Transcription of OPC UA Configuration Manager - Kepware
1 OPC UA Configuration Manager 2021 PTC Inc. All Rights Reser ved. OPCUAC onfigur ationM anager Table of ContentsOPC UA Configur ation M anager 1 Table of Contents2 OPC UA Conf igurat ion Manager4 Overview4 OPC UA Configur ation M anager 5 Project Propert ies OPC UA5 Server Endpoint s7 Trust ed Client s9 Discovery Servers10 Trust ed Servers10 Inst ance Cert if icat es12 OPC UA Tutor ial15 Connection Examples25Tr oubleshooting Tips27 Unable t o connect t o t he UA server when t rying t o import it ems in t he Device Propert ies dia-log27 Unable t o see t he UA server when at t empt ing t o browse f rom t he UA client 27 The t arget comput er running t he UA server is not shown in t he net work browse f rom t he UA client 28 Unable t o connect t o t he UA server via t he
2 Correct Endpoint URL28 Connect ion at t empt s t o t he UA server require aut hent icat ion (Username and Password)29 Cannot ping a rout er t hat uses port f orwarding t o send request s t o t he UA server29No OPC UA Specif ic Error Messages are Post ed t o t he Event Log29 Event Log M essages30 Account '<nam e>' does not have per m ission to r un this application. Contact the system adm in-istr ator .30 The UA Ser ver cer tificate has been r eissued. UA clients m ust tr ust the new cer tificate to UA Client Dr iver cer tificate has been r eissued. UA ser ver s m ust tr ust the new cer tificate for the client dr iver to UA Client cer tificate '<client nam e>' has been r ejected. The ser ver cannot accept connections fr om the UA Client cer tificate '<client nam e>' has been tr usted.
3 The ser ver can accept connections fr om the UA Ser ver cer tificate '<ser ver nam e>' has been r ejected. The UA Client Dr iver cannot con-nect to the ser ver .30 The UA Ser ver cer tificate '<ser ver nam e>' has been tr usted. The UA Client Dr iver can connect to f igu rat ion M an agerthe ser ver .The UA Ser ver cer tificate '<ser ver nam e>' has been added to Tr usted Ser ver s. The UA Client Dr iver can now connect to the ser ver .31 The UA Client cer tificate '<client nam e>' has been added to Tr usted clients . The UA Ser ver can now accept connections fr om the UA Client cer tificate '<client nam e>' has been r em oved fr om Tr usted clients . The UA Ser ver cannot accept connections fr om the UA Ser ver cer tificate '<ser ver nam e>' has been r em oved fr om Tr usted Ser ver s.
4 The UA Cli-ent Dr iver cannot connect to the ser ver .31 The endpoint '<ur l>' has been added to the UA Ser ver .31 The endpoint '<ur l>' has been r em oved fr om the UA Ser ver .31 The UA Discover y Ser ver '<ser ver nam e>' has been added. The UA Ser ver endpoints can now r egister with this UA Discover y Ser ver .31 The UA Discover y Ser ver '<ser ver nam e>' has been r em oved. The UA Ser ver endpoints can no longer r egister with this UA Discover y Ser ver .31 The endpoint '<ur l>' has been UA Client Dr iver cer tificate has been im por ted. UA ser ver s m ust tr ust the new cer tificate for the client dr iver to UA Ser ver cer tificate has been im por ted. UA clients m ust tr ust the new cer tificate to endpoint '<ur l>' has been Trust ed Client 32 Remove Trust ed Client 32 Reject Trust ed Client 32 Trust Trust ed Client 32 Add Trust ed Server32 Remove Trust ed Server32 Reject Trust ed Server33 Trust Trust ed Server33 Add Endpoint 33 Enable an Endpoint 33 Disable an Endpoint 33 Remove Endpoint 33 Add Discovery Server33 Remove Discovery Server33 Reissue Client Cert if icat e33 Reissue Server Cert if icat e33 Index34 ationM anager OPC UA Configurat ion M anagerHelp ver sion CON TEN TS OverviewWhat is OPC Unified Ar chitectur e and how is it used?
5 OPC UA Configurat ion M anagerWher e can I find infor m ation on the tabs in the OPC UA Configur ation M anager ? OPC UA Tut orialWher e can I find a tutor ial on how to im plem ent OPC UA? Connect ion Exam plesWher e can I find exam ples of connections and infor m ation on the best OPC UA pr actices? Troubleshoot ing TipsWher e can I find descr iptions of com m on tr oubleshooting pr oblem s? Event Log M essagesWhat m essages does the Event Log pr oduce? Overview OPC Unified Ar chitectur e (UA) is an open standar d cr eated by the OPC Foundation with help fr om dozens of m em ber or ganizations. Although UA intends to pr ovide a platfor m independent inter oper ability standar d (in or der to m ove away fr om M icr osoft COM ) it is not a r eplacem ent for OPC Data Access (DA) technologies.
6 For m ost industr ial applications, UA will com plem ent or enhance an existing DA ar chitectur e. It will not be a system -wide r eplacem ent. OPC UA com plem ents OPC DA infr astr uctur es in the following ways: lIt offer s a secur e m ethod of client-to-ser ver connectivity without depending on M icr osoft DCOM and has the ability to connect secur ely thr ough fir ewalls and over VPN connections. For user s connecting to r em ote com puter s within the cor por ate networ k (inside the fir ewall) on a dom ain, an OPC DA and DCOM connection m ay be satisfactor y. lIt pr ovides an additional way to shar e factor y floor data to business system s (shop-floor to top-floor ). OPC UA can aggr egate data fr om m ultiple OPC DA sour ces into non-industr ial system s.
7 For the m ajor ity of user applications, the m ost r elevant com ponents of the UA standar d ar e as follows: lSecur e connections thr ough tr usted cer tificates for client and ser ver endpoints. lRobust item subscr iption m odel to pr ovide efficient data updates between clients and ser ver s. lAn enhanced m ethod of discover ing available infor m ation fr om par ticipating UA ser ver s. f igu rat ion M an agerOPC UA Configurat ion M anagerThe OPC UA Configur ation M anager assists user s in adm inister ing the UA ser ver configur ation settings. OPC UA's secur ity r equir es that all endpoints par ticipating in UA com m unication do so over a secur e con-nection. To com ply with this secur ity r equir em ent, each UA ser ver instance and UA client instance m ust pr ovide a tr usted cer tificate to identify itself.
8 These cer tificates m ay be self-signed. As such, they m ust be added to a local tr usted cer tificate stor e on both the ser ver and client nodes by a user with adm inistr ator pr ivileges befor e any secur e UA client / ser ver connections m ay be attem pted. The OPC UA Configur ation M anager is a user -fr iendly inter face thr ough which the cer tificate exchange m ay be per for m ed. For mor e infor mation on a specific OPC UA Configur ation Manager pr oper ty, select a link fr om the list below. Server Endpoint sTrust ed Client s Discovery ServersTrust ed ServersInst ance Cert ificat es Project Propert ies OPC UA OPC Unified Ar chitectur e (UA) pr ovides a platfor m independent inter oper ability standar d.
9 It is not a r eplace-m ent for OPC Data Access (DA) technologies: for m ost industr ial applications, UA com plem ents or enhances an existing DA ar chitectur e. The OPC UA Pr oject Pr oper ties gr oup displays the cur r ent OPC UA settings in the ser ver . N ot e: To change a setting, click in the specific pr oper ty's second colum n. This invokes a dr op-down m enu that displays the options available. Ser ver Inter face Enable: When enabled, the UA ser ver inter face is initialized and accepts client connections. When disabled, the r em aining pr oper ties on this page ar e ationM anager Log diagnost ics: When enabled, OPC UA stack diagnostics ar e logged to the OPC Diagnostics Viewer . This should only be enabled for tr oubleshooting pur poses.
10 Client Sessions Allow anonym ous login: This pr oper ty specifies whether or not a user nam e and passwor d ar e r equir ed to establish a connection. For secur ity, the default setting is No to disallow anonym ous access and r equir e cr e-dentials to log in. N ot e: If this setting is disabled, user s cannot login as the default user in the User M anager . User s can login as the Adm inistr ator pr ovided that a passwor d is set in the User M anager and is used to : Additional user s m ay be configur ed to access data without all the per m issions associated with the adm inistr ator account. When the client supplies a passwor d on connect, the ser ver decr ypts the passwor d using the encr yption algor ithm defined by the secur ity policy of the endpoint, then uses it to login.