# PFC100 OPC UA - CA Certificate handling

**URL:** <https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816>\
**Category:** Hardware and Linux\
**Created:** [March 11, 2024, 11:34am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816 "2024-03-11T11:34:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![WaEm2303](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@WaEm2303](https://www.wago.community/u/WaEm2303)\
**Post date:** [March 11, 2024, 11:34am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/1 "2024-03-11T11:34:42Z")

</div>

Hi all,

we use the “WAGO 750-8100 PFC100 2ETH ECO” controller and we have configured the OPC UA interface via the WBM.

We use the programm “UaExpert” for testing.  
Without any problems, we can see all variables declared in e!COCKPIT.

The next step is to set up the secure connection with certificates.

Before we use CA Certificate, we want to test the manual certificate handling.  
The following setting is in the OPC UA Configuration in the WBM:

- OPC UA Endpoints:  
Security Policy - Basic128Rsa15  
Security Policy - Basic256Sha256  
are enabled.

OPC UA Security Settings:  
All enabled except “Trust all clients”

When establishing a connection with UA Expert, I have to trust the certificate provided by Wago.  
This is followed by an warning message: “BadCertificateHostNameInvalid”.  
The reason for this is that the IP is not set for the alternative requestor in the WAGO certificate. This is the first problem.  
Is it the case that the WAGO certificate does not comply with the OPC AU specification?

But I can ignore this message, connect and see data.

Now I have my own CA certificates, which I have uploaded in WBM under “Server certificates”:  
OPC UA Server Own Certificates: My own certificate issued by the CA from the network  
OPC UA Server Private Keys: My own private key issued by the CA from the network

I have deleted Wago’s own certificate: certificate.der and key.pem

If I now establish a connection with UA Expert, the Wago’s own certificates are still shown (although I have deleted the certificates).  
When I restart the controller, the Wago certificates are displayed again…  
Why are the CA certificates not accepted and the Wago certificates still there?  
Has anyone had any experience with it?

---

<div class="post-metadata">

**Author:** ![WagoKurt](https://sea2.discourse-cdn.com/flex016/user_avatar/www.wago.community/wagokurt/32/11_2.png) [@WagoKurt](https://www.wago.community/u/WagoKurt)\
**Post date:** [March 11, 2024, 2:59pm UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/2 "2024-03-11T14:59:03Z")

</div>

Hello,  
You might find this thread useful as it is a similar subject.

> [@Tech Note: 3S Runtime with OPC UA Server](https://www.wago.community/t/tech-note-3s-runtime-with-opc-ua-server/305/9):
>
> Does anyone have successfully create his own certificates using openssl and not CODESYS ? The aim is to add the IP in the SubjectAltName, which is not part of the CODESYS generated certificates (only DNS is provided). Sor far here is what I’ve done : Create a ssl.conf file : [req] default\_bits = 3072 serial = 0 default\_md = sha256 distinguished\_name = subject req\_extensions = req\_ext x509\_extensions = req\_ext string\_mask = utf8only prompt = no [req\_ext] basicConstraints = critical, CA:T…

---

<div class="post-metadata">

**Author:** ![WaEm2303](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@WaEm2303](https://www.wago.community/u/WaEm2303)\
**Post date:** [March 12, 2024, 8:00am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/3 "2024-03-12T08:00:31Z")

</div>

@WagoKurt  
Thank you for the helpful thread.  
If I now connect via the host name, I no longer get an error message in UAExpert (as the host name is in the certificate).

As described above, I would now like to use my own CA certificate:

> Now I have my own CA certificates, which I have uploaded in WBM under “Server certificates”:  
> OPC UA Server Own Certificates: My own certificate issued by the CA from the network  
> OPC UA Server Private Keys: My own private key issued by the CA from the network
> 
> I have deleted Wago’s own certificate: certificate.der and key.pem
> 
> If I now establish a connection with UA Expert, the Wago’s own certificates are still shown (although I have deleted the certificates).  
> When I restart the controller, the Wago certificates are displayed again…  
> Why are the CA certificates not accepted and the Wago certificates still there?  
> Has anyone had any experience with it?

@PatrickR I have seen your helpful posts on OPC UA. Do you have any idea why no CA certificates are displayed in UAExpert?

Any help would be appreciated 🙂

---

<div class="post-metadata">

**Author:** ![PatrickR](https://sea2.discourse-cdn.com/flex016/user_avatar/www.wago.community/patrickr/32/262_2.png) [@PatrickR](https://www.wago.community/u/PatrickR)\
**Post date:** [March 13, 2024, 11:56am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/4 "2024-03-13T11:56:39Z")

</div>

Hello @WaEm2303  
unfortunately I won’t be able to test this until next week as I’m not in the office at the moment.

The only thing I can think of off the top of my head is that all certificates in the chain must be known to the server and the crl must also be known to the server. Maybe you should have a look in the Pki. For the WAGO OPC UA server, I think this should be somewhere under /etc

BR  
Patrick

---

<div class="post-metadata">

**Author:** ![WaEm2303](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@WaEm2303](https://www.wago.community/u/WaEm2303)\
**Post date:** [March 19, 2024, 1:21pm UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/5 "2024-03-19T13:21:20Z")

</div>

Hello @PatrickR,

I have found the PKI folder with the certificates on the PLC:  
 ![grafik](https://us1.discourse-cdn.com/flex016/uploads/wago/original/1X/6b70f0486b07e1c5f00b0e858646e4cb8b8ed230.png)

If I delete these certificates and replace them with my self-created certificates, the certificates are automatically recreated as soon as I restart the controller.

Have you been able to test it in the office?

BTW: Does the Wago support the automatic renewal of certificates with a GDS server/client (push/pull)?

---

<div class="post-metadata">

**Author:** ![PatrickR](https://sea2.discourse-cdn.com/flex016/user_avatar/www.wago.community/patrickr/32/262_2.png) [@PatrickR](https://www.wago.community/u/PatrickR)\
**Post date:** [March 21, 2024, 7:17am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/6 "2024-03-21T07:17:19Z")

</div>

Hi @WaEm2303 ,

Here in the manual you can see how the renewal of certificates with UaExpert via GDS Push works. [WAGO USA | 5574984](https://www.wago.com/us/d/5574984)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/wago/original/1X/830d9419f925652f5df9d217221e374eb6d77489.png)

I had actually also assumed that you had tried to use a CA-signed certificate via the CSR generated here (UaExpert → GDS Push View).

You might have to take a look at the certificate to see if everything matches.  
The most important thing for OPC UA is the ApplicationUri as URL in the SubjectAlternativeName.  
Everything should already be entered in the CSR.

Have you tried this?

---

<div class="post-metadata">

**Author:** ![WaEm2303](https://avatars.discourse-cdn.com/v4/letter/w/2bfe46/32.png) [@WaEm2303](https://www.wago.community/u/WaEm2303)\
**Post date:** [March 21, 2024, 7:54am UTC](https://www.wago.community/t/pfc100-opc-ua-ca-certificate-handling/816/7 "2024-03-21T07:54:25Z")

</div>

Hi @PatrickR,

thanks for the document. I hadn’t found it before and it’s certainly helpful!

So far I have tried to generate the certificate with my own CA (via OpenSSL).  
I will now try this via UaGDS and then compare the certificates.

Many thanks for your help!
