Self Signed Certificate - Expiry|OPC UA Implementation: Stacks, Tools, and Samples|Forum|OPC Foundation

Avatar
Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
Lost password?
sp_Feed sp_PrintTopic sp_TopicIcon
Self Signed Certificate - Expiry
Avatar
Vinod Pydi
Member
Members
Forum Posts: 16
Member Since:
12/15/2020
sp_UserOfflineSmall Offline
1
11/15/2021 - 03:08
sp_Permalink sp_Print

Hi, 

We have OPC UA , all of which have self-signed certificates. When we choose Sign&Encrypt Security Mode, the self-signed cert is presented and we have the option to accept once or accept permanently. When we accept permanently, the cert is stored in the trusted certs folder.

Now, my understanding is that this cert is the authentication root for all further communication with this device. Meaning, for all further communications, the cert from the device is checked if present in the trusted certs folder and validated. If the certificate expires after say 1 year, What is the behavior here? Would an exception be thrown that communication failed? Or would the user be prompted again to accept the certificate? If so, when the cert is accepted would the expired cert in the trusted certs folder be replaced by the new cert? Kindly clarify

 

Regards,

Vinod Pydi

Avatar
Randy Armstrong
Admin
Forum Posts: 1451
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
2
11/15/2021 - 04:19
sp_Permalink sp_Print

Certificates must pass all validation checks even if they are a trusted root.

i.e. expiry, revocation (non-self signed), signature, etc.

The verification is done each time a secure channel is created or renewed.

Avatar
Vinod Pydi
Member
Members
Forum Posts: 16
Member Since:
12/15/2020
sp_UserOfflineSmall Offline
3
11/15/2021 - 04:22
sp_Permalink sp_Print

Hi Randy, Thanks for your quick reply. So you mean the stack will take care of the verification part. ?

Avatar
Randy Armstrong
Admin
Forum Posts: 1451
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
4
11/15/2021 - 04:41
sp_Permalink sp_Print

Yes a stack should do that but you need to check to make sure your stack does.

Avatar
Vinod Pydi
Member
Members
Forum Posts: 16
Member Since:
12/15/2020
sp_UserOfflineSmall Offline
5
11/15/2021 - 04:46
sp_Permalink sp_Print

Ok, Thanks Randy Smile

Forum Timezone: America/Phoenix
Most Users Ever Online: 510
Currently Online:
Guest(s) 13
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Forum Stats:
Groups: 2
Forums: 10
Topics: 1351
Posts: 4579