Glossary · Industrial communication
OPC UA security policy
Also known as: OPC UA security mode, Security policy (OPC UA)
German: OPC-UA-Sicherheitsrichtlinie
In OPC UA, a security policy is the named set of cryptographic algorithms and key lengths that an endpoint uses to sign and encrypt messages, and it is combined with a message security mode of None, Sign or SignAndEncrypt and with X.509 application instance certificates to protect the communication between client and server.
- Industrial communication
- OT security
- Standards
In one sentence
An OPC UA security policy sets the algorithms an endpoint uses; with the mode None, Sign or SignAndEncrypt and certificates it protects messages.
Example
The OPC UA server of a case packer offers only the policy Basic256Sha256 with mode SignAndEncrypt; the MES client's certificate is added to the server's trust list during commissioning.
How it applies
- Engineering: Each server endpoint names its security policy (for example None, Basic256Sha256, Aes128_Sha256_RsaOaep or Aes256_Sha256_RsaPss) and its mode. Older policies such as Basic128Rsa15 and Basic256 are deprecated by the OPC Foundation and should be disabled.
- Security: Mode Sign protects integrity, SignAndEncrypt also confidentiality; None protects nothing. Application certificates authenticate the applications, while user authentication (user name, certificate or token) is a separate step. A strong policy doesn't make a system secure; certificate management, access rights and network segmentation per IEC 62443 still apply.
- Commissioning: Certificates must be exchanged and trusted on both sides. Leaving the None endpoint enabled "for testing" or trusting every certificate automatically is a typical finding in audits.
- Documentation: The documentation team documents the offered endpoints with policy and mode, how certificates are created, trusted, renewed and revoked (by hand or via a Public key infrastructure (PKI)), and which user roles exist.
Security policy vs. security mode
The mode says whether messages are signed, encrypted or neither; the policy says with which algorithms. An endpoint is defined by the combination, for example "Basic256Sha256 – SignAndEncrypt".