Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

Requirements for Generating a Valid OPC UA Server Certificate

Geo SCADA Knowledge Base

Access vast amounts of technical know-how and pro tips from our community of Geo SCADA experts.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Geo SCADA Knowledge Base
  • Requirements for Generating a Valid OPC UA Server Certificate
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Labels
Top Labels
  • Alphabetical
  • database 32
  • Web Server and Client 31
  • WebX 19
  • Request Form 18
  • Lists, Events & Alarms 16
  • ViewX 15
  • Application Programming 12
  • Setup 12
  • Telemetry 8
  • Events & Alarms 7
  • Lists 7
  • Mimic Graphics 7
  • Downloads 6
  • Support 5
  • IoT 5
  • SCADA 5
  • Geo SCADA Expert 5
  • Drivers and Communications 4
  • Security 4
  • DNP 3 3
  • IEC 61131-3 Logic 3
  • Trends and Historian 2
  • Virtual ViewX 2
  • Geo Scada 1
  • ClearSCADA 1
  • Templates and Instances 1
  • Releases 1
  • Maps and GIS 1
  • Mobile 1
  • Architectures 1
  • Tools & Resources 1
  • Privacy Policy 1
  • OPC-UA 1
  • Previous
  • 1 of 4
  • Next
Latest Blog Posts
  • OPC UA - Driver and Server
  • Requirements for Generating a Valid OPC UA Server Certificate
  • Load Events Using LoadRecord and LoadRecords
  • Geo SCADA Embedded Component Licenses
  • Geo SCADA 2023 Known Issues

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
AdamWoodland
AdamWoodland Schneider Alumni (Retired)
Schneider Alumni (Retired)
‎2024-04-29 12:26 AM
0 Likes
0
1637
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

‎2024-04-29 12:26 AM

Requirements for Generating a Valid OPC UA Server Certificate

Originally published on Geo SCADA Knowledge Base by AdamWoodland | April 29, 2024 09:26 AM

Go: Home Back

Overview

Generation of a valid server certificate for an OPC UA server is a very similar to the process for generating a new certificate for a web servers, however the OPC UA certificate requires some additional information within the certificate signing request (CSR) to be included within the certificate "Alternative Name" section under URL. For general details on how to create the CSR using Windows Certificate Manager as a custom request, refer to third party websites such as https://knowledge.digicert.com/solution/generate-a-csr-via-mmc-certificate-snap-in-using-windows as relevant for your version of Windows.

 

Required Configuration

Within the CSR process when creating a custom request, while entering the certificate's properties under the alternative name section select URL and add "urn:server" where "server" is the machine's domain name and/or IP addresses that hosts the certificate. See below for an example request field (without all the other mandatory fields such as country, organisation, etc) of a server called "testserver" and an IP address of 192.168.0.1 with the mandatory URL fields. The URL entry fields do not need to match 1-to-1 with the configured common name (CN) or any IP addresses in the certificate, you should ensure that the URL fields include any access method that the OPC UA client will use so the certificate is valid, and this means you may need to add multiple URL entries.

 

urn.png

 

When the certificate is generated from the request and loaded back into Certificate Manager, it should now contain the necessary information allowing the certificate to be loaded into Geo SCADA as the OPC UA server certificate.

 

The generated certificate can also be used within IIS as a web site certificate, assuming the necessary fields are valid for that too.

 

For the client to trust the generated certificate ensure that the client also has the necessary root and intermediate CA certificates installed that were used to generate the server certificate.

 

Your organisation or the issuer of the server certificate may have specific guidance on what other fields are necessary to include within the CSR.

 

Additional Information

Generating the CSR via Certificate Manager's "Create Custom Request" should create a certificate with the necessary properties, on top of the URL info required above. However should the certificate still not be valid the following are the full requirements of the server certificate:

 

  • The certificate has a private key
  • The private key is exportable
  • The certificate's "Enhanced Key Usage" contains "Server Authentication"
  • The certificate contains a Subject Alternative Name
  • The Subject Alternative Name contains a URL of the current machine (e.g. it is expected that a URL similar to "URL=urn:testserver" is specified)
  • The certificate's Subject Key Identifier (SKI) and Authority Key Identifier (AKI) matches. For self-signed certificates AKI should be the same as its own SKI. Otherwise AKI should be the SKI of the issuer.


Go: Home Back

Author

Biography

AdamWoodland

Link copied. Please paste this link to share this article on your social media post.

  • Back to Blog
  • Newer Article
  • Older Article
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of