DCOM hardening: impact on local client-server communication|Classic OPC: DA, A&E, HDA, XML-DA, etc.|Forum|OPC Foundation

Avatar
Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
Lost password?
sp_Feed sp_PrintTopic sp_TopicIcon
DCOM hardening: impact on local client-server communication
Avatar
Frank Zettier
New Member
Members
Forum Posts: 2
Member Since:
08/23/2022
sp_UserOfflineSmall Offline
1
09/12/2022 - 06:55
sp_Permalink sp_Print

Hello everyone,

I´m new to OPC communication and since this dcom hardening patch affected my company in July 2022, I´m working on updating to  OPC UA. At this time the registry entry keeps data flowing. We´re using some old Honewell software, which can only use OPC DA/HDA.

So my question is: do I have to update to OPC UA on a machine, where an OPC DA server and also the Honeywell software (with an integrated OPC DA client) are installed? So the OPC DA server-client connection is on the same machine. Does this scenario still work after MS has delivered the final patch (14.03.2023)?

Best regards for any information,

Frank

Avatar
Randy Armstrong
Admin
Forum Posts: 1564
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
2
09/12/2022 - 15:16
sp_Permalink sp_Print

It should work without changes for localhost connections but that is not a guarantee.

You need to test.

Avatar
Frank Zettier
New Member
Members
Forum Posts: 2
Member Since:
08/23/2022
sp_UserOfflineSmall Offline
3
09/15/2022 - 03:13
sp_Permalink sp_Print

Hi Randy,

thank´s a lot for your quick reply. I also checked some youtube videos from Rockwell and they say, that local OCP DA Server connections will keep working.

One more question regarding testing OPC hardening impacts:

Is it enough to change the registry value to "1" in  "Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RequireIntegrityActivationAuthenticationLevel" to enable the hardening or is anything else required?

 

best regards,

Frank

Avatar
Randy Armstrong
Admin
Forum Posts: 1564
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
4
09/15/2022 - 14:02
sp_Permalink sp_Print

Theoretically that should be enough but others with more experience testing legacy DCOM based software may have something to add.

Forum Timezone: America/Phoenix
Most Users Ever Online: 510
Currently Online:
Guest(s) 47
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Forum Stats:
Groups: 2
Forums: 10
Topics: 1435
Posts: 4855