<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kepware OPCUA certificate in Kepware</title>
    <link>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058677#M3335</link>
    <description>&lt;P&gt;Thank you Ntripathi for the reply. I previously explained this to the customer as well—the certificate mechanism is designed this way for security and mutual trust. I understand now. Thank you for your assistance.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2026 01:27:10 GMT</pubDate>
    <dc:creator>WY_14406740</dc:creator>
    <dc:date>2026-03-16T01:27:10Z</dc:date>
    <item>
      <title>Kepware OPCUA certificate</title>
      <link>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058256#M3324</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;使用者希望使用&lt;/FONT&gt;&lt;FONT&gt;有效期限為&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;10 年或更長的&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;&lt;FONT&gt;自簽名憑證&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;&lt;FONT&gt;。使用原有的&lt;/FONT&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;FONT&gt;KEPServerEX&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;FONT&gt;客戶端&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;時，只需&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;一個憑證&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;即可實現雙向通訊。然而，&lt;/FONT&gt;&lt;FONT&gt;由於架構較為複雜，&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;目前似乎無法在多個系統間重複使用&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;自簽名憑證。請確認&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;自簽名客戶端憑證是否可以被多個伺服器使用&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;。&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;FONT&gt;&lt;FONT&gt;OPC UA&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT&gt;&lt;FONT&gt;證書會&lt;/FONT&gt;&lt;FONT&gt;自動續約或延長有效期限嗎？&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;如果&lt;/FONT&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT&gt;&lt;FONT&gt;用戶端憑證過期&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;&lt;FONT&gt;，是否會影響現有系統？例如，是否會導致&lt;/FONT&gt;&lt;FONT&gt;EAP&lt;/FONT&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;FONT&gt;&lt;FONT&gt;無法&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT&gt;&lt;FONT&gt;連線&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT&gt;&lt;FONT&gt;等問題？&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The user would like to use a &lt;STRONG&gt;self-signed certificate&lt;/STRONG&gt; with a validity period of &lt;STRONG&gt;10 years or longer&lt;/STRONG&gt;. With the original &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;KEPServerEX&lt;/SPAN&gt;&lt;/SPAN&gt; client&lt;/STRONG&gt;, only &lt;STRONG&gt;one certificate&lt;/STRONG&gt; is needed for mutual communication.&lt;BR /&gt;However, it seems that a self-signed certificate &lt;STRONG&gt;cannot currently be reused across multiple systems&lt;/STRONG&gt;, possibly due to the more complex architecture. Please confirm whether a &lt;STRONG&gt;self-signed client certificate can be used by multiple servers&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Will **&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;OPC UA&lt;/SPAN&gt;&lt;/SPAN&gt; certificates automatically renew or extend their validity period?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the &lt;STRONG&gt;client certificate expires&lt;/STRONG&gt;, will it affect the existing system? For example, could it cause issues such as &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;EAP&lt;/SPAN&gt;&lt;/SPAN&gt; being unable to connect&lt;/STRONG&gt;?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Mar 2026 03:50:06 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058256#M3324</guid>
      <dc:creator>WY_14406740</dc:creator>
      <dc:date>2026-03-12T03:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Kepware OPCUA certificate</title>
      <link>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058573#M3329</link>
      <description>&lt;P&gt;Greetings&amp;nbsp;&lt;a href="https://www.ptcusercommunity.com/t5/user/viewprofilepage/user-id/1062641"&gt;@WY_14406740&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this email finds you well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;I am writing to inform you that the OPC UA certificate generated by the Kepware Server is created by default with a validity period of 3 years. After this 3‑year period, the certificate cannot be extended and must be reissued. For detailed information, please refer to the article&amp;nbsp;&lt;A href="https://www.ptc.com/en/support/article/CS368928?as=1" target="_blank"&gt;Article - CS368928 - Is it possible to extend the expiration of OPC UA certificate generated by Kepware?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note the following important points:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;OPC UA certificates do not renew automatically.&lt;BR /&gt;There is no built‑in mechanism in Kepware or OPC UA to extend or auto‑renew an existing certificate.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When an OPC UA client certificate expires, the secure connection will fail immediately.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;BR /&gt;Naveen&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 16:32:34 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058573#M3329</guid>
      <dc:creator>ntripathi</dc:creator>
      <dc:date>2026-03-13T16:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Kepware OPCUA certificate</title>
      <link>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058587#M3334</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://www.ptcusercommunity.com/t5/user/viewprofilepage/user-id/1062641"&gt;@WY_14406740&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;I would like to inform you that self‑signed certificates cannot typically be used across multiple servers. In most environments, self‑signed certificates operate on a one‑to‑one trust relationship, meaning each server generally requires its own certificate to establish a secure and trusted connection.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Whether a certificate can be reused depends on the issuing Certificate Authority (CA).&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 13 Mar 2026 19:23:28 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058587#M3334</guid>
      <dc:creator>ntripathi</dc:creator>
      <dc:date>2026-03-13T19:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Kepware OPCUA certificate</title>
      <link>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058677#M3335</link>
      <description>&lt;P&gt;Thank you Ntripathi for the reply. I previously explained this to the customer as well—the certificate mechanism is designed this way for security and mutual trust. I understand now. Thank you for your assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 01:27:10 GMT</pubDate>
      <guid>https://www.ptcusercommunity.com/t5/Kepware/Kepware-OPCUA-certificate/m-p/1058677#M3335</guid>
      <dc:creator>WY_14406740</dc:creator>
      <dc:date>2026-03-16T01:27:10Z</dc:date>
    </item>
  </channel>
</rss>

