An OPC UA Global Discovery Server (GDS) manages a cross-LDS registry plus a Certificate Authority (CA) that issues client and server certificates across a multi-site infrastructure, dramatically simplifying OPC UA PKI management.
True
The GDS is the enterprise extension of the LDS. It aggregates LDS instances from multiple sites into a single inter-site view, embeds a Certificate Authority that signs application certificates, manages Trust List push to enrolled applications, and produces audit logs (who registers, which certificates are issued). The GDS is the right answer for large Industrie 4.0 estates with many sites and many servers. Common implementations include the Siemens GDS Push Server and the Unified Automation OPC UA Gateway with GDS option.
Plan the GDS before the first PLC goes live, not after: retrofitting central PKI onto an installed base of devices that already trust manually-exchanged certificates is significantly harder than provisioning them through a GDS from day one.
OPC UA bank in preparation
The full OPC UA bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.
Join the waitlist →See the 9 other OPC UA practice questions
Related questions
- OPC UA supports two communication patterns: Client/Server (the classic Request/Response model) and Pub/Sub (publish/subscribe over MQTT or UDP multicast/unicast), the latter introduced in version 1.04 to address Industrie 4.0 use cases.1. Architecture · Client/Server vs. Pub/Sub
- The OPC UA Address Space is a hierarchical structure of Nodes linked by typed References (HasComponent, HasProperty, HasTypeDefinition, etc.), exposed as a graph that clients can walk through the Browse service.1. Architecture · Address Space
- The main OPC UA Service Sets are: Discovery, SecureChannel, Session, NodeManagement, View, Query, Attribute (Read/Write), MonitoredItem, Subscription, and Method (Call).3. Services · Hauptsächliche Service Sets
- OPC UA separates Application authentication (the client/server X.509 certificate) from User authentication (the actual end-user login), which can be Anonymous, Username/Password, or User Certificate.4. Security · User-Authentifizierung
- PA-DIM (Process Automation Device Information Model) is an OPC UA Companion Specification for process transmitters (temperature, pressure, flow, level), standardising 70+ parameters that are read identically on Endress+Hauser, Yokogawa, Siemens and ABB devices.6. Companion Specs · PA-DIM