Flow Ctrl Tech Engineering

OPC UA Security: Managing X.509 Certificates, Rejected Lists & Trust Stores

Demystifying OPC UA secure handshakes: self-signed vs Certificate Authority (CA) certs, mutual certificate exchange, resolving "BadSecurityChecksFailed", and automated certificate rotation.

  • OPC UA requires both the client and server to possess and exchange cryptographic certificates before sharing data.
  • When a new client attempts to connect, the server places its certificate into the "Rejected" directory by default.
  • An administrator must explicitly move the rejected certificate into the "Trusted" store to authorize communications.

Flow Ctrl Tech Engineering: Turnkey industrial automation, PLC programming, SCADA development, HMI, fieldbuses, and IIoT architectures. Contact our engineering center at [email protected] or phone +91 91110 91005.