OPC UA communication
9.2 Security at OPC UA
Communication
186
Function Manual, 05/2021, A5E03735815-AJ
Certificate management
Certificate management has the task of automating the administration and distribution of
certificates and trust lists for OPC UA applications.
In this context, a distinction is made between the following roles:
•
Certificate manager - an OPC UA application that provides certificate management
functions
•
Certificate recipient – an OPC UA application that receives certificates, trust lists and CRLs
from the certificate manager.
There are two models for certificate management: Pull and push management.
•
With pull management, the OPC UA application acts as a client of the GDS server and uses
certificate management methods to request certificate updates and trust list updates.
•
With push management, the OPC UA application acts as a server and provides methods for
an OPC UA GDS as OPC UA client. The GDS in the role of certificate manager uses these
methods to transfer ("push") certificates and trusted list updates, see explanation of the
concept for automated certificate update below.
As of firmware version V2.9, the S7-1500 CPU currently only supports push management for
the OPC UA server of the CPU.
You cannot transfer certificates for the OPC UA client instructions of the CPU to the CPU via
push management.
System configuration with GDS
The figure below shows an example of the tasks of the devices involved in combination with
a GDS that provides certificate management functions.
①
Root CA - device that issues certificates for the system (these certificates can also be transmitted
in other ways, for example, by email)
②
OPC UA GDS with certificate manager creates or signs device certificates, manages trust lists
and certificate revocation lists (CRLs), and writes certificates and lists to the devices (push func-
tion). This device requires OPC UA client functionality for the push function.
③
Device with OPC UA application receives "pushed" certificates and lists
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......