Certificategroups In The Address Model - Siemens SIMATIC ET 200AL System Manual

Distributed i/o system
Hide thumbs Also See for SIMATIC ET 200AL:
Table of Contents

Advertisement

9.2.7.6

CertificateGroups in the address model

Certificates and trust lists for the OPC UA server that can be updated during runtime are
located in the address model in the "CertificateGroups" object - for the OPC UA server of the
S7-1500 CPU there is exactly one certificate group called "OpcUaServerGroup".
CertificateGroup in the address model
The following figure shows the structure of the "CertificateGroups" object below the
"ServerConfiguration" node.
You can change the Display Name of the "OpcUaServerGroup" group in STEP 7 (TIA Portal):
1. In the Inspector window (CPU properties), go to the "OPC UA > Server > Certificates" area.
2. Select the option "Use certificates managed by certificate management server during
runtime".
3. Change the group name (DisplayName) of the certificate group in the table below. 1-64
characters in 7-bit ASCII format are permitted.
"CertificateTypes" node
The "CertificateTypes" variable specifies the NodeIds of the certificate types that are assigned
to the server application.
Currently, only "RsaSha256ApplicationCertifcateType" is supported.
"TrustList" node
The node for the trust list object (TrustList file) defines an OPC UA file type (Binary encoded
stream) that contains information on the certificates and CRLs that can be read and updated
in the "pki store\trusted/issuer" directory of the Memory Card. This node provides methods
and attributes that make reading and updating possible.
The node is an instance of the OPC UA data type "TrustListDataType" with the following
structure:
Parameter
specifiedLists
trustedCertificates
trustedCrls
issuerCertificates
issuerCrls
Communication
Function Manual, 05/2021, A5E03735815-AJ
Data type
Description
TrustListsMasks
Bit mask that shows which lists contain infor-
mation.
ByteStrings
List of the trusted application certificates and
CA certificates.
ByteStrings
CRLs for the certificates in the "trustedCertifi-
cates" list.
ByteStrings
List of the CA certificates that are necessary for
validating the CA-signed certificates.
ByteStrings
CRLs of the CA certificates in the "issuerCertifi-
cates" list.
OPC UA communication
9.2 Security at OPC UA
199

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents