View Issue Details

IDProjectCategoryView StatusLast Update
000714610000-006: MappingsSpecpublic2021-08-31 16:55
ReporterThilo Bellinger Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityN/A
Status closedResolutionfixed 
Summary0007146: Recommend certificate chains for GetEndpoints
Description

"Part 6 6.2.3 Certificate Chains" describes that certificate chains can be used for

  • SecureChannel negotiation
  • CreateSession/ActivateSession handshake.

I recommend to state also the EndpointDescriptions for the GetEndpoints service as this is the usual way to get a yet unknown certificate.
If a GetEndpoints service returns only the leaf certificate then it is likely that the client cannot validate the server certificate before trying to open the SecureChannel, thus the procedure to create a new connection is likely to fail due to unexpected reasons.

Chains are already implicitly allowed for the EndpointDescriptions as in "All OPC UA applications shall accept partial or complete chains in any field that contains a DER encoded Certificate", but I would state the GetEndpointsService explicitly, similar as for SecureChannel, CreateSession and ActivateSession.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Randy Armstrong

2021-08-18 09:31

administrator   ~0014761

The text already says:

All OPC UA applications shall accept partial or complete chains in any field that contains a DER encoded Certificate.

So there is no change in requirequirements.

Added GetEndpoints to the list of examples in 1.05.1 Draft 3,

Jim Luth

2021-08-31 16:55

administrator   ~0014796

Agreed to changes in 1.05.01 Draft 4.

Issue History

Date Modified Username Field Change
2021-07-28 14:34 Thilo Bellinger New Issue
2021-08-18 09:31 Randy Armstrong Assigned To => Randy Armstrong
2021-08-18 09:31 Randy Armstrong Status new => resolved
2021-08-18 09:31 Randy Armstrong Resolution open => fixed
2021-08-18 09:31 Randy Armstrong Note Added: 0014761
2021-08-31 16:55 Jim Luth Status resolved => closed
2021-08-31 16:55 Jim Luth Note Added: 0014796