Configure certificate user login

Configure trusted X.509 user certificates for OPC UA certificate user login.
Obtain the intended X.509 user certificates.
The application transport trust store at
PKI/Trusted/Certs
authorizes clients to open a SecureChannel. The user identity trust store at
PKI/User/Trusted/Certs
authorizes OPC UA certificate user login.
Certificates trusted for application transport are not automatically accepted as user identity credentials.
  1. In the project files, open
    PKI/User/Trusted/Certs
    .
  2. Copy the intended X.509 user certificates to
    PKI/User/Trusted/Certs
    .
  3. If the user certificates are issued by a CA, copy the CA certificates to
    PKI/User/Issuers/Certs
    .
The OPC UA server authorizes certificate user login for the trusted user certificates.
IMPORTANT: Certificate authentication for built-in Root and RootUserType users is blocked by design. Password-based login is unaffected.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal