort family) on TIA Portal V20 frequently encounter a class of authentication faults that block both simulation and download paths. The visible symptoms include:

  • "The simulation password is not valid — enter the password in TIA Portal simulation settings" when launching RT Unified from the project tree.
  • "HMI had no encrypted transfer configured" raised by the simulator before the runtime is even reached.
  • "Runtime simulation is configured for encrypted transfer — enter the password or deactivate it manually in the local WinCC Unified Configuration".
  • Download to the real panel (PC runtime or Unified Comfort) terminating on a different password mismatch code that names the engineering station as a runtime target.
  • WinCC Runtime Manager opening with "wrong password" and showing an empty list of active runtimes, even when a runtime is in fact running on the same PC.

The fault is particularly confusing because the project has been recompiled with no secure transfer flag set, yet the runtime still demands a password. The cause is almost always a stale setting persisted by the WinCC Unified Configuration tool on the local machine, not by the TIA project itself.

Tested configuration: TIA Portal V20 Update 4 with WinCC Unified V20, MTP1500 Comfort Panel project, simulation via PLCSIM/PLCSIM Advanced and via local RT Unified. The same fault pattern has been observed on Unified Comfort Panels (MTP700/MTP1000/MTP1200/MTP1500/MTP1900/MTP2200) and on PC-based WinCC Unified Runtime.

Where the Four Passwords Live

WinCC Unified has four independent places that can each demand a password. They are not synchronized, and disabling one does not disable the others.

# Location UI Path Setting / Flag Scope
1 TIA Portal — Simulation Project tree → Devices → HMI_RT → Simulation → Settings "Enable secure download / encrypted transfer" with password field Project — affects RT Simulator start only
2 TIA Portal — HMI Runtime Settings HMI device → Runtime settings → General "Activate encrypted transfer" (with password) Project — compiled into the runtime project on the target
3 WinCC Unified Configuration (local tool) Start menu → Siemens → WinCC Unified Configuration Section "Download of projects / Activate secure download" Local PC — controls the download/transfer channel on the engineering station
4 WinCC Runtime Manager Start menu → Siemens → WinCC Runtime Manager Password prompt on application start, project list, Stop / Delete actions Local PC — controls the active runtimes catalogue
All four are evaluated when a download or simulation is started. A mismatch on any one of them will abort the operation with a generic "password not valid" message, even when the other three are correct.

Root Cause Analysis

On TIA V20 the WinCC Unified runtime is a separate process tree that registers itself with the local Unified Configuration service. Two failure modes are observed in the field:

Mode A — Stale local "Activate secure download" flag

Once the checkbox Activate secure download in WinCC Unified Configuration has been enabled and applied, the password and the on/off state are stored in a local configuration store (registry/service). Disabling the checkbox and clicking Apply does not always persist the change on the first attempt. The runtime keeps the previous (enabled) state. On the next download or simulation, the runtime therefore asks for the old password, even though the TIA project itself contains no encryption flag.

Mode B — TIA cannot see the cleared local state

Even when the TIA project clearly shows Activate encrypted transfer = OFF in the device runtime settings, the local Unified Configuration still enforces secure download for the project that is about to be loaded. The TIA Portal does not write to the Unified Configuration during a normal download — it relies on the user having pre-configured the channel. The net result is a "the configuration in TIA says off, but the runtime says on" mismatch.

Mode C — Leftover runtime from an old, encrypted project

If a previously downloaded project used encrypted transfer and was not cleanly removed, the local runtime manager still knows about that project and prompts for the old password whenever the catalog is opened or refreshed. This survives TIA reinstalls, but is normally cleared by uninstalling/reinstalling the runtime or by manually deleting the project via Runtime Manager once the correct (old) password is supplied.

Step-by-Step Resolution

Apply the steps below in order. Do not skip the restart actions — the configuration service caches the flag in memory.

  1. Open the TIA project. In the project tree, right-click the HMI device → Runtime settings → General. Clear the checkbox Activate encrypted transfer. Leave the password field empty. Compile (rebuild all) the HMI device so the .bin/runtime is regenerated.
  2. Open TIA simulation settings. Project tree → device → Simulation → Settings. Uncheck any "Enable secure download" flag. Save the project.
  3. Open WinCC Unified Configuration on the engineering PC. In the section Download of projects, clear the checkbox Activate secure download. Click Next until the wizard completes, then click Apply. Reopen the tool and verify the checkbox is still cleared — if it has reverted, repeat and complete the wizard a second time, then reboot the configuration service (see step 5).
  4. Open WinCC Runtime Manager. If it prompts for a password, enter the password of the previously encrypted project that is still registered locally. The catalog of runtimes will populate. Select the stale project, click Stop, then Delete. Close the Runtime Manager.
  5. Restart the Unified Configuration service to force a reload of the secure-download flag. Open an elevated command prompt and run:
    net stop "Siemens.WinCC.Unified.ConfigurationService"
    net start "Siemens.WinCC.Unified.ConfigurationService"
    If the service name varies by version, use sc queryex type= service state= all | findstr /I "Unified" to list the actual service names. On some builds, a full workstation restart is required.
  6. Rebuild and download. In TIA Portal, recompile the HMI device, then choose Download to device → PC runtime or Download to device → HMI panel. Confirm the download preview shows no security prompt and that the transfer proceeds to 100%.
  7. Start the simulation. Launch the runtime from the project tree. The "simulation password is not valid" message should no longer appear. If a residual prompt is shown, the local secure-download flag is still on — return to step 3.
If you want encrypted transfer to remain active (e.g. for plant acceptance with signed projects), set the same password in all four locations and complete the Unified Configuration wizard. The runtime does not compare passwords across locations — it only checks that the project password matches the channel password on the local machine.

Verification Procedure

After applying the resolution, run the following checks before handing the station back to operations:

  1. Simulation round-trip. Start and stop the RT Unified simulator from TIA. Repeat three times consecutively. The first launch may still pick up cached state; launches 2 and 3 must run without a password prompt.
  2. Download to PC runtime. From TIA, perform Download to device → PC runtime. The transfer should complete in one pass with no mid-download "wrong password" dialog.
  3. Download to MTP panel. With the panel connected, choose Download to device → HMI panel. Confirm in the Runtime Manager that the new project appears in the catalog without a re-prompt for an old password.
  4. Unified Configuration audit. Reopen the WinCC Unified Configuration tool. The checkbox Activate secure download must show the same state as the TIA project. If they disagree, the service has not reloaded — restart it.
  5. Runtime Manager catalog. Open the Runtime Manager without entering any password. If a prompt appears, a stale encrypted project is still registered — repeat step 4 of the resolution.

Diagnostic Matrix

Symptom Likely Mode Fastest Diagnostic Fix
"Simulation password is not valid — enter the password in TIA Portal simulation settings" Mode A or B Reopen WinCC Unified Configuration, observe the Activate secure download flag Disable the flag in Unified Configuration and restart the configuration service
"Runtime simulation is configured for encrypted transfer" despite TIA project showing OFF Mode B Compare TIA runtime settings against WinCC Unified Configuration; they will disagree Reapply the wizard in Unified Configuration and restart the service
Runtime Manager opens with "wrong password" and shows empty runtime list Mode C Try the old project's password — catalog will populate Stop and delete the stale project, restart Runtime Manager
Download to MTP aborts with a different password mismatch code Mode B + C Check whether the engineering PC is being treated as a runtime target (project list in Runtime Manager) Remove the stale runtime, then retry the download
Configuration wizard checkbox reverts on reopen Mode A — wizard not committed Watch for the final Apply step; some builds require both Next and Apply Complete the wizard twice, restart the configuration service

Edge Cases and Field-Proven Caveats

  • TIA 21 upgrade path. Field reports indicate the local Unified Configuration state is preserved across a TIA Portal V20 → V21 in-place upgrade only if the upgrade installer is run with administrative rights. A failed upgrade can leave the runtime thinking secure download is on while the TIA project shows it as off. Repairing the TIA installation, or completing the V21 install, has been observed to clear the inconsistency.
  • Multiple engineering users on the same PC. The Unified Configuration is per-machine, not per-user. A second user logging in with a TIA project that has encrypted transfer enabled will inadvertently enable the flag for all users. Conversely, disabling it as one user disables it for all.
  • Remote desktop / RDP engineering. When the engineering PC is accessed over RDP, the configuration service runs in the console session, not the RDP session. Configure the runtime on the console session; verify from the RDP session.
  • Antivirus interference. Some endpoint protection products block writes to the Unified Configuration store, causing the Apply step to silently fail. Whitelist the Siemens configuration service executable and the project download folder (default %ProgramData%\Siemens\Automation\WinCCUnified).
  • Custom certificates. If the project is signed with a custom WinCC Unified certificate, "encrypted transfer" is a separate setting from "signed transfer". The password issue described here is independent of certificate management; clearing the encryption flag does not invalidate the project signature.
  • PLCSIM coexistence. When simulating both the controller (PLCSIM / PLCSIM Advanced) and the HMI, secure download affects only the HMI channel. The controller simulation is unaffected.

Related Siemens Documentation

Preventive Recommendations

  1. For development and simulation workstations, leave Activate secure download disabled in WinCC Unified Configuration. Re-enable it only for the specific engineering PC that is responsible for transferring signed, encrypted projects to plant.
  2. Maintain a small commissioning checklist that includes verifying all four password locations are either all set to the same value, or all disabled.
  3. After any TIA Portal upgrade, repeat steps 3, 5, and 6 of the resolution on every engineering PC. A V20→V21 jump is the most common trigger for Mode A faults.
  4. Where encrypted transfer is mandatory (signed deliverables, customer acceptance), document the password in the project functional specification and in the project TIA portal team-share comment, not on a local sticky note.

FAQ

Why does the runtime demand an old project password even after I disabled encrypted transfer in TIA?

The local WinCC Unified Configuration service on the engineering PC caches the Activate secure download flag independently of the TIA project. The runtime consults this local flag, not the TIA project, when starting a transfer. Open WinCC Unified Configuration, uncheck the flag, complete the wizard with Next → Apply, then restart the configuration service (net stop / net start "Siemens.WinCC.Unified.ConfigurationService").

WinCC Runtime Manager always opens with "wrong password" and shows no runtimes — is this a bug?

No. The catalog of runtimes is encrypted on disk. The prompt is the catalog decryption password. If the catalog was last written by a project with encrypted transfer, enter that project's password; the list will populate. Select the stale project, Stop and Delete it, then close the Runtime Manager. Future opens will no longer prompt for that password.

Can I have encrypted transfer enabled in the TIA project but disabled in the local Unified Configuration?

Technically yes, but the download will fail. The runtime requires that the local channel flag and the project flag agree. For a development PC, disable both. For a production engineering PC that must deliver encrypted projects, enable both with the same password in all four locations.

Does this issue affect MTP700/MTP1000/MTP1200/MTP1900/MTP2200 panels as well as the MTP1500?

Yes. The secure-download / encrypted-transfer logic is part of the WinCC Unified runtime and is shared across the entire Unified Comfort Panel family and the PC-based Unified Runtime. The same four-location password model applies.

Will reinstalling TIA Portal clear the stale secure-download flag?

Not always. The Unified Configuration state is stored under the local Siemens configuration service, which may be retained across TIA reinstalls. A V20 → V21 in-place upgrade has been observed to clear it, but the more deterministic path is to manually disable the flag in WinCC Unified Configuration and restart the configuration service as described above.

Back to blog