Set up Certificate Logon for a DeltaV OPC UA workstation server with
third-party clients
Note
Connecting to third-party clients that are external to the DeltaV
network is a security risk.
Note
User Certificate logon requires that application certificates are
trusted.
Open User Manager.
Click
File → New → User.
Enter a name in the
Name field.
Enter and confirm a password.
In the
Account Type section, select the
OPC UA User checkbox. Click
Certificates.
The software displays the
User Certificate dialog. Make sure there are
values in the
Name,
Valid Until and
Thumbprint fields. If these fields are blank,
click
Generate. Then, click
Close.
Click
OK.
Open DeltaV Explorer.
Navigate to the workstation's OPC server subsystem and right-click
Properties.
Click
Set Users.
Select the user that you created earlier in this procedure.
Click
Add.
Click
OK.
Select the
Certificate Logon checkbox.
Click
OK.
Download the OPC UA server subsystem.
Open User Manager and double-click the user you created earlier in
this procedure.
The software opens the
Properties For User dialog.
Click
Certificates.
The software displays the
User Certificate dialog.
Click
Private + Public key (.pfx).
Enter a password. This password will be used later when splitting
the certificate into .der and .pem files or when importing the .pfx file.
Click
Export.
The software exports a .pfx file. Third-party clients need
this file for Certificate Logon.
Make sure application certificates are trusted between clients and
the server.