Usage of Insucure cryptographic algorithms in opc-ua-stack-1.4.1-224.jar|OPC UA Implementation: Stacks, Tools, and Samples|Forum|OPC Foundation

Avatar
Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
Lost password?
sp_Feed sp_PrintTopic sp_TopicIcon
Usage of Insucure cryptographic algorithms in opc-ua-stack-1.4.1-224.jar
Avatar
Sasidhar Grandhe
Member
Members
Forum Posts: 4
Member Since:
08/19/2019
sp_UserOfflineSmall Offline
1
08/19/2019 - 22:55
sp_Permalink sp_Print

Some of the functions in opc-ua-stack-1.4.1-224.jar has usage of MD5 and SHA1 algorithms which are no longer considered sufficiently secure. We are using IBM App scan security tool to scan our product which results high severity issues with these algorithms.

Avatar
Randy Armstrong
Admin
Forum Posts: 1564
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
2
08/20/2019 - 16:14
sp_Permalink sp_Print

Where did you get that file from?

Avatar
Sasidhar Grandhe
Member
Members
Forum Posts: 4
Member Since:
08/19/2019
sp_UserOfflineSmall Offline
3
08/20/2019 - 22:45
sp_Permalink sp_Print

We got that jar file from GitHub, here is the link

https://github.com/OPCFoundati.....y/releases

Thanks.

Avatar
Randy Armstrong
Admin
Forum Posts: 1564
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
4
08/21/2019 - 10:36
sp_Permalink sp_Print

I have updated the documentation to indicate that they should not be used.

I will check to see if they should be pulled down entirely.

If you are looking for Java support I suggest:

https://github.com/eclipse/milo

or

https://www.prosysopc.com/prod.....-java-sdk/

Forum Timezone: America/Phoenix
Most Users Ever Online: 510
Currently Online:
Guest(s) 22
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Forum Stats:
Groups: 2
Forums: 10
Topics: 1435
Posts: 4855