OPC UA communication
9.2 Security at OPC UA
Communication
192
Function Manual, 05/2021, A5E03735815-AJ
Entering the provisioning phase
After startup of the OPC UA server, the CPU automatically enters the provisioning phase when
one of the following conditions is met:
•
The OPC UA server certificate is the initial self-signed certificate generated by the CPU and
has not yet been replaced by a valid server certificate.
•
The trust list (list of trustworthy clients) is empty.
The OPC UA server certificate generated by the CPU contains the most important parameters
of the OPC UA server and is re-generated, including the private key, after each startup of the
OPC UA server following POWER ON - until the valid server certificate is present. For this
reason, the OPC UA server may take longer to start up after a POWER ON.
After the hardware configuration is downloaded, the certificate store for certificates that can
be updated during runtime is deleted on download or the certificates are retained, depending
on the setting. In other words, if GDS is activated and the certificate store has been deleted,
the CPU is in the provisioning phase after loading the hardware configuration.
Provisioning phase diagnostics
In addition to the lit Maintenance LED, the GDS address model has two nodes that provide
information on whether the OPC UA server of the CPU is in the provisioning phase:
You can only use the two nodes as marked in the figure for diagnostics if the requirements
for GDS are met (endpoint security signed & encrypted plus administrator function rights
available).
ProvisioningModeEnabled: Indicates that a provisioning phase is supported
ProvisioningModeActive: Indicates that the OPC UA server of the CPU is in the provisioning
phase.
End of the provisioning phase
The CPU ends the provisioning phase automatically when the following conditions are met:
•
The certificate generated and self-signed by the CPU for the provisioning phase has been
overwritten by a valid server certificate. This valid server certificate can be a self-signed
certificate or a CA-signed certificate.
•
The trust list in the CPU is not empty, i.e. client certificates of the OPC UA clients to be
trusted or CA certificates for checking the client certificates are available.
If the OPC UA client transfers a CA-signed certificate and also adds the CA certificate to the
trust list, the OPC UA server of the CPU can automatically accept all other certificates from
OPC UA clients that were signed by the same CA.
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......