logo

Notification

Icon
Error

Options
Go to last post Go to first unread
Offline dima_t  
#1 Posted : Thursday, June 8, 2017 10:47:23 AM(UTC)
dima_t

Rank: Member

Joined: 9/23/2015(UTC)
Posts: 29

Was thanked: 6 time(s) in 5 post(s)
Is there a way to use signed application certificate for client?
If I try to substitute default self-signed certificate with same certificate but signed by my CA it won't pass validation.
There is another thing I've tried, I've created my own V3 certificate and signed it, same story it didn't pass validation.

It worked well with ver 2 of UA client SDK.
thanks 1 user thanked dima_t for this useful post.
Offline Shubhi Gogna  
#2 Posted : Tuesday, June 13, 2017 3:48:46 AM(UTC)
Shubhi Gogna

Rank: Advanced Member

Joined: 3/23/2017(UTC)
Posts: 30

Thanks: 1 times
Was thanked: 15 time(s) in 15 post(s)
Hi Dima,

Thanks for reaching out to us.

Can you please provide more details about the problem.
What error are you receiving while validation. Are the certificates moving to Rejected folder. If yes, can you please move them manually to Trusted folder.

Regards,
Shubhi Gogna
thanks 1 user thanked Shubhi Gogna for this useful post.
Offline dima_t  
#3 Posted : Monday, June 19, 2017 7:06:47 AM(UTC)
dima_t

Rank: Member

Joined: 9/23/2015(UTC)
Posts: 29

Was thanked: 6 time(s) in 5 post(s)
You are right, it goes to rejected folder, and I have to move them manually one directory up.
What I want to achieve is to sign client application certificate myself (the one which client will generate on its own if it is missing) so I don't have to move them manually (on the server), due to lack of access to servers and I wish to use CA to authorize clients by signing client application certificates.
I was able to do that in version 2 of client SDK (I mean to substitute client application certificate with signed one).
As soon as I sign client application certificate myself it won't pass validation inside the client and client throws me OpcUa_BadInternalError 0x80020000 on initialization.
No issues with user certificate though, I can sign that one and server successfully validates it without moving anything to rejected directory because it is signed and server knows about CA.
I hope this makes sense.
thanks 1 user thanked dima_t for this useful post.
Offline Shubhi Gogna  
#4 Posted : Wednesday, June 21, 2017 4:42:08 AM(UTC)
Shubhi Gogna

Rank: Advanced Member

Joined: 3/23/2017(UTC)
Posts: 30

Thanks: 1 times
Was thanked: 15 time(s) in 15 post(s)
Hi Dima,

Sorry for my delayed response.
I will test it at my side and get back to you with my findings.

Regards,
Shubhi Gogna
thanks 1 user thanked Shubhi Gogna for this useful post.
Offline Shubhi Gogna  
#5 Posted : Wednesday, June 28, 2017 11:00:18 PM(UTC)
Shubhi Gogna

Rank: Advanced Member

Joined: 3/23/2017(UTC)
Posts: 30

Thanks: 1 times
Was thanked: 15 time(s) in 15 post(s)
Hi Dima,

We analyzed it further and found it is a issue at our end. We will fixing it.
Thanks for reporting this issue.

Regards,
Shubhi Gogna
thanks 1 user thanked Shubhi Gogna for this useful post.
Offline dima_t  
#6 Posted : Thursday, June 29, 2017 6:54:44 AM(UTC)
dima_t

Rank: Member

Joined: 9/23/2015(UTC)
Posts: 29

Was thanked: 6 time(s) in 5 post(s)
Thank you.
thanks 2 users thanked dima_t for this useful post.
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

Matrikon Subscribe  |   Matrikon Unsubscribe  |   Global Unsubscribe  |   Privacy Statement  |   Your Privacy Choices   |   Cookie Notice