OPC UA security policy
Manage connections between
OPC UA
servers, OPC UA
clients, and other components of your system policy
model.
TIP:
You must manually copy certificates to OPC UA client certificates if you:
- Generate and deploy an OPC UA server certificate inFactoryTalk Policy Managerand connect with the OPC UA server through a third-party OPC UA client application.
- If you use a third-party OPC UA server that does not support UA Part 12 Discovery and Global Services.
OPC UA servers
In
FactoryTalk Policy Manager
, OPC UA
servers are device
types, which you can add to the policy model and use as conduit endpoints. You can also
import certificates of OPC UA
servers. The certificates are exported to
C:\ProgramData\Rockwell Automation\FactoryTalk System Services\OPC UA Deployments
FactoryTalk® Linx™ Gateway
devices may support multiple endpoint URLs exposed by a single OPC UA
local discovery service. This enables you to configure
specific entry points to OPC UA
servers. You must configure
connections between OPC UA
servers and OPC UA
clients in FactoryTalk Policy Manager
.For more information about
FactoryTalk Linx Gateway
, see:- For more information, see FactoryTalk Linx Gateway Getting Results Guide, publication FTLG-GR001H-EN.
OPC UA
servers support these authentication methods: - Certificate
- Authenticate with an X.509 certificate granted by a trusted certificate authority.
- Username and password
- Authenticate with a username and password or as an anonymous user.
Endpoint Security Policy | Message security mode | Endpoint security level |
|---|---|---|
None- None | None | Low security |
Basic128Rsa15 | Sign | |
Basic128Rsa15 | Sign & Encrypt | |
Basic256 | Sign | |
Basic256 | Sign & Encrypt | |
Aes128Sha256RsaOaep | Sign | Medium security |
Aes128Sha256RsaOaep | Sign & Encrypt | |
Basic256Sha256 | Sign | High security |
Basic256Sha256 | Sign & Encrypt | |
Aes256Sha256RsaPss | Sign | |
Aes256Sha256RsaPss | Sign & Encrypt |
TIP:
Rockwell Automation
recommends setting message security mode to Sign
& Encrypt.Each
OPC UA
server has its own trust list and admin list.
If you add an OPC UA
server to a zone for the first time
and deploy the policy model configuration, the zone trust list and admin list overwrites the
OPC UA
server trust list and admin list. Consecutive
deployments merge the OPC UA
server and zone trust lists
and admin lists.For more information about
OPC UA
server properties, see
Device properties.OPC UA clients
In
FactoryTalk Policy Manager
, you can add OPC UA
clients
to the policy model and use as them conduit endpoints. You can also import and export
certificates of OPC UA
clients. The certificates are exported to
C:\ProgramData\Rockwell Automation\FactoryTalk System Services\OPC UA Deployments
IMPORTANT:
If you export
OPC UA
certificates or
CSRs from an OPC UA
device and the security policy model
contains both a certificate and a CSR, only the certificate is exported.OPC UA
clients may support these authentication methods:
- Certificate
- Authenticate with an X.509 certificate granted by a trusted certificate authority.
- Username and password
- Authenticate with a username and password or as an anonymous user.
OPC UA security policy in zones and conduits
Zones and conduits follow these non-editable
OPC UA security policy
settings:
- OPC UAclients trustOPC UAservers based on certificates
- OPC UAservers do not trustOPC UAservers
- OPC UAclients do not trustOPC UAclients
Conduits with OPC UA endpoints
With
OPC UA
endpoints, you can create these conduits:
Endpoint 1 | Endpoint 2 |
|---|---|
Zone | Zone |
Zone | OPC UA server |
Zone | OPC UA client |
Zone | Range |
OPC UA client | OPC UA server |
Conduits must follow these rules:
- Conduits cannot be duplicated, each combination of endpoints must be unique.
- One of the endpoints must beCIP SecurityorOPC UA security policycapable.
- If one endpoint is a zone, the other endpoint cannot be a device within that zone.
- Devices not assigned to any zone or onboarding devices cannot be used as endpoints.
Compatibility
OPC UA security policy
features work with these Rockwell Automation
product families:
- ControlLogix®5580 controllers firmware revision 36.00 or later
- GuardLogix®5580 controllers firmware revision 36.00 or later
- ControlLogix®5590 controllers firmware revision 38.00 or later
- CompactLogix™5380 controllers firmware revision 36.00 or later
- Compact GuardLogix®5380 controllers firmware revision 36.00 or later
- ControlLogix®Process controllers firmware revision 36.00 or later
- CompactLogix™Process controllers firmware revision 36.00 or later
- FactoryTalk® Linx™ Gatewayfirmware revision 6.60 or later
TIP:
OPC UA security policy
features do not
work with:
- ControlLogix®andControlLogix®Process L81 controllers
- CompactLogix™and CompactGuardLogix®L306 controllers
- RedundantControlLogix®andGuardLogix®controllers
Provide Feedback