EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  <20242025  Index 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  <20242025 
<== Date ==> <== Thread ==>

Subject: Re: OPCUA SSL problem
From: Ralph Lange via Tech-talk <tech-talk at aps.anl.gov>
To: EPICS Tech Talk <tech-talk at aps.anl.gov>
Date: Fri, 4 Oct 2024 12:57:42 +0200
Hi Karel,

The low-level client, Open62541 in your case, indeed handles most of the dealing with OpenSSL for the Secure OPC UA connections.

Hmmm... more things you could try:
  • In your container, install the evaluation bundle of the UA SDK. (The evaluation bundle has full features, just limited to one hour of runtime.) Build the OPCUA Device Support against that.
    The two IOC binaries (linked against Open62541 and UASDK-Eval) are drop-in compatible and you can run either one of them against your server. The Wireshark captures should be directly comparable. (UAExpert also uses the UASDK as its low-level client.)
  • Do the same thing on an older Linux version (using OpenSSL1) with the Open62541 client against one of the "binary distribution" tars (that have a fully working version of the OPCUA  Support with UASDK using OpenSSL1) to see if behavior changes between the OpenSSL versions.
  • Use the UASDK demo server (part of the mentioned bundle), where you have full access to the server certificates. You can create and configure the server with self-signed or CA-signed certificates and check how the IOC needs to be set up to be able to connect.

The key thing to find out is if the issue is caused by how the Device Support handles the open62541 client or by how the open62541 client handles OpenSSL or by the server acting differently from other servers.
Thanks for your help and patience!

Cheers,
~Ralph



Replies:
RE: OPCUA SSL problem Majer Karel via Tech-talk
References:
OPCUA SSL problem Majer Karel via Tech-talk
Re: OPCUA SSL problem Ralph Lange via Tech-talk
RE: OPCUA SSL problem Majer Karel via Tech-talk

Navigate by Date:
Prev: Smaract MCS2 position polling issue Jeffrey Gamsby via Tech-talk
Next: Re: Smaract MCS2 position polling issue Jeffrey Gamsby via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  <20242025 
Navigate by Thread:
Prev: RE: OPCUA SSL problem Majer Karel via Tech-talk
Next: RE: OPCUA SSL problem Majer Karel via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  <20242025 
ANJ, 07 Oct 2024 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions ·
· Download · Search · IRMIS · Talk · Documents · Links · Licensing ·