Configure OPC UA security policy and certificate-based mutual authentication between client and server

domain: iot · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Choose a security mode for the endpoint: None, Sign, or SignAndEncrypt — mode None is only valid when the SecurityPolicy is also None, and that combination should be disabled by default
  2. Select a shared SecurityPolicy, identified by a unique URI (e.g. http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256), that both client and server support; the policy defines the signing/encryption and key-derivation algorithms used
  3. Generate an Application Instance Certificate (X.509) for both the client and the server
  4. Add each peer's certificate (or its issuing CA) to the other side's Certificate Trust List (CTL) — an OPC UA application should reject connections from any application whose certificate is not trusted
  5. Open the SecureChannel: client and server exchange and validate certificates against their trust lists before a session is created, and the client verifies the endpoint URL matches the hostname in the server's certificate
  6. Maintain the trust list and certificate revocation list going forward, restricting write access to trusted admins, or use a Global Discovery Server (GDS) for automated certificate push/pull provisioning

Known gotchas

Related routes

Provision and rotate mutual-TLS client certificates for OCPP 2.0.1 Security Profile 3
openchargealliance.org · 5 steps · unrated
Run an OPA bundle server, configure OPA to poll it for policy bundles, and validate decision log and status plugin output
security/compliance · 5 steps · unrated
Authenticate to the ADP API using OAuth client_credentials flow with certificate-based mutual TLS
developers.adp.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans