OPC UA communication
9.2 Security at OPC UA
Communication
Function Manual, 05/2021, A5E03735815-AJ
199
9.2.7.6
CertificateGroups in the address model
Certificates and trust lists for the OPC UA server that can be updated during runtime are
located in the address model in the "CertificateGroups" object - for the OPC UA server of the
S7-1500 CPU there is exactly one certificate group called "OpcUaServerGroup".
CertificateGroup in the address model
The following figure shows the structure of the "CertificateGroups" object below the
"ServerConfiguration" node.
You can change the Display Name of the "OpcUaServerGroup" group in STEP 7 (TIA Portal):
1.
In the Inspector window (CPU properties), go to the "OPC UA > Server > Certificates" area.
2.
Select the option "Use certificates managed by certificate management server during
runtime".
3.
Change the group name (DisplayName) of the certificate group in the table below. 1-64
characters in 7-bit ASCII format are permitted.
"CertificateTypes" node
The "CertificateTypes" variable specifies the NodeIds of the certificate types that are assigned
to the server application.
Currently, only "RsaSha256ApplicationCertifcateType" is supported.
"TrustList" node
The node for the trust list object (TrustList file) defines an OPC UA file type (Binary encoded
stream) that contains information on the certificates and CRLs that can be read and updated
in the "pki store\trusted/issuer" directory of the Memory Card. This node provides methods
and attributes that make reading and updating possible.
The node is an instance of the OPC UA data type "TrustListDataType" with the following
structure:
Parameter
Data type
Description
specifiedLists
TrustListsMasks
Bit mask that shows which lists contain infor-
mation.
trustedCertificates
ByteStrings
List of the trusted application certificates and
CA certificates.
trustedCrls
ByteStrings
CRLs for the certificates in the "trustedCertifi-
cates" list.
issuerCertificates
ByteStrings
List of the CA certificates that are necessary for
validating the CA-signed certificates.
issuerCrls
ByteStrings
CRLs of the CA certificates in the "issuerCertifi-
cates" list.
Summary of Contents for SIMATIC ET 200AL
Page 2: ......
Page 143: ......
Page 218: ......
Page 250: ......
Page 296: ......
Page 337: ......
Page 365: ......
Page 392: ......
Page 419: ......
Page 451: ......
Page 483: ......
Page 597: ......
Page 648: ......
Page 702: ......
Page 739: ......
Page 781: ......
Page 804: ......
Page 828: ......
Page 853: ......
Page 880: ......
Page 906: ......
Page 996: ...Diagnostics ...
Page 1121: ......
Page 1565: ......