Siemens SIMATIC S7-1500 Function Manual page 189

Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

OPC UA communication
9.3 Using the S7-1500 as an OPC UA server
Configuring security settings of the server
The figure below shows the available server security settings for signing and encrypting
messages.
Figure 9-21
Configuring security settings of the server
By default, a server certificate is created that uses SHA256 signing. The following security
policies are enabled:
● None
Unsecured end point
Note
Disabling security policies you do not want
If you have enabled all security policies in the secure channel settings of the S7-1500
OPC UA server (default setting) – thus, also the end point "None" (no security) –
unsecured data traffic (neither signed nor encrypted) between the server and client is
also possible. The identity of the client remains unknown with "No security". Each OPC
UA client can then connect to the server irrespective of any subsequent security settings.
When configuring the OPC UA server, make sure that only security policies that are
compatible with the security concept of your machine or plant are selected. All other
security policies should be disabled.
Recommendation: If possible, use the setting "Basic256Sha256".
● Basic128Rsa15 -Sign
Insecure end point, supports a series of algorithms that use the hash algorithm RSA15
and 128-bit encryption.
This endpoint protects the integrity of the data through signing.
188
Function Manual, 11/2019, A5E03735815-AH
Communication

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents