Configure certificate user login
Configure trusted X.509 user certificates for OPC UA certificate user login.
Obtain the intended X.509 user certificates.
The application transport trust store at
PKI/Trusted/Certs
authorizes clients to open a SecureChannel. The user identity trust store at PKI/User/Trusted/Certs
authorizes OPC UA certificate user login.Certificates trusted for application transport are not automatically accepted as user identity credentials.
- In the project files, openPKI/User/Trusted/Certs.
- Copy the intended X.509 user certificates toPKI/User/Trusted/Certs.
- If the user certificates are issued by a CA, copy the CA certificates toPKI/User/Issuers/Certs.
The OPC UA server authorizes certificate user login for the trusted user certificates.
IMPORTANT:
Certificate authentication for built-in Root and RootUserType users is blocked by design. Password-based login is unaffected.
Provide Feedback