OPC UA communication
9.2 Security at OPC UA
Communication
196
Function Manual, 05/2021, A5E03735815-AJ
Method / Attribute (Variable) Description
GetRejectedList
Method that returns a list of certificates that were rejected by the
OPC UA server.
Rejected certificates are currently not stored by the OPC UA server
of the S7-1500 CPUs. The method returns an empty array (Rejected-
List).
ServerCapabilities
Variable is not supported by the OPC UA server of the S7-1500 CPU.
SupportedPrivateKeyFormats
Variable that specifies permitted formats of the private key. For S7-
1500 CPUs only "PEM" (String Array)
MaxTrustListSize
Variable that specifies the maximum size of the trust list.
MulticastDnsEnabled
Variable that specifies whether multicast DNS is supported. For S7-
1500 CPUs, the value is "False".
CertificateGroups
Object (directory) that organizes all certificate groups supported by
the OPC UA server. The certificate groups contain the objects that
can be updated dynamically during runtime: One trust list each and
one or multiple certificates that are assigned to an OPC UA applica-
tion.
Details on the structure of the CertificateGroups object and the
methods and attributes that are available in the object are described
in the next section.
CreateSigningRequest
The method has the following parameters:
Parameter
Data type
Description
[in] certificateGroupId
NodeId
NodeId of the CertificateGroup object. Only one
certificate groups is currently supported by the
CPU (DefaultApplicationGroup).
[in] certificateTypeId
NodeId
Requested certificate type.
List of permitted certificate types is specified by
the "CertificateTypes" variable of the certificate
group.
Currently only the certificate type
"RsaSha256ApplicationCertificateType".
[in] subjectName
String
Subject Name that is requested in the Certifi-
cate Request. If not specified, the current Sub-
ject Name of the certificate is used.
[in] regeneratePrivateKey
Boolean
True: Server generates a new private key. This
key is saves until the UpdateCertificate meth-
ods with the matching signed certificate is
called.
False: Server uses the available private key.
[in] nonce
ByteString
Additional nonce for generating the new pri-
vate key (see regeneratePrivateKey). Must be at
least 32 bytes long.
[out] certificateRequest
ByteString
PKCS #10 - DER coded Certificate Request.
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......