View Issue Details

IDProjectCategoryView StatusLast Update
000395610000-005: Information ModelSpecpublic2017-09-28 12:18
ReporterMatthias Damm Assigned Tojeffhardingabb  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Summary0003956: How to grant Role based on Application Identity
Description

In OPC UA Part 3 - 4.8 Roles (4.8.1 Overview), the description states that the standard mapping allows Roles to be granted to Users, Applications and Endpoints.

From the definition of the RoleType Properties Identities and Applications, it is not clear how I can grant a role to an Application. The description of Identities implies that I always need a user identity. Can I set ANONYMOUS_5 and AUTHENTICATED_USER_6 for Identities to make the decision just based on the application? Or is it expected that ANONYMOUS_5 is used if I want to authorize just based on the application instance certificate?

In addition the Applications is defined as String[] but the description of the Property talkes about Application Instance Certificates. How are the certificates converted to strings. Is the thumbprint used?

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Jim Luth

2017-09-26 07:40

administrator   ~0008485

We agreed to add a bit to the endpoint array and the application instance array to specify if the array is an "include" list or an "exclude" list.

Jim Luth

2017-09-28 12:18

administrator   ~0008529

Agreed to changes edited in Prague meeting.

Issue History

Date Modified Username Field Change
2017-09-19 07:36 Matthias Damm New Issue
2017-09-19 15:42 Jim Luth Status new => assigned
2017-09-19 15:42 Jim Luth Assigned To => jeffhardingabb
2017-09-26 07:40 Jim Luth Note Added: 0008485
2017-09-27 09:44 jeffhardingabb Status assigned => resolved
2017-09-27 09:44 jeffhardingabb Fixed in Version => 1.04
2017-09-27 09:44 jeffhardingabb Resolution open => fixed
2017-09-28 12:18 Jim Luth Note Added: 0008529
2017-09-28 12:18 Jim Luth Status resolved => closed