GDS CRL's renewals|OPC UA Standard|Forum|OPC Foundation

Avatar
Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
Lost password?
sp_Feed sp_PrintTopic sp_TopicIcon
GDS CRL's renewals
Avatar
Svein Folkeson
New Member
Members
Forum Posts: 1
Member Since:
11/20/2018
sp_UserOfflineSmall Offline
1
03/15/2023 - 07:33
sp_Permalink sp_Print

I have an infrastructure with an Offline CA server, CA server, more than 100 UA Servers and more than 100 UA Clients.

To keep track on expire dates for the Certificates I use information from the GDS Server.

How do I keep track on the next update for the Offline CA Crl and the CA Crl on every server and client. When the next update time has expired I get errors telling me that the Crl has expired.

I don't have access to the machines and folders where the Crl's are stored so I can't read them with an application to check for the expiration (i.e. next update) date.

Do you have any good suggestions for how to keep the Crl's up to date at any time?

I have also noticed that Kepware doesn't seem to have any Crl's. Is that correct?

Avatar
Randy Armstrong
Admin
Forum Posts: 1445
Member Since:
05/30/2017
sp_UserOfflineSmall Offline
2
03/15/2023 - 12:04
sp_Permalink sp_Print

If your applications are using Pull Management they must periodically connect to the GDS to see if there is an updated TrustList.

The GDS will have a TrustList object assigned to the application:

https://reference.opcfoundatio.....cs/7.8.2.1

The LastUpdateTime will tell the client that the TrustList (and any CRLs in it have changed).

You do not keep track of CRLs - you only care about the TrustList assigned to the application which will contain the latest CRLs that the application needs.

If your applications are using Push Management then the GDS connects to the application and provides an updated TrustList when it changes. The LastUpdateTime on the TrustList Object exposed by the application tells the GDS if the TrustList needs an update.

Forum Timezone: America/Phoenix
Most Users Ever Online: 510
Currently Online:
Guest(s) 10
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Forum Stats:
Groups: 2
Forums: 10
Topics: 1347
Posts: 4567