The PolicyId and UserTokenType of the identityToken shall match one of the elements of the UserTokenPolicies Property. If the identityToken is not provided the Server should use the ApplicationInstanceCertificate and/or the UserIdentityToken provided for the Session (or the request if using a Session-less Method Call) to determine privileges.
If the associated UserTokenPolicy provides a SecurityPolicyUri, then the identityToken is encrypted and digitally signed using the format defined for UserIdentityToken secrets in OPC 10000-4.
For UserNameIdentityTokens the secret is the password and the signature is created with the Client ApplicationInstanceCertificate. The signed and encrypted secret is passed in the password field.
For X.509 v3IdentityTokens the secret is null and signature is created with the key associated with user Certificate. The signed and encrypted secret is passed in the certificateData field.
For IssuedIdentityTokens the secret is the token and the signature is created with the key associated a user Certificate or the Client ApplicationInstanceCertificate. The signed and encrypted secret is passed in the tokenData field.
The Server shall check the signingTime in against the current system clock. The Server shall reject the request if the signingTime is outside of a configurable range. A suitable default value is 5 minutes. The permitted clock skew is a Server configuration parameter.
This Method requires an encrypted channel and that the Client provides credentials with administrative rights for the application which is having the credentials revoked.
RequestAccessToken ( [in] UserIdentityToken identityToken, [in] String resourceId, [out] String accessToken );
|identityToken||The identity used to authorize the Access Token request.|
|resourceId||The identifier for the Resource that the Access Token is used to access.
This is usually the ApplicationUri for a Server.
|accessToken||The Access Token granted to the application.|
Method Result Codes (defined in Call Service)
|Bad_IdentityTokenInvalid||The identityToken does not match one of the allowed UserTokenPolicies.|
|Bad_IdentityTokenRejected||The identityToken was rejected.|
|Bad_NotFound||The resourceId is not known to the Server.|
|Bad_UserAccessDenied||The current user does not have the rights required.|
Table 63 specifies the AddressSpace representation for the RequestAccessToken Method.
Table 63 – RequestAccessToken Method AddressSpace Definition