Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

M580 NUA100 OPC-UA Module

Modicon PAC Forum

A forum for topics related to the scope of Modicon PAC offers and ecosystem along the whole lifecycle: Modicon M580 and 340, EcoStruxure Control Expert, EcoStruxure Process Expert (Unity Pro) and more.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Industrial Automation
  • Modicon PAC Forum
  • M580 NUA100 OPC-UA Module
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
MatthewM
Lt. Commander MatthewM
8
RoozeeR
Lt. Commander RoozeeR Lt. Commander
7
Trinxs1
Lt. Commander Trinxs1 Lt. Commander
6
ciupol
Lieutenant ciupol
6
View All
Related Products
product field
Schneider Electric
Modicon M580

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Modicon PAC Forum
DStobie
Ensign DStobie
Ensign

Posted: ‎2023-02-16 06:49 PM

0 Likes
1
1269
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2023-02-16 06:49 PM

M580 NUA100 OPC-UA Module

When using the NUA0100 OPC-UA module in CA mode, the CSR generated by the module has three ip addresses in the Subject Alternative Name field.

1. Backplane IP

2. Control Port IP

3. Default IP based on Mac Address.

We've recently discovered by accident that if any of the IP addresses within the Subject Alternative Name field are incorrect, the module will drop the certificate on restart and revert to a self signed and provide you absolutely no indication of why it's done this (whilst politely refusing to go into run mode).

I expect that the "Security Export" of this module contains all the modules certificates and private key and is intended to allow someone to restore the configuration onto another card in the event of failure given that a password must be entered to secure the information in the export. 

If the OPC-UA module is being used in critical infrastructure, such as a water treatment plant and it fails out of hours, then i would expect an on-call maintenance technician to be able to arrive on site and replace it - especially if the module is being used as Schneider promote as the future planned link between GeoSCADA and M580 PACs. 

The problem is that the technician can't get the module going again. The replacement module has a different default IP address (because it has a different MAC address) and after he restores the configuration and restarts the module the certificate is dropped and the unit will refuse to go into run. 

This is pointless and means that a failed OPC module in CA mode can't be replaced out of hours without someone from ICT being woken up to generate a new certificate that matches the default IP address of the replacement unit.

It seems like an oversight and is a big enough operational risk that i would not recommend using the modules in CA mode anywhere where it forms part of a critical communication link. 

The module needs to be updated to remove the default IP address from the Subject Alternative Name - it doesn't need to be there, and nothing remotely is talking to it using this IP anyway.

 

 

 

 

 

Labels
  • Labels:
  • 02. Modicon M580 ePAC
  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic
Reply 1
FrancisBreysach
Ensign FrancisBreysach Ensign
Ensign

Posted: ‎2023-02-17 02:25 AM . Last Modified: ‎2023-02-17 02:34 AM

0 Likes
0
1258
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2023-02-17 02:25 AM . Last Modified: ‎2023-02-17 02:34 AM

Hello,

I saw that the Module Serial Number appears in the self-signed certificate.

So I had the same thought when the self-signed certificate is used when changing modules.

An Export/Import of the configuration will it be functional?

or a new exchange of certificates must be managed between Client and Server?

Thanks

Reply

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of