Configuration and operation
4.8 Configuration of the CP in STEP 7 Professional
CP 443-1 OPC UA
Operating Instructions, 01/2017, C79000-G8976-C427-02
71
Here you set the options for checking the certificates of the communications partners for the
UA server function of the CP.
●
The CP always checks the certificate of the communications partner.
If the partner certificate is invalid or is not trustworthy, communication is aborted.
●
No strict certificate validation
If the option is enabled, the CP allows communication in the following situations:
– The IP address of the communications partner is not identical to the IP address in its
certificate.
Note: The OPC UA server does not check the IP address of the communications
partner (client).
– The use stored in the certificate (OPC UA client/server) differs from the function (OPC
UA client/server) of the communications partner.
– The current time on the CP is outside the period of validity of the partner certificate.
Regardless of these exceptions, to establish a connection, at least the following
requirements must be met:
– The application URI sent by the requesting client must match the URI of the server
application of the CP.
– If the partner certificate is not trustworthy, the CP must at least have stored a self-
signed certificate of the partner.
– If the partner certificate was issued by several CAs, all CAs must be saved in the
certificate store of the CP.
●
Do not check period of validity
If the option is enabled, the CP checks the certificate of the communications partner. The
CP also allows communication in the following situation:
– The current time on the CP is outside the period of validity of the partner certificate.
If none of the options is enabled, no certificates are checked.
Note the information in the section Handling certificates (Page 73) on the establishment of
communication.
OPC UA client
OPC UA client
●
Enable this option to enable the function of an OPC UA client on the CP.
You specify the remaining settings for the client function using the program blocks FB230 to
FB236 of the library "SIMATIC_NET_CP" see section Programming the OPC UA client
blocks (Page 79).