OPC UA uses X.509 certificates to authenticate applications (both client and server): each application holds its own certificate, and trust is established mutually through the exchange that happens during the SecureChannel handshake.
True
Each OPC UA application owns an Application Instance Certificate together with its private key. During the SecureChannel handshake the client presents its certificate, the server presents its own, and each side checks the other against its local Trust List (accepted certificates) and Rejected List (explicitly refused certificates). The first connection attempt from a new client typically fails with BadCertificateUntrusted; the administrator then moves the certificate from the Rejected to the Trusted folder and the second attempt succeeds. This two-way model means there is no central authority required for small deployments.
Always export the server certificate fingerprint from the engineering tool and verify it on the device front panel before approving trust: copy-pasting trust without checking the fingerprint defeats the whole mutual-authentication design.
OPC UA bank in preparation
The full OPC UA bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.
Join the waitlist →See the 9 other OPC UA practice questions
Related questions
- What is the complete format of an OPC UA NodeId?2. NodeIds · NodeId-Format
- An OPC UA Subscription groups several MonitoredItems and publishes value changes periodically (PublishingInterval typically 100-1000 ms); the server keeps a buffer of unacknowledged notifications for reliability.3. Services · Subscriptions
- Which Security Modes does an OPC UA SecureChannel support per the standard?4. Security · SecureChannel-Modi
- OPC UA Pub/Sub supports several transports: UDP multicast (lowest latency, machine-to-machine), MQTT (cloud-friendly via broker) and AMQP (enterprise messaging), making it adaptable to a wide range of use cases.9. Pub/Sub · Transport-Optionen
- OPC UA Pub/Sub supports two encodings: Binary (compact and fast, about 30% of the payload size of JSON) and JSON (human-readable, debug-friendly, easy to integrate with web and REST stacks). The choice depends on the performance versus interoperability trade-off.9. Pub/Sub · JSON- vs. Binär-Encoding