Search
33 result(s) for CertificateGroup
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services3.1.2 CertificateGroupCertificateGroup a context used to manage the TrustList and Certificate(s) associated with Applications or Users
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global ServicesCertificateGroups by browsing the CertificateGroups Folder of the Directory Object . If more than one CertificateGroup is returned, the user selects the relevant CertificateGroups used by the application. The selected CertificateGroupIds
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Servicesused to create a connection with MessageSecurityMode SignAndEncrypt and an Anonymous user. The default CertificateGroup from the Client configuration is used to establish the connection. Application authentication is used ... ApplicationId NodeId of the OPC UA Application in the CertificateManager . CertificateGroupIds NodeIds for each CertificateGroup in the CertificateManager that are relevant to the OPC UA Application . This includes a mapping
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Servicesinvolved in updating the Certificate are described in the Update TrustList workflow. For each CertificateGroup the TrustList is updated first. The updates shall include all issuers and CRLs needed ... validate new Certificates assigned to the CertificateGroup. If the CertificateManager needs to connect using an Endpoint associated with the CertificateGroup then the TrustList update shall include all Certificates needed
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Servicesstarts when the CertificateManager determines that an update to a Certificate assigned to a CertificateGroup is required. It is shown in Figure 19 . The boxes with blue text indicate Method
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.7.5 Create Endpoint Workflowlist of UpdateTargets is needed. Only records referenced by the UpdateTargets are processed. New CertificateGroup Required? Checks if a new CertificateGroup is required. Add CertificateGroup A new CertificateGroup is added ... configuration. An UpdateTarget with UpdateType=INSERT is created for the new CertificateGroup . The Path is 'CertificateGroups.[n]' where n is the index in the list of CertificateGroups currently
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.2.5 CloseAndUpdateTrustList plus any updates and validates the new TrustList . The Purpose of the associated CertificateGroup determines the validation rules for Certificates placed in the TrustList . For ApplicationCertificateType , the Server shall
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.2.6 AddCertificateClient to add a single Certificate to the TrustList . The Purpose of the associated CertificateGroup determines the validation rules for the Certificate . For ApplicationCertificateType , the Server shall verify that
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.3.1 CertificateGroupTypeCertificateGroupType This ObjectType is used for Objects which represent CertificateGroups in the AddressSpace . A CertificateGroup is a context that contains a TrustList and one or more CertificateTypes that ... CertificateTypes and TrustLists managed by the Server . Typically, there is a mapping between a CertificateGroup in a Server and a CertificateGroup in the CertificateManager . The mechanisms for creating that mapping
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.3.2 GetRejectedListerrors but are not trusted. For PullManagement , this Method is not present on the CertificateGroup . For PushManagement , this Method shall be called from an authenticated SecureChannel and from a Client
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.3.3 CertificateGroupFolderTypePush Model for Global Certificate and TrustList Management The DefaultApplicationGroup Object represents the default CertificateGroup for Applications . It is used to access the default application TrustList and to define ... subtypes of CertificateType (see 7.8.4.1 and Table 99 ). The DefaultHttpsGroup Object represents the default CertificateGroup for HTTPS communication. It is used to access the default HTTPS TrustList and to define
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.3.4 CertificateGroupDataTypeCertificateGroupDataType This type is used to serialize a single CertificateGroup configuration. It is defined in Table 44 . This type is used as part of the ApplicationConfigurationDataType defined in 7.10.19 which ... Name of the record is the name portion of the BrowseName of the associated CertificateGroup Object in the AddressSpace . It may not be possible to delete CertificateGroups such as DefaultApplicationGroup
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.8.5.2 CloseAndUpdatecurrent state of the record does not allow the operation. For example, a CertificateGroup has Certificates assigned. Table 29 specifies the AddressSpace representation for the CloseAndUpdate Method . Table 63 - CloseAndUpdate
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.2 CertificateDirectoryTypeSubtype of the 2: DirectoryType defined in 6.5.3 . 0:Organizes Object 2:CertificateGroups 0:CertificateGroup FolderType Mandatory 0:HasComponent Method 2:StartSigningRequest Defined in 7.9.3 . Mandatory 0:HasComponent Method ... PullManagement Clients . These Clients use the NodeIds to relate their local configuration to the CertificateGroup in the CertificateManager . The StartSigningRequest Method is used to request a new a Certificate that
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.4 StartNewKeyPairRequestidentifier assigned to the application by the CertificateManager . CertificateGroupId The NodeId of the CertificateGroup which provides the context for the new request. If null the CertificateManager shall choose the DefaultApplicationGroup ... passed to the FinishRequest Method . The CertificateGroupId parameter allows the caller to specify a CertificateGroup that provides context for the request. If null the CertificateManager shall choose the DefaultApplicationGroup
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.7 GetCertificateGroupsCertificateGroupIds An identifier for the CertificateGroups assigned to the application. A CertificateGroup provides a TrustList and one or more CertificateTypes which may be assigned to an application. This Method shall
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.8 GetCertificatesGetCertificates Method returns the Certificates assigned to the application and associated with the CertificateGroup . This Method shall be called from an authenticated SecureChannel and from a Client that has access ... identifier assigned to the application by the GDS. CertificateGroupId An identifier for the CertificateGroup that the Certificates belong to. If null, the CertificateManager shall return the Certificates for all CertificateGroups
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.9 GetTrustListidentifier assigned to the application by the GDS. CertificateGroupId An identifier for a CertificateGroup that the application belongs to. If null, the CertificateManager shall return the TrustListId for a suitable
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.9.10 GetCertificateStatusapplication has to update its Certificate . If this Method is called for a CertificateGroup which the application does not belong to then the Method shall return UpdateRequired =TRUE. This Method ... ApplicationId The identifier assigned to the applicationby the GDS. CertificateGroupId The NodeId of the CertificateGroup which provides the context. If null the CertificateManager shall choose the DefaultApplicationGroup . CertificateTypeId The NodeId
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global ServicesSubtype of the 0: AuditUpdateMethodEventType defined in OPC 10000-5 . 0:HasProperty Variable 2:CertificateGroup 0:NodeId 0:PropertyType Mandatory 0:HasProperty Variable 2:CertificateType 0:NodeId 0:PropertyType Mandatory ... Properties of the AuditUpdateMethodEventType . Their semantic is defined in OPC 10000-5 . The CertificateGroup Property specifies the CertificateGroup that was affected by the update. The CertificateType Property specifies the type
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global ServicesSubtype of the 0: AuditUpdateMethodEventType defined in OPC 10000-5 . 0:HasProperty Variable 2:CertificateGroup 0:NodeId 0:PropertyType Mandatory 0:HasProperty Variable 2:CertificateType 0:NodeId 0:PropertyType Mandatory ... Properties of the AuditUpdateMethodEventType . Their semantic is defined in OPC 10000-5 . The CertificateGroup Property specifies the CertificateGroup that was affected by the update. The CertificateType Property specifies the type
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.5 UpdateCertificateoutside the Server and is updated with this Method . The Purpose of the associated CertificateGroup determines the validation rules for Certificate being updated. For ApplicationCertificateType , the Server shall verify ... shall be reported. The validation process requires that the TrustList associated with the CertificateGroup already contains the IssuerCertificates . Revocation checks may be done with CRLs in the TrustList or using
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.6 CreateSelfSignedCertificateCreateSelfSignedCertificate CreateSelfSignedCertificate Method creates a new self-signed Certificate and associates it with a CertificateGroup . This Method allows an administration Client to create a Certificate used by the Server ... Purpose of the CertificateGroup specifies what the Certificate is used for. For example, a CertificateGroup that contains ApplicationInstance Certificates would only contain Certificates that are valid ApplicationInstance Certificates as defined
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.7 DeleteCertificateDeleteCertificate DeleteCertificate Method a Certificate that is associated with a CertificateGroup . If no Certificate is assigned to the CertificateType slot then a Bad_InvalidState error is returned. If a transaction ... DeleteCertificate( [in] NodeId CertificateGroupId [in] NodeId CertificateTypeId ); Argument Description CertificateGroupId The identifier for the CertificateGroup . CertificateTypeId The CertificateType for the Certificate to be deleted. Method Result Codes (defined in Call
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.8 GetCertificatesGetCertificates The GetCertificates Method returns the Certificates assigned to CertificateTypes associated with a CertificateGroup . This Method shall be called from an authenticated SecureChannel and from a Client that has access ... CertificateGroupId [out] NodeId[] CertificateTypeIds [out] ByteString[] Certificates ); Argument Description CertificateGroupId The identifier for the CertificateGroup . CertificateTypeIds The CertificateTypes that currently have a Certificate assigned. The length of this list
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.10 CreateSigningRequestRegeneratePrivateKey [in] ByteString Nonce [out] ByteString CertificateRequest ); Argument Description CertificateGroupId The NodeId of the CertificateGroup Object which is affected by the request. If null the DefaultApplicationGroup is used. CertificateTypeId ... permitted types is specified by the CertificateTypes Property belonging to the CertificateGroup . SubjectName The subject name to use in the Certificate Request . If not specified the SubjectName from the current
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.17 TransactionDiagnosticsTypeincluded in the transaction. It is updated each time as soon as a CertificateGroup is added to the transaction.The Errors Property has a list of errors that occurred when
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.19 ApplicationConfigurationDataTypePort. Each ClientEndpoint has a unique combination of NetworkName and Port. At least one CertificateGroup linked to a ServerEndpoint (see 7.10.23 ) shall have a CertificateType slot compatible with the Server ... such slot exists the configuration update is rejected. The TrustList associated with that CertificateGroup shall trust the Client Certificate used for the current Session. Updates to the configuration are applied
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.20 ApplicationConfigurationFileTypeCertificateTypes Property is a list of CertificateTypeIds that may be used in a CertificateGroup (see 7.8.3.4 ). It shall have at least one element specified. The CertificateGroupPurposes Property is a list ... Purposes that may be used in a CertificateGroup (see 7.8.3.4 ). It shall have at least one element specified. The MaxEndpoints Property specifies the maximum total number of Endpoints ( Client plus
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.24 SecuritySettingsDataTypespecify the SecuritySettings for a Server Endpoint . It is defined in Table 114 . The CertificateGroup specifies one or more Certificates that are assigned to a Server . When generating EndpointDescriptions ... than None ) that are not valid for one of the Certificates associated with the CertificateGroup are ignored. If a SecurityPolicyUri is valid for more than one Certificate in the CertificateGroup
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.25 UserTokenSettingsDataTypeUserTokenSettingsDataType in the is used to configure how to validate UserIdentityTokens . If a CertificateGroup is specified it refers to the TrustList used to verify credentials by either verifying that ... using a Certificate in the TrustList to verify the Signature on an IssuedIdentityToken . The CertificateGroup is not specified for UserName or Anonymous TokenTypes . The KeyCredentialName is only specified for IssuedIdentityTokens
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services7.10.27 CertificateUpdatedAuditEventTypeSubtype of the 0: AuditUpdateMethodEventType defined in OPC 10000-5 . 0:HasProperty Variable 0:CertificateGroup 0:NodeId 0:PropertyType Mandatory 0:HasProperty Variable 0:CertificateType 0:NodeId 0:PropertyType Mandatory ... NodeId of the Object with the Method that triggered the Event . The CertificateGroup Property specifies the CertificateGroup that was affected by the update. The CertificateType Property specifies the type
-
OPC-10000-21 – OPC Unified Architecture - Part 21: Device Onboarding9.3.1 OverviewRegistrar when it authenticates a Device . The DefaultApplicationGroup Object is a well-known CertificateGroup that stores the Application Instance Certificate and TrustList for the DCA provided by the Registrar . This ... these cases, DCAs shall add a Reference from the ServerConfiguration CertificateGroups Folder to the CertificateGroup Object under the Application