View Issue Details

IDProjectCategoryView StatusLast Update
000267310000-007: ProfilesSpecpublic2015-03-24 15:28
ReporterThomas Merk Assigned ToKarl Deiretsbacher  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version1.02 
Target Version1.03Fixed in Version1.03 
Summary0002673: Nano embedded server requires encryption
Description

The Nano Embedded Device Server Profile requires encryption since the Core Server Facet requires Username / Password authentication with encryption of UserIdentityToken in case of unencrypted messages.

Thus no full featured profile can be implemented without encryption.
Is this a desired behaviour?

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Karl Deiretsbacher

2014-08-19 15:34

developer   ~0005440

proposed for v1.03

Karl Deiretsbacher

2014-08-22 06:50

developer   ~0005460

This seems to be a mis-understanding.

The description of the Core Server Facet states:
"Server does not need to support encryption and signing of user identity tokens (This assumes the Server also supports a transport that provides security.)"

The transport that provides security is outside the scope of OPC UA.

Karl Deiretsbacher

2014-09-23 15:58

developer   ~0005501

Add text to explain that security shall be provided by a secure transport (like VPN) that is outside the scope of UA.

Karl Deiretsbacher

2014-09-24 11:35

developer   ~0005504

The description of the Core Server Facet has been enhanced. It now states:

The Core Server Facet does not require the encryption and signing of user identity tokens. This exception is made with the assumption that the OPC UA Server will use means outside the scope of OPC UA to secure the identity token so that it cannot be retrieved by sniffing the communication. One option would be a secure transport like a VPN.

Changed in version "OPC UA Part 7 - Profiles 1.04 Draft 01.docx"

Karl Deiretsbacher

2014-11-11 16:25

developer   ~0005604

reopened since we will change the resolution.
We will add text to the individual user tokens and nothing to the core server facet.

Karl Deiretsbacher

2014-11-25 17:15

developer   ~0005653

fixed in OPC UA Part 7 - Profiles 1.03 Draft 03.docx

Will be closed when the change has also been made in the database.

Jim Luth

2015-03-24 15:28

administrator   ~0005938

Agreed to changes in database.

Issue History

Date Modified Username Field Change
2013-11-13 10:49 Thomas Merk New Issue
2013-11-19 17:52 Jim Luth Status new => assigned
2013-11-19 17:52 Jim Luth Assigned To => Karl Deiretsbacher
2014-08-19 15:34 Karl Deiretsbacher Note Added: 0005440
2014-08-19 15:34 Karl Deiretsbacher Category (No Category) => Spec
2014-08-19 15:34 Karl Deiretsbacher Target Version => 1.03
2014-08-22 06:50 Karl Deiretsbacher Note Added: 0005460
2014-08-22 06:50 Karl Deiretsbacher Status assigned => resolved
2014-08-22 06:50 Karl Deiretsbacher Resolution open => no change required
2014-09-23 15:58 Karl Deiretsbacher Note Added: 0005501
2014-09-23 15:58 Karl Deiretsbacher Status resolved => feedback
2014-09-23 15:58 Karl Deiretsbacher Resolution no change required => reopened
2014-09-23 15:59 Karl Deiretsbacher Status feedback => assigned
2014-09-24 11:35 Karl Deiretsbacher Note Added: 0005504
2014-09-24 11:35 Karl Deiretsbacher Status assigned => resolved
2014-09-24 11:35 Karl Deiretsbacher Fixed in Version => 1.03
2014-09-24 11:35 Karl Deiretsbacher Resolution reopened => fixed
2014-11-11 16:25 Karl Deiretsbacher Note Added: 0005604
2014-11-11 16:25 Karl Deiretsbacher Status resolved => feedback
2014-11-11 16:25 Karl Deiretsbacher Resolution fixed => reopened
2014-11-11 16:25 Karl Deiretsbacher Status feedback => assigned
2014-11-25 17:15 Karl Deiretsbacher Note Added: 0005653
2014-11-25 17:15 Karl Deiretsbacher Status assigned => resolved
2014-11-25 17:15 Karl Deiretsbacher Resolution reopened => fixed
2015-03-24 15:28 Jim Luth Note Added: 0005938
2015-03-24 15:28 Jim Luth Status resolved => closed