Avatar
Please consider registering
guest
sp_LogInOut Log Insp_Registration Register
Register | Lost password?
Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
sp_Feed Topic RSSsp_TopicIcon
Basic256Sha256 (Sign and Sign&Encrypt)
October 29, 2015
12:58, EET
Avatar
cguerin
Vienna, Austria
Member
Members
Forum Posts: 20
Member Since:
April 9, 2013
sp_UserOfflineSmall Offline

I tried my OPC UA Server with those security Policies
However when I try to valid the first SecureMessage (CreateSession) after the OpenSecureChannel suceeded.
The HMAC SHA256 Verify failed.

With which Server have you tested your client against those Security Policies ?

October 29, 2015
15:29, EET
Avatar
Jouni Aro
Moderator
Moderators
Forum Posts: 1044
Member Since:
December 21, 2011
sp_UserOfflineSmall Offline

There were interoperability issues against the C/.NET servers before Java SDK version 2.1.2, since the specification was different to those implementations. Which version of the SDK are you using?

The change was mentioned in the release notes as well: https://downloads.prosysopc.co…..2-478.html

November 3, 2015
8:05, EET
Avatar
cguerin
Vienna, Austria
Member
Members
Forum Posts: 20
Member Since:
April 9, 2013
sp_UserOfflineSmall Offline

Hello,

I am using my own Server based on the 1.02 OPC UA Stack version.

November 10, 2015
13:55, EET
Avatar
Jouni Aro
Moderator
Moderators
Forum Posts: 1044
Member Since:
December 21, 2011
sp_UserOfflineSmall Offline

Sorry for the late response.

A possible reason is that the specification is actually defining a wrong URL for the AsymmetricSignatureAlgorithm, ‘http://www.w3.org/2000/09/xmldsig#rsa-sha256’, whereas all the implementations actually use the correct one, ‘http://www.w3.org/2001/04/xmldsig-more#rsa-sha256’. This was fixed also for the Java stack in version 2.1.2, but the respective change was not taken to the specification version 1.03 either. Hopefully, there will be an errata that fixes it finally. The following Mantis issue can be used to track it:

https://opcfoundation-onlineap…..hp?id=3208

November 12, 2015
15:11, EET
Avatar
cguerin
Vienna, Austria
Member
Members
Forum Posts: 20
Member Since:
April 9, 2013
sp_UserOfflineSmall Offline

I don’t know.

Anyway, my Server is working with the latest UAExpert v1.4.0 which supports Basic256Sha256.
I will wait for the Prosys OPC UA Client to be support it as well.

Regards.
Camille Guérin.

November 12, 2015
16:10, EET
Avatar
Bjarne Boström
Moderator
Moderators
Forum Posts: 1070
Member Since:
April 3, 2012
sp_UserOfflineSmall Offline

It technically supported it for a while now, but it is not visible in the UI because servers didn’t support it. Will show in the newest build (2.2.0-35). Will be shortly the release version.

November 13, 2015
8:15, EET
Avatar
cguerin
Vienna, Austria
Member
Members
Forum Posts: 20
Member Since:
April 9, 2013
sp_UserOfflineSmall Offline

My Server supports Basic256Sha256 and it works with the latest UAExpert client (which supports it as well)
However it does not work with Prosys OPC UA Client, the CreateSecureChannelRequest with Basic256Sha256 is not well signed, I guess it used the wrong algorithmus.

November 13, 2015
12:52, EET
Avatar
Jouni Aro
Moderator
Moderators
Forum Posts: 1044
Member Since:
December 21, 2011
sp_UserOfflineSmall Offline

I discussed this with Unified Automation and heard that there were interoperability issues with the OPC Foundation stack implementations in last week’s Interoperability Workshop – and these issues were fixed in the OPC Foundation stacks.

Our Java and Unified Automation implementations should be interoperable.

But which stack implementation are you using? OPC Foundation’s .NET or C and which version?

November 13, 2015
12:53, EET
Avatar
Jouni Aro
Moderator
Moderators
Forum Posts: 1044
Member Since:
December 21, 2011
sp_UserOfflineSmall Offline

The C stack has at least been updated this week:

https://opcfoundation.org/deve…..urce-code/

Forum Timezone: Europe/Helsinki
Most Users Ever Online: 1919
Currently Online:
Guest(s) 54
Top Posters:
Heikki Tahvanainen: 402
hbrackel: 144
rocket science: 100
pramanj: 86
Francesco Zambon: 83
Ibrahim: 78
Sabari: 62
kapsl: 57
gjevremovic: 49
Xavier: 43
Member Stats:
Guest Posters: 0
Members: 773
Moderators: 7
Admins: 1
Forum Stats:
Groups: 3
Forums: 15
Topics: 1558
Posts: 6567
Newest Members:
berniecebetche1, henrygilley3003, virgiethompkins, chris.s, aracelyhaley4, raphaelschonell, Ashmag, kathyreimann56, brittanylemos, dorthycundiff76
Moderators: Jouni Aro: 1039, Pyry: 1, Petri: 1, Bjarne Boström: 1054, Jimmy Ni: 26, Matti Siponen: 359, Lusetti: 0
Administrators: admin: 1