Search
20 result(s) for SecurityGroups
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model4.5.3.2 Broker-lessthese are outside the scope of the OPC UA specification. The configuration of SecurityGroups requires careful consideration when deploying systems to ensure security. The model is illustrated in Figure
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub5.3.7 SecurityGroupgenerate and check signatures on a NetworkMessage . A Security Key Service (SKS) manages SecurityGroups and maintains a mapping between Roles and their access Permissions for a SecurityGroup . This mapping defines
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub5.4.5.2 SecurityGroup ManagementSecurityGroup Management The SKS is the entity with knowledge of SecurityGroups and it maintains a mapping between Roles and SecurityGroups . The related User Authorization model is defined
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub6.2.12.2 SecurityGroupDataTypeName of the SecurityGroup. SecurityGroupFolder String[] Optional path of the SecurityGroupFolders used to group SecurityGroups where each entry in the String array represents one level in a folder hierarchy
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub6.2.12.4 PubSubConfiguration2DataTypegroups or DataSetReaders. The general definition for the SecurityKeyServices parameter is in 6.2.5.4 . SecurityGroups SecurityGroupDataType[] The SecurityGroups contained in the configuration. The SecurityGroupDataType is defined in 6.2.12.2 . PubSubKeyPushTargets PubSubKeyPushTarget DataType
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub8.1 Overviewdefines the Method for pull access to security keys and the related management of SecurityGroups. This ObjectType is used for the PublishSubscribe Object if only the Security Key Service functionality ... PublishSubscribeType is used instead. A SecurityGroup manages keys used for securing PubSub NetworkMessages . The SecurityGroups are organized by the SecurityGroupFolderType and represented by instances of the SecurityGroupType . A PubSubKeyPushTarget
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSubGetSecurityKeys Defined in 8.3.2 . Optional HasComponent Method GetSecurityGroup Defined in 8.3.3 . Optional HasComponent Object SecurityGroups SecurityGroupFolderType Optional HasComponent Object KeyPushTargets PubSubKeyPushTargetFolderType Optional Conformance Units PubSub Model SKS The PubSubKeyServiceType ObjectType ... concrete type and can be used directly. The SecurityGroups folder organizes the Objects representing the SecurityGroup configuration. The KeyPushTargets folder organizes the Objects representing the PubSubKeyPushTarget configuration
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSubaccess the keys is different to the Permission necessary to modify the configuration of SecurityGroups . Table 213 - SecurityGroupType definition Attribute Value BrowseName SecurityGroupType IsAbstract False References NodeClass BrowseName DataType TypeDefinition
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSubused to build a tree of folder Objects used to organize the configured SecurityGroups . The SecurityGroup Objects are added as components to the instance of the SecurityGroupFolderType . A SecurityGroup Object
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub8.6.3 ConnectSecurityGroupsConnectSecurityGroups ( [in] NodeId[] SecurityGroupIds, [out] StatusCode[] ConnectResults ); Argument Description SecurityGroupIds The NodeIds of the SecurityGroups to connect to the PushTarget . ConnectResults The result codes for the SecurityGroups to connect. Method ... Result Codes ResultCode Description Bad_UserAccessDenied The Session user is not allowed to connect SecurityGroups to the push target. Bad_SecurityModeInsufficient The communication channel is not using signing. Operation Result
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSubshall stop using the push model to distribute the keys of those SecurityGroups to the PubSubKeyPushTarget . The Client shall be authorized to modify the configuration for the SKS functionality ... DisconnectSecurityGroups ( [in] NodeId[] SecurityGroupIds, [out] StatusCode[] DisconnectResults ); Argument Description SecurityGroupIds The NodeIds of the SecurityGroups to disconnect. DisconnectResults The result codes for the SecurityGroups to disconnect. Method Result Codes ResultCode
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub8.6.5 TriggerKeyUpdate MethodTriggerKeyUpdate Method This Method triggers a key update of all SecurityGroups related to the PubSubKeyPushTarget . The SKS shall push the new set of keys for all related SecurityGroups , even
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSubKnown SKS Roles BrowseName Suggested Permissions SecurityKeyServerAdmin This Role allows an administrator to manage SecurityGroups and PushTargets on a SKS. This includes executing methods related to management of SecurityGroups ... pull but it is expected that different custom Roles are used for different SecurityGroups . SecurityKeyServerPush This Role allows an SKS to push security keys to PubSub Applications . This includes executing
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub9.1.3.7.3 PubSubConfigurationRefDataTypethat is referenced. ElementIndex UInt16 Specifies the index into the DataSetWriters , DataSetReaders , PublishedDataSets , SubscribedDataSets , SecurityGroups or PubSubKeyPushTargets array of the PubSubConfiguration depending on the bits ReferenceWriter , ReferenceReader , ReferencePubDataset , ReferenceSubDataset , ReferenceSecurityGroup
-
OPC-10000-14 – OPC Unified Architecture - Part 14: PubSub9.1.12.1 PubSubCapabilitiesTypenumber of DataSetWriters in one WriterGroup . The MaxSecurityGroups Variable defines the maximum number of SecurityGroups that can be configured. A value of 0 indicates that the OPC UA Application forces ... limit on the number of SecurityGroups . The MaxPushTargets Variable defines the maximum number of PushTargets that can be configured. A value of 0 indicates that the OPC UA Application forces
-
OPC-10000-81 – OPC Unified Architecture - Part 81: UAFX Connecting Devices and Information Model6.7.3.2 Establishing Connectionsconfiguration, the ConnectionManager shall also call the SKS and add the appropriate configuration ( SecurityGroups and/or PushTargets ; see E.5 for examples). If a configuration entry is null or empty, the corresponding
-
OPC-10000-81 – OPC Unified Architecture - Part 81: UAFX Connecting Devices and Information Model6.7.3.3 Closing Connectionswere removed, the ConnectionManager shall also remove the appropriate configuration from the SKS ( SecurityGroups and/or PushTargets ; see E.5 for examples
-
OPC-10000-81 – OPC Unified Architecture - Part 81: UAFX Connecting Devices and Information ModelHasComponent Variable 4:SecurityKeyServer 4:SecurityKeyServerAddressDataType 4:SecurityKeyServerAddressType O 0:HasComponent Variable 4:SecurityGroups 0:SecurityGroupDataType[] 0:BaseDataVariableType O 0:HasComponent Variable 4:PubSubKeyPushTargets 0:PubSubKeyPushTargetDataType[] 0:BaseDataVariableType ... ConnectionManager itself if providing SKS functionality, or other SKS within the network. SecurityGroups and PubSubPushKeyTargets define the configuration information to be applied to the SKS for PubSub security configuration
-
OPC-10000-81 – OPC Unified Architecture - Part 81: UAFX Connecting Devices and Information ModelE.2.1 OverviewFigure E.6 as red boxes with straight lines; which is targeted for the SKS ( SecurityGroups and PubSubKeyPushTargets ), illustrated in Figure E.6 as green boxes with dashed lines; and information which ... AutomationComponent (see 6.2.4 ). This includes the communication model information targeted for the AutomationComponent (i.e., SecurityGroups and PubSubKeyPushTargets are omitted). If using PubSub , a specific sequence of calls could be required
-
OPC-10000-81 – OPC Unified Architecture - Part 81: UAFX Connecting Devices and Information ModelAddSecurityGroup and AddPushTarget Methods . Instead, it might use any internal method. The usage of SecurityGroups is defined by OPC 10000-14 as follows: The SKS is responsible for generating keys ... configured SecurityGroups . The SKS can expose the SecurityGroups in its Information Model . A Publisher uses the current key to sign or sign and encrypt NetworkMessages , and Subscriber(s) to authenticate