Opc.Ua.Service.Config.xml 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278
  1. <?xml version="1.0" encoding="utf-8"?>
  2. <ApplicationConfiguration
  3. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  4. xmlns:ua="http://opcfoundation.org/UA/2008/02/Types.xsd"
  5. xmlns="http://opcfoundation.org/UA/SDK/Configuration.xsd"
  6. >
  7. <ApplicationName>Opc.Ua.Service</ApplicationName>
  8. <ApplicationUri>urn:localhost:Opc.Ua.Service</ApplicationUri>
  9. <ProductUri>https://Shunnet.top</ProductUri>
  10. <ApplicationType>Server_0</ApplicationType>
  11. <SecurityConfiguration>
  12. <!-- Where the application instance certificate is stored-->
  13. <ApplicationCertificate>
  14. <StoreType>Directory</StoreType>
  15. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\own</StorePath>
  16. <SubjectName>CN=Service, C=KR, S=Seoul, O=OpcUaAutomation, DC=localhost</SubjectName>
  17. </ApplicationCertificate>
  18. <!-- Where the issuer certificate are stored (certificate authorities) -->
  19. <TrustedIssuerCertificates>
  20. <StoreType>Directory</StoreType>
  21. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\issuer</StorePath>
  22. </TrustedIssuerCertificates>
  23. <!-- Where the trust list is stored -->
  24. <TrustedPeerCertificates>
  25. <StoreType>Directory</StoreType>
  26. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\trusted</StorePath>
  27. </TrustedPeerCertificates>
  28. <!-- The directory used to store invalid certficates for later review by the administrator. -->
  29. <RejectedCertificateStore>
  30. <StoreType>Directory</StoreType>
  31. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\rejected</StorePath>
  32. </RejectedCertificateStore>
  33. <!-- WARNING: The following setting (to automatically accept untrusted certificates) should be used
  34. for easy debugging purposes ONLY and turned off for production deployments! -->
  35. <AutoAcceptUntrustedCertificates>false</AutoAcceptUntrustedCertificates>
  36. <!-- WARNING: SHA1 signed certficates are by default rejected and should be phased out.
  37. The setting below to allow them is only required for UACTT (1.02.336.244) which uses SHA-1 signed certs. -->
  38. <RejectSHA1SignedCertificates>false</RejectSHA1SignedCertificates>
  39. <RejectUnknownRevocationStatus>true</RejectUnknownRevocationStatus>
  40. <MinimumCertificateKeySize>2048</MinimumCertificateKeySize>
  41. <AddAppCertToTrustedStore>false</AddAppCertToTrustedStore>
  42. <SendCertificateChain>true</SendCertificateChain>
  43. <!-- Where the User issuer certificates are stored -->
  44. <UserIssuerCertificates>
  45. <StoreType>Directory</StoreType>
  46. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\issuerUser</StorePath>
  47. </UserIssuerCertificates>
  48. <!-- Where the User trust list is stored-->
  49. <TrustedUserCertificates>
  50. <StoreType>Directory</StoreType>
  51. <StorePath>%CommonApplicationData%\OpcUaAutomation\pki\trustedUser</StorePath>
  52. </TrustedUserCertificates>
  53. </SecurityConfiguration>
  54. <TransportConfigurations></TransportConfigurations>
  55. <TransportQuotas>
  56. <OperationTimeout>600000</OperationTimeout>
  57. <MaxStringLength>1048576</MaxStringLength>
  58. <MaxByteStringLength>1048576</MaxByteStringLength>
  59. <MaxArrayLength>65535</MaxArrayLength>
  60. <MaxMessageSize>4194304</MaxMessageSize>
  61. <MaxBufferSize>65535</MaxBufferSize>
  62. <ChannelLifetime>300000</ChannelLifetime>
  63. <SecurityTokenLifetime>3600000</SecurityTokenLifetime>
  64. </TransportQuotas>
  65. <ServerConfiguration>
  66. <BaseAddresses>
  67. <ua:String>https://127.0.0.1:6688/Opc.Ua.Service</ua:String>
  68. <ua:String>opc.tcp://127.0.0.1:8866/Opc.Ua.Service</ua:String>
  69. </BaseAddresses>
  70. <!--
  71. These list the alternate addresses (via firewalls, multiple NICs etc.) that can be
  72. used to communicate with the server. The URL used by the client when calling
  73. FindServers/GetEndpoints or CreateSession will be used to filter the list of
  74. endpoints returned by checking for alternate base addresses that have a domain
  75. that matches the domain in the url provided by the client.
  76. Note that any additional domains should be listed in the server's certificate. If they
  77. are left out the client make refuse to connect because it has no way to know if the
  78. alternate domain was authorized by the server administrator.
  79. -->
  80. <!--
  81. <AlternateBaseAddresses>
  82. <ua:String>http://AlternateHostName/Service</ua:String>
  83. <ua:String>http://10.10.103.150/Service</ua:String>
  84. <ua:String>http://[2a01::626d]/Service</ua:String>
  85. </AlternateBaseAddresses>
  86. -->
  87. <SecurityPolicies>
  88. <ServerSecurityPolicy>
  89. <SecurityMode>Sign_2</SecurityMode>
  90. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256</SecurityPolicyUri>
  91. </ServerSecurityPolicy>
  92. <ServerSecurityPolicy>
  93. <SecurityMode>None_1</SecurityMode>
  94. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#None</SecurityPolicyUri>
  95. </ServerSecurityPolicy>
  96. <ServerSecurityPolicy>
  97. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  98. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256</SecurityPolicyUri>
  99. </ServerSecurityPolicy>
  100. <!-- deprecated security policies for reference only
  101. <ServerSecurityPolicy>
  102. <SecurityMode>Sign_2</SecurityMode>
  103. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256</SecurityPolicyUri>
  104. </ServerSecurityPolicy>
  105. <ServerSecurityPolicy>
  106. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  107. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256</SecurityPolicyUri>
  108. </ServerSecurityPolicy>
  109. <ServerSecurityPolicy>
  110. <SecurityMode>Sign_2</SecurityMode>
  111. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic128Rsa15</SecurityPolicyUri>
  112. </ServerSecurityPolicy>
  113. <ServerSecurityPolicy>
  114. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  115. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic128Rsa15</SecurityPolicyUri>
  116. </ServerSecurityPolicy>
  117. -->
  118. <ServerSecurityPolicy>
  119. <SecurityMode>Sign_2</SecurityMode>
  120. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Aes128_Sha256_RsaOaep</SecurityPolicyUri>
  121. </ServerSecurityPolicy>
  122. <ServerSecurityPolicy>
  123. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  124. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Aes128_Sha256_RsaOaep</SecurityPolicyUri>
  125. </ServerSecurityPolicy>
  126. <ServerSecurityPolicy>
  127. <SecurityMode>Sign_2</SecurityMode>
  128. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Aes256_Sha256_RsaPss</SecurityPolicyUri>
  129. </ServerSecurityPolicy>
  130. <ServerSecurityPolicy>
  131. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  132. <SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Aes256_Sha256_RsaPss</SecurityPolicyUri>
  133. </ServerSecurityPolicy>
  134. <ServerSecurityPolicy>
  135. <SecurityMode>Sign_2</SecurityMode>
  136. <SecurityPolicyUri></SecurityPolicyUri>
  137. </ServerSecurityPolicy>
  138. <ServerSecurityPolicy>
  139. <SecurityMode>SignAndEncrypt_3</SecurityMode>
  140. <SecurityPolicyUri></SecurityPolicyUri>
  141. </ServerSecurityPolicy>
  142. </SecurityPolicies>
  143. <MinRequestThreadCount>100</MinRequestThreadCount>
  144. <MaxRequestThreadCount>1000</MaxRequestThreadCount>
  145. <MaxQueuedRequestCount>2000</MaxQueuedRequestCount>
  146. <!-- The SDK expects the server to support the same set of user tokens for every endpoint. -->
  147. <UserTokenPolicies>
  148. <!-- 匿名登录 -->
  149. <ua:UserTokenPolicy>
  150. <ua:TokenType>Anonymous_0</ua:TokenType>
  151. <ua:SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#None</ua:SecurityPolicyUri>
  152. </ua:UserTokenPolicy>
  153. <!-- 账号密码登录 -->
  154. <ua:UserTokenPolicy>
  155. <ua:TokenType>UserName_1</ua:TokenType>
  156. <!-- passwords must be encrypted - this specifies what algorithm to use -->
  157. <ua:SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256</ua:SecurityPolicyUri>
  158. </ua:UserTokenPolicy>
  159. <!-- 证书登录 -->
  160. <ua:UserTokenPolicy>
  161. <ua:TokenType>Certificate_2</ua:TokenType>
  162. <!-- certificate possession must be proven with a digital signature - this specifies what algorithm to use -->
  163. <ua:SecurityPolicyUri>http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256</ua:SecurityPolicyUri>
  164. </ua:UserTokenPolicy>
  165. </UserTokenPolicies>
  166. <DiagnosticsEnabled>true</DiagnosticsEnabled>
  167. <MaxSessionCount>100</MaxSessionCount>
  168. <MinSessionTimeout>10000</MinSessionTimeout>
  169. <MaxSessionTimeout>3600000</MaxSessionTimeout>
  170. <MaxBrowseContinuationPoints>10</MaxBrowseContinuationPoints>
  171. <MaxQueryContinuationPoints>10</MaxQueryContinuationPoints>
  172. <MaxHistoryContinuationPoints>100</MaxHistoryContinuationPoints>
  173. <MaxRequestAge>600000</MaxRequestAge>
  174. <MinPublishingInterval>100</MinPublishingInterval>
  175. <MaxPublishingInterval>3600000</MaxPublishingInterval>
  176. <PublishingResolution>50</PublishingResolution>
  177. <MaxSubscriptionLifetime>3600000</MaxSubscriptionLifetime>
  178. <MaxMessageQueueSize>100</MaxMessageQueueSize>
  179. <MaxNotificationQueueSize>100</MaxNotificationQueueSize>
  180. <MaxNotificationsPerPublish>1000</MaxNotificationsPerPublish>
  181. <MinMetadataSamplingInterval>1000</MinMetadataSamplingInterval>
  182. <AvailableSamplingRates>
  183. <SamplingRateGroup>
  184. <Start>5</Start>
  185. <Increment>5</Increment>
  186. <Count>20</Count>
  187. </SamplingRateGroup>
  188. <SamplingRateGroup>
  189. <Start>100</Start>
  190. <Increment>100</Increment>
  191. <Count>4</Count>
  192. </SamplingRateGroup>
  193. <SamplingRateGroup>
  194. <Start>500</Start>
  195. <Increment>250</Increment>
  196. <Count>2</Count>
  197. </SamplingRateGroup>
  198. <SamplingRateGroup>
  199. <Start>1000</Start>
  200. <Increment>500</Increment>
  201. <Count>20</Count>
  202. </SamplingRateGroup>
  203. </AvailableSamplingRates>
  204. <RegistrationEndpoint>
  205. <ua:EndpointUrl>opc.tcp://localhost:4840</ua:EndpointUrl>
  206. <ua:Server>
  207. <ua:ApplicationUri>opc.tcp://localhost:4840</ua:ApplicationUri>
  208. <ua:ApplicationType>DiscoveryServer_3</ua:ApplicationType>
  209. <ua:DiscoveryUrls>
  210. <ua:String>opc.tcp://localhost:4840</ua:String>
  211. </ua:DiscoveryUrls>
  212. </ua:Server>
  213. <ua:SecurityMode>SignAndEncrypt_3</ua:SecurityMode>
  214. <ua:SecurityPolicyUri />
  215. <ua:UserIdentityTokens />
  216. </RegistrationEndpoint>
  217. <MaxRegistrationInterval>30000</MaxRegistrationInterval>
  218. <NodeManagerSaveFile>Opc.Ua.Service.Nodes.Json</NodeManagerSaveFile>
  219. <MinSubscriptionLifetime>10000</MinSubscriptionLifetime>
  220. <MaxPublishRequestCount>20</MaxPublishRequestCount>
  221. <MaxSubscriptionCount>10000</MaxSubscriptionCount>
  222. <MaxEventQueueSize>10000</MaxEventQueueSize>
  223. <!-- see https://opcfoundation-onlineapplications.org/profilereporting/ for list of available profiles -->
  224. <ServerProfileArray>
  225. <ua:String>http://opcfoundation.org/UA-Profile/Server/StandardUA2017</ua:String>
  226. <ua:String>http://opcfoundation.org/UA-Profile/Server/DataAccess</ua:String>
  227. <ua:String>http://opcfoundation.org/UA-Profile/Server/Methods</ua:String>
  228. </ServerProfileArray>
  229. <ShutdownDelay>5</ShutdownDelay>
  230. <ServerCapabilities>
  231. <ua:String>DA</ua:String>
  232. </ServerCapabilities>
  233. <SupportedPrivateKeyFormats>
  234. <ua:String>PFX</ua:String>
  235. <ua:String>PEM</ua:String>
  236. </SupportedPrivateKeyFormats>
  237. <MaxTrustListSize>0</MaxTrustListSize>
  238. <MultiCastDnsEnabled>false</MultiCastDnsEnabled>
  239. </ServerConfiguration>
  240. <TraceConfiguration>
  241. <OutputFilePath>%LocalApplicationData%/log/Opc.Ua.Service.log.txt</OutputFilePath>
  242. <DeleteOnLoad>true</DeleteOnLoad>
  243. <!-- Show Only Errors -->
  244. <!-- <TraceMasks>1</TraceMasks> -->
  245. <!-- Show Only Security and Errors -->
  246. <!-- <TraceMasks>513</TraceMasks> -->
  247. <!-- Show Only Security, Errors and Trace -->
  248. <!-- <TraceMasks>515</TraceMasks> -->
  249. <!-- Show Only Security, COM Calls, Errors and Trace -->
  250. <!-- <TraceMasks>771</TraceMasks> -->
  251. <!-- Show Only Security, Service Calls, Errors and Trace -->
  252. <!-- <TraceMasks>523</TraceMasks> -->
  253. <!-- Show Only Security, ServiceResultExceptions, Errors and Trace -->
  254. <!-- <TraceMasks>519</TraceMasks> -->
  255. </TraceConfiguration>
  256. </ApplicationConfiguration>