Security
Cryptography, certificates, security policies, and the certificate store (client and server).
ua::SecPolAes128Sha256RsaOaep
class
The Aes128_Sha256_RsaOaep RSA security policy.
Concrete SecurityPolicy for the OPC UA Aes128_Sha256_RsaOaep profile: RSA-OAEP (SHA-1) asymmetric encryption, RSA-PKCS#1 v1.5 (SHA-256) asymmetric signatures, AES-128-CBC symmetric encryption, and HMAC-SHA-256 symmetric signatures. Every method reports the fixed cryptographic parameters of this profile; instances are stateless and may be shared across secure channels.
Functions
SecurityPolicyId id() const override
Returns the security-policy identifier for this profile.
Returns: The security-policy identifier for this profile.
String uri() const override
Returns the canonical OPC UA security-policy URI for this profile.
Returns: The canonical OPC UA security-policy URI for this profile.
CertificateType certificate_type() const override
Returns the certificate type accepted by this profile (an RSA certificate type).
Returns: The RSA certificate type accepted by this profile.
bool is_authenticated() const override
Indicates whether this policy authenticates the peer (signs and/or encrypts).
Returns: true if this policy authenticates the peer (signs and/or encrypts).
bool is_rsa() const override
Indicates that this is an RSA-family policy.
Returns: true; this is an RSA-family policy.
bool is_ecc() const override
Indicates that this is an ECC-family policy.
Returns: false; this is not an ECC-family policy.
bool uses_legacy_sequence_no() const override
Indicates whether this policy uses the legacy secure-channel sequence-number scheme.
Returns: true if this policy uses the legacy secure-channel sequence-number scheme.
size_t nonce_length() const override
Returns the required nonce length, in bytes.
Returns: The required nonce length, in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size, in bytes.
Returns: The symmetric cipher plaintext block size, in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric (RSA-OAEP) plaintext block size for the peer certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose RSA key size sets the block size. Must not be null.
Returns: The largest plaintext block, in bytes, that fits one RSA-OAEP encryption block.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size, in bytes.
Returns: The symmetric cipher ciphertext block size, in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric (RSA) ciphertext block size for the given peer certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose RSA key size sets the block size. Must not be null.
Returns: The RSA encryption block size, in bytes (equal to the modulus length).
size_t symmetric_signature_size() const override
Returns the symmetric signature (HMAC) size, in bytes.
Returns: The symmetric signature (HMAC) size, in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric (RSA) signature size for the given peer certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose RSA key size sets the signature size. Not null.
Returns: The RSA signature size, in bytes (equal to the modulus length).
size_t symmetric_signature_key_size() const override
Returns the symmetric signing (HMAC) key size, in bytes.
Returns: The symmetric signing (HMAC) key size, in bytes.
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption (AES) key size, in bytes.
Returns: The symmetric encryption (AES) key size, in bytes.
size_t symmetric_iv_size() const override
Returns the symmetric encryption initialization-vector size, in bytes.
Returns: The symmetric encryption initialization-vector size, in bytes.
size_t min_asymmetric_key_length() const override
Returns the minimum permitted asymmetric (RSA) key length, in bits.
Returns: The minimum permitted asymmetric (RSA) key length, in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum permitted asymmetric (RSA) key length, in bits.
Returns: The maximum permitted asymmetric (RSA) key length, in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm (RSA-OAEP with SHA-1).
Returns: The asymmetric encryption algorithm (RSA-OAEP with SHA-1).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm (RSA-PKCS#1 v1.5 with SHA-256).
Returns: The asymmetric signature algorithm (RSA-PKCS#1 v1.5 with SHA-256).
String asymmetric_signature_algorithm_uri() const override
Returns the canonical URI of the asymmetric signature algorithm.
Returns: The canonical URI of the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm (AES-128-CBC).
Returns: The symmetric encryption algorithm (AES-128-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm (HMAC-SHA-256).
Returns: The symmetric signature algorithm (HMAC-SHA-256).
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric signing and encryption keys for a channel from the exchanged nonces.
context(shared_ptr< SecureChannelContext >) - Secure-channel context the keys are derived for. Must outlive the call.localNonce(ByteString) - Nonce generated by this endpoint for the current token.remoteNonce(ByteString) - Nonce received from the peer for the current token.role(ChannelRole) - Whether this endpoint acts as the server or the client, which fixes nonce ordering during derivation.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the Result holds the local and remote SecurityToken::Keys (signing key, encryption key, IV) as a pair; on failure it carries an ErrorDetail. This overload never throws.
ua::SecPolAes256Sha256RsaPss
class
The Aes256_Sha256_RsaPss RSA-family OPC UA security policy.
Implements the cryptographic parameters and key derivation defined by the http://opcfoundation.org/UA/SecurityPolicy#Aes256_Sha256_RsaPss profile: AES-256-CBC symmetric encryption, HMAC-SHA-256 symmetric signatures, RSA-OAEP (SHA-256) asymmetric encryption, and RSA-PSS (SHA-256) asymmetric signatures.
Instances are immutable and stateless; the same policy object may be shared across secure channels and called concurrently from any thread. SecurityPolicy, SecPolRsa
Functions
SecurityPolicyId id() const override
Returns the policy identifier (SecurityPolicyId::Aes256_Sha256_RsaPss).
Returns: The policy identifier (SecurityPolicyId::Aes256_Sha256_RsaPss).
String uri() const override
Returns the OPC UA security policy URI for this policy.
Returns: The OPC UA security-policy URI for this policy.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (RSA).
Returns: The RSA certificate type required by this policy.
bool is_authenticated() const override
Indicates whether the policy provides message authentication.
Returns: true - this policy signs and (where applicable) encrypts messages.
bool is_rsa() const override
Indicates whether the policy uses RSA asymmetric cryptography.
Returns: true.
bool is_ecc() const override
Indicates whether the policy uses elliptic-curve asymmetric cryptography.
Returns: false.
bool uses_legacy_sequence_no() const override
Indicates whether the policy uses the legacy secure-channel sequence-number scheme.
Returns: true if the policy uses the legacy secure-channel sequence-number scheme.
size_t nonce_length() const override
Returns the required length, in bytes, of the secure-channel nonce.
Returns: The required secure-channel nonce length, in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size, in bytes.
Returns: The symmetric cipher plaintext block size, in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric cipher plaintext block size, in bytes, for the given certificate.
certificate(const X509Certificate *) - Certificate whose public-key modulus determines the block size. Borrowed for the call; must remain valid until it returns.
Returns: The asymmetric cipher plaintext block size, in bytes, for certificate.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size, in bytes.
Returns: The symmetric cipher ciphertext block size, in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric cipher ciphertext block size, in bytes, for the given certificate.
certificate(const X509Certificate *) - Certificate whose public-key modulus determines the block size. Borrowed for the call; must remain valid until it returns.
Returns: The asymmetric cipher ciphertext block size, in bytes, for certificate.
size_t symmetric_signature_size() const override
Returns the symmetric signature (MAC) size, in bytes.
Returns: The symmetric signature (MAC) size, in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size, in bytes, for the given certificate.
certificate(const X509Certificate *) - Certificate whose private-key length determines the signature size. Borrowed for the call; must remain valid until it returns.
Returns: The asymmetric signature size, in bytes, for certificate.
size_t symmetric_signature_key_size() const override
Returns the symmetric signing (MAC) key size, in bytes.
Returns: The symmetric signing (MAC) key size, in bytes.
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size, in bytes.
Returns: The symmetric encryption key size, in bytes.
size_t symmetric_iv_size() const override
Returns the symmetric initialization-vector size, in bytes.
Returns: The symmetric initialization-vector size, in bytes.
size_t min_asymmetric_key_length() const override
Returns the minimum accepted RSA key length, in bits.
Returns: The minimum accepted RSA key length, in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum accepted RSA key length, in bits.
Returns: The maximum accepted RSA key length, in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm used by this policy (RSA-OAEP, SHA-256).
Returns: The asymmetric encryption algorithm (RSA-OAEP, SHA-256).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (RSA-PSS, SHA-256).
Returns: The asymmetric signature algorithm (RSA-PSS, SHA-256).
String asymmetric_signature_algorithm_uri() const override
Returns the OPC UA URI of the asymmetric signature algorithm.
Returns: The OPC UA URI of the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (AES-256-CBC).
Returns: The symmetric encryption algorithm (AES-256-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (HMAC-SHA-256).
Returns: The symmetric signature algorithm (HMAC-SHA-256).
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric session keys for a secure channel from the exchanged nonces.
context(shared_ptr< SecureChannelContext >) - Secure-channel context the derived keys belong to. Held for the duration of the derivation; must outlive the call.localNonce(ByteString) - Nonce generated by this endpoint.remoteNonce(ByteString) - Nonce received from the peer.role(ChannelRole) - Whether this endpoint acts as the channel server or client; selects the per-role nonce ordering.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the Result holds the local and remote SecurityToken::Keys; on failure it carries an ErrorDetail. This overload never throws.
ua::SecPolBasic128Rsa15
class
The deprecated Basic128Rsa15 OPC UA security policy.
Implements the RSA-family SecurityPolicy for the Basic128Rsa15 profile: RSA-PKCS1.5 asymmetric encryption, RSA-SHA1 asymmetric signatures, AES-128-CBC symmetric encryption, and HMAC-SHA1 symmetric signatures. The policy is retained for interoperability only; it is reported as deprecated and should not be selected for new endpoints. Instances are immutable and stateless, so the const accessors are safe to call from any thread.
SecurityPolicy
Functions
SecurityPolicyId id() const override
Returns the policy identifier (Basic128Rsa15).
Returns: The policy identifier (Basic128Rsa15).
String uri() const override
Returns the canonical OPC UA security policy URI for Basic128Rsa15.
Returns: The canonical OPC UA security-policy URI for Basic128Rsa15.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (RSA).
Returns: The RSA certificate type required by this policy.
bool is_authenticated() const override
Returns whether the policy provides message authentication.
Returns: true if the policy provides message authentication.
bool uses_legacy_sequence_no() const override
Returns whether the policy uses the legacy sequence-number handling.
Returns: true if the policy uses the legacy sequence-number handling.
bool is_deprecated() const override
Returns whether the policy is deprecated; always true for Basic128Rsa15.
Returns: true; Basic128Rsa15 is deprecated.
size_t nonce_length() const override
Returns the length in bytes of the nonce exchanged during channel setup.
Returns: The nonce length exchanged during channel setup, in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size, in bytes.
Returns: The symmetric cipher plaintext block size, in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric plaintext block size for the given certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose key length sizes the block; not retained.
Returns: The plaintext block size in bytes.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size, in bytes.
Returns: The symmetric cipher ciphertext block size, in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric ciphertext block size for the given certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose key length sizes the block; not retained.
Returns: The ciphertext block size in bytes.
size_t symmetric_signature_size() const override
Returns the symmetric signature size, in bytes.
Returns: The symmetric signature size, in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size for the given certificate, in bytes.
certificate(const X509Certificate *) - Peer certificate whose key length sizes the signature; not retained.
Returns: The signature size in bytes.
size_t symmetric_signature_key_size() const override
Returns the symmetric signing key size, in bytes.
Returns: The symmetric signing key size, in bytes.
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size, in bytes.
Returns: The symmetric encryption key size, in bytes.
size_t symmetric_iv_size() const override
Returns the symmetric initialization-vector size, in bytes.
Returns: The symmetric initialization-vector size, in bytes.
size_t min_asymmetric_key_length() const override
Returns the minimum accepted asymmetric (RSA) key length, in bits.
Returns: The minimum accepted asymmetric (RSA) key length, in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum accepted asymmetric (RSA) key length, in bits.
Returns: The maximum accepted asymmetric (RSA) key length, in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm (RSA-PKCS1.5).
Returns: The asymmetric encryption algorithm (RSA-PKCS1.5).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm (RSA-SHA1).
Returns: The asymmetric signature algorithm (RSA-SHA1).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying the asymmetric signature algorithm.
Returns: The URI identifying the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm (AES-128-CBC).
Returns: The symmetric encryption algorithm (AES-128-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm (HMAC-SHA1).
Returns: The symmetric signature algorithm (HMAC-SHA1).
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric key sets for a secure channel from the exchanged nonces.
context(shared_ptr< SecureChannelContext >) - Secure channel context for which keys are derived; retained for the duration of the asynchronous flow.localNonce(ByteString) - Nonce generated by this endpoint.remoteNonce(ByteString) - Nonce received from the peer.role(ChannelRole) - Whether this endpoint is the server or the client, fixing nonce ordering.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the Result holds the derived { local, remote } key pair; on failure it carries an ErrorDetail. This overload never throws.
ua::SecPolBasic256
class
The OPC UA Basic256 security policy (RSA family).
Implements SecurityPolicy for the Basic256 suite: RSA-OAEP (SHA-1) asymmetric encryption, RSA-PKCS#1 v1.5 SHA-1 asymmetric signatures, AES-256-CBC symmetric encryption, and HMAC-SHA-1 symmetric signatures. The accessors below report the fixed cryptographic parameters of this suite and key derivation uses the P-SHA1 scheme.
This policy is deprecated by the OPC UA specification (SHA-1 is no longer considered secure); prefer SecPolBasic256Sha256 or an AES-GCM policy for new deployments. It remains for interoperability with legacy peers.
Instances are stateless and created via SecurityPolicy::create.
SecurityPolicy, SecPolBasic256Sha256
Functions
SecurityPolicyId id() const override
Returns the policy identifier, SecurityPolicyId::Basic256.
Returns: SecurityPolicyId::Basic256.
String uri() const override
Returns the policy URI string that identifies Basic256 on the wire.
Returns: The Basic256 security policy URI.
CertificateType certificate_type() const override
Returns the certificate type this policy requires (RSA).
Returns: The required certificate type (RSA).
bool is_authenticated() const override
Reports whether the policy provides authentication (signing).
Returns: true; Basic256 signs message chunks.
bool uses_legacy_sequence_no() const override
Reports whether the policy uses the legacy sequence-number scheme.
Returns: true; Basic256 predates the modern sequence-number rules.
bool is_deprecated() const override
Reports whether the policy is deprecated by the OPC UA specification.
Returns: true; Basic256 relies on SHA-1 and should be avoided for new use.
size_t nonce_length() const override
Returns the required nonce length in bytes for key derivation.
Returns: The nonce length in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size in bytes (AES-256-CBC).
Returns: The symmetric plaintext block size in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric plaintext block size in bytes for the given certificate.
certificate(const X509Certificate *) - Peer certificate whose RSA key size determines the block size; must not be null.
Returns: Maximum plaintext bytes that fit in one RSA-OAEP encryption block.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size in bytes (AES-256-CBC).
Returns: The symmetric ciphertext block size in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric ciphertext block size in bytes for the given certificate.
certificate(const X509Certificate *) - Peer certificate whose RSA key size determines the block size; must not be null.
Returns: Size in bytes of one RSA ciphertext block (the RSA modulus size).
size_t symmetric_signature_size() const override
Returns the symmetric signature size in bytes (HMAC-SHA-1).
Returns: The symmetric signature size in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size in bytes for the given certificate.
certificate(const X509Certificate *) - Signing certificate whose RSA key size determines the signature size; must not be null.
Returns: Size in bytes of one RSA signature (the RSA modulus size).
size_t symmetric_signature_key_size() const override
Returns the symmetric signing key length in bytes (HMAC-SHA-1).
Returns: The symmetric signing key length in bytes.
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key length in bytes (AES-256).
Returns: The symmetric encryption key length in bytes.
size_t symmetric_iv_size() const override
Returns the symmetric initialization vector size in bytes (AES block size).
Returns: The symmetric initialization vector size in bytes.
size_t min_asymmetric_key_length() const override
Returns the minimum permitted RSA key length in bits for this policy.
Returns: The minimum permitted RSA key length in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum permitted RSA key length in bits for this policy.
Returns: The maximum permitted RSA key length in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm (RSA-OAEP with SHA-1).
Returns: The asymmetric encryption algorithm (RSA-OAEP with SHA-1).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm (RSA-PKCS#1 v1.5 with SHA-1).
Returns: The asymmetric signature algorithm (RSA-PKCS#1 v1.5 with SHA-1).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying the asymmetric signature algorithm on the wire.
Returns: The URI identifying the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm (AES-256-CBC).
Returns: The symmetric encryption algorithm (AES-256-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm (HMAC-SHA-1).
Returns: The symmetric signature algorithm (HMAC-SHA-1).
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric session keys for a secure channel from the exchanged nonces.
context(shared_ptr< SecureChannelContext >) - Secure channel context the derived keys belong to; must outlive the operation.localNonce(ByteString) - Nonce generated by this endpoint.remoteNonce(ByteString) - Nonce received from the peer.role(ChannelRole) - Whether this endpoint is the server or the client, which fixes the nonce ordering per the spec.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the Result holds the {local, remote} key pair; on failure it carries an ErrorDetail. This overload never throws.
ua::SecPolBasic256Sha256
class
The Basic256Sha256 OPC UA security policy.
Implements the RSA-family security policy http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256: RSA-OAEP (SHA-1) asymmetric encryption, RSA-PKCS#1.5 (SHA-256) asymmetric signatures, AES-256-CBC symmetric encryption, and HMAC-SHA-256 symmetric signatures, with P-SHA-256 key derivation. Instances are immutable and stateless; the cryptographic parameters reported by the accessors are fixed by the policy and do not depend on instance state. Obtain one via SecurityPolicy::create rather than constructing it directly.
SecPolRsa, SecurityPolicy
Functions
SecurityPolicyId id() const override
Returns the policy identifier, SecurityPolicyId::Basic256Sha256.
Returns: SecurityPolicyId::Basic256Sha256.
String uri() const override
Returns the policy URI, http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256.
Returns: The Basic256Sha256 security policy URI.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (RSA-SHA-256).
Returns: The required certificate type (RSA-SHA-256).
bool is_authenticated() const override
Returns whether the policy authenticates message exchanges; always true for Basic256Sha256.
Returns: true; Basic256Sha256 signs message chunks.
bool uses_legacy_sequence_no() const override
Returns whether the policy uses the legacy (pre-1.04) sequence-number handling.
Returns: true; Basic256Sha256 uses the legacy sequence-number scheme.
size_t nonce_length() const override
Returns the length in bytes of the nonces exchanged during secure-channel setup.
Returns: The nonce length in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric plaintext block size in bytes (AES block size).
Returns: The symmetric plaintext block size in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric plaintext block size in bytes for the given certificate's key.
certificate(const X509Certificate *) - Certificate whose public key determines the modulus length. Must be non-null; not retained beyond the call.
Returns: The usable plaintext block size in bytes.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric ciphertext block size in bytes (AES block size).
Returns: The symmetric ciphertext block size in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric ciphertext block size in bytes for the given certificate's key.
certificate(const X509Certificate *) - Certificate whose public key determines the modulus length. Must be non-null; not retained beyond the call.
Returns: The ciphertext block size in bytes.
size_t symmetric_signature_size() const override
Returns the symmetric signature (HMAC-SHA-256) size in bytes.
Returns: The symmetric signature (HMAC-SHA-256) size in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size in bytes for the given certificate's key.
certificate(const X509Certificate *) - Certificate whose public key determines the signature length. Must be non-null; not retained beyond the call.
Returns: The asymmetric signature size in bytes.
size_t symmetric_signature_key_size() const override
Returns the size in bytes of the derived symmetric signing key.
Returns: The symmetric signing key size in bytes.
size_t symmetric_encryption_key_size() const override
Returns the size in bytes of the derived symmetric encryption key (32 bytes for AES-256).
Returns: The symmetric encryption key size in bytes (32 for AES-256).
size_t symmetric_iv_size() const override
Returns the size in bytes of the symmetric initialisation vector (AES block size).
Returns: The symmetric initialisation vector size in bytes.
size_t min_asymmetric_key_length() const override
Returns the minimum permitted asymmetric (RSA) key length in bits.
Returns: The minimum permitted RSA key length in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum permitted asymmetric (RSA) key length in bits.
Returns: The maximum permitted RSA key length in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm used by this policy (RSA-OAEP with SHA-1).
Returns: The asymmetric encryption algorithm (RSA-OAEP with SHA-1).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (RSA-PKCS#1.5 with SHA-256).
Returns: The asymmetric signature algorithm (RSA-PKCS#1.5 with SHA-256).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying the asymmetric signature algorithm.
Returns: The URI identifying the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (AES-256-CBC).
Returns: The symmetric encryption algorithm (AES-256-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (HMAC-SHA-256).
Returns: The symmetric signature algorithm (HMAC-SHA-256).
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric signing, encryption, and IV keys for both directions of the channel.
context(shared_ptr< SecureChannelContext >) - Secure-channel context the derivation runs against; shared ownership is held for the duration of the operation.localNonce(ByteString) - Nonce generated by this endpoint.remoteNonce(ByteString) - Nonce received from the peer.role(ChannelRole) - Whether this endpoint acts as ChannelRole::Server or ChannelRole::Client, which fixes the nonce ordering.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the Result holds the derived local and remote key sets; on failure it carries an ErrorDetail. This overload never throws.
ua::SecPolEcc
class
Shared base for the elliptic-curve (ECC) OPC UA security policies.
Implements the parts of SecurityPolicy common to every ECC curve and cipher suite (NIST P-256/P-384, Brainpool, Curve25519/448), and leaves the per-suite choices - ephemeral-key algorithm, certificate-key algorithm, key derivation hash and AEAD vs. CBC framing - as pure-virtual hooks for the concrete curve subclasses to supply.
Instances are immutable after construction and shared via shared_ptr<SecurityPolicy>; all members are safe to call concurrently from any thread.
SecurityPolicy, SecPolRsa
Static functions
ByteString construct_per_message_iv(span< const byte > baseIv, uint32_t tokenId, uint32_t sequenceNumber)
Builds the per-message initialization vector from the channel base IV and counters.
baseIv(span< const byte >) - The security token's base initialization vector.tokenId(uint32_t) - Identifier of the active security token.sequenceNumber(uint32_t) - Per-message sequence number.
Returns: The constructed per-message IV.
Functions
bool is_rsa() const override
Returns false: ECC policies are never RSA-based.
Returns: false; ECC policies are never RSA-based.
bool is_ecc() const override
Returns true: every policy in this family is elliptic-curve based.
Returns: true; every policy in this family is elliptic-curve based.
bool is_authenticated() const override
Reports whether the policy authenticates the peer at the channel layer.
Returns: true if the policy authenticates the peer at the channel layer.
bool is_deprecated() const override
Reports whether the policy is deprecated by the OPC UA specification.
Returns: true if the policy is deprecated by the OPC UA specification.
bool uses_legacy_sequence_no() const override
Reports whether the policy uses the legacy (pre-1.04) sequence-number scheme.
Returns: true if the policy uses the legacy (pre-1.04) sequence-number scheme.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the asymmetric encryption algorithm used for the handshake.
Returns: The asymmetric encryption algorithm; a no-encryption variant, as ECC policies perform no asymmetric message encryption.
size_t min_asymmetric_key_length() const override
Returns the minimum permitted asymmetric (certificate) key length, in bits.
Returns: The minimum permitted asymmetric (certificate) key length, in bits.
size_t max_asymmetric_key_length() const override
Returns the maximum permitted asymmetric (certificate) key length, in bits.
Returns: The maximum permitted asymmetric (certificate) key length, in bits.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric plaintext block size, in bytes, for certificate.
certificate(const X509Certificate *) - Peer certificate whose key sizes the block size, or nullptr to size against the policy's own key parameters.
Returns: The asymmetric plaintext block size, in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric ciphertext block size, in bytes, for certificate.
certificate(const X509Certificate *) - Peer certificate whose key sizes the block size, or nullptr to size against the policy's own key parameters.
Returns: The asymmetric ciphertext block size, in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size, in bytes, for certificate.
certificate(const X509Certificate *) - Peer certificate whose key sizes the signature, or nullptr to size against the policy's own key parameters.
Returns: The asymmetric signature size, in bytes.
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric channel keys from the agreed ECDH nonces.
context(shared_ptr< SecureChannelContext >) - Secure-channel context the derived keys belong to; kept alive for the duration of the call.localNonce(ByteString) - This endpoint's ephemeral nonce.remoteNonce(ByteString) - The peer's ephemeral nonce.role(ChannelRole) - Whether this endpoint is the server or the client; selects the nonce ordering required by the spec.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome: on success the DeriveSymmetricKeysResult holds the (local, remote) key pair; on failure it carries an ErrorDetail. This overload never throws.
EphemeralKeyAlgorithm ephemeral_key_algorithm() const =0
Returns the ephemeral-key (ECDH) algorithm used for key agreement.
Returns: The ephemeral-key (ECDH) key-agreement algorithm.
CertificateKeyAlgorithm certificate_key_algorithm() const =0
Returns the algorithm of the long-term certificate key required by this policy.
Returns: The required certificate key algorithm.
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const =0
Returns the certificate key algorithms permitted for remote certificates under this policy.
Returns: The permitted certificate key algorithms, in preference order.
HashAlgorithm key_derivation_hash() const =0
Returns the hash algorithm used by the key-derivation function.
Returns: The hash algorithm used by the key-derivation function.
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const =0
Returns the symmetric key-derivation algorithm (the KDF) this policy applies.
Returns: The symmetric key-derivation algorithm (the KDF) this policy applies.
bool uses_aead() const =0
Reports whether the policy uses authenticated encryption with associated data (AEAD).
Returns: true for AEAD suites (e.g. ChaCha20-Poly1305), false for encrypt-then-MAC (CBC) suites.
void construct_per_message_signing_key_async(const Crypto &crypto, std::optional< boost::asio::strand< boost::asio::any_io_executor > > strand, span< const byte > baseKey, uint32_t tokenId, uint32_t sequenceNumber, std::function< void(ByteStringResult)> callback) const
Derives the per-message signing key from the token's base signing key.
crypto(const Crypto &) - Crypto provider used to run the derivation.strand(std::optional< boost::asio::strand< boost::asio::any_io_executor > >) - Optional strand on which to post the callback; pass std::nullopt to run inline on the completing thread.baseKey(span< const byte >) - The token's base signing key; viewed, not copied - must stay valid until the callback runs.tokenId(uint32_t) - Identifier of the active security token.sequenceNumber(uint32_t) - Per-message sequence number.callback(std::function< void(ByteStringResult)>) - Receives the outcome: on success the ByteStringResult holds the derived signing key; on failure it carries an ErrorDetail. Never throws.
ua::SecPolEccAead
class
An ECC security policy whose symmetric layer uses AEAD encryption.
Specialises SecPolEcc for the ECC policies that combine encryption and authentication in a single AEAD pass (AES-GCM) rather than the encrypt-then-MAC scheme used by the legacy policies. Concrete curve-specific policies derive from this class; it overrides only the symmetric message hooks, inheriting all asymmetric handshake behaviour from SecPolEcc.
Functions
bool uses_aead() const override
Reports that this policy authenticates symmetric messages with AEAD.
Returns: Always true; an AEAD tag replaces the separate symmetric signature.
ua::SecPolEccBrainpoolP256r1
class
The OPC UA ECC_brainpoolP256r1 security policy.
A concrete CBC-mode elliptic-curve policy bound to the Brainpool P-256r1 (256-bit) curve, SHA-256 hashing, and AES-128-CBC symmetric encryption. Each method returns a fixed policy parameter prescribed by OPC UA Part 7 for this policy; instances are stateless and the accessors are safe to call from any thread.
Functions
SecurityPolicyId id() const override
Returns the security policy identifier for this policy (ECC_brainpoolP256r1).
Returns: The ECC_brainpoolP256r1 security policy identifier.
String uri() const override
Returns the canonical security policy URI for this policy.
Returns: The canonical ECC_brainpoolP256r1 security policy URI.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (a Brainpool P-256 ECC certificate).
Returns: The required certificate type (a Brainpool P-256 ECC certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key agreement algorithm used to establish symmetric keys.
Returns: The ephemeral key agreement algorithm used to establish symmetric keys.
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the key algorithm a certificate must use to be valid under this policy.
Returns: The certificate key algorithm required by this policy.
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms accepted for a remote peer's certificate.
Returns: A view over the accepted peer certificate key algorithms (P-256 and P-384); valid for the lifetime of the policy instance.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used in symmetric key derivation (SHA-256).
Returns: The key-derivation hash algorithm (SHA-256).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key derivation algorithm used to expand the shared secret.
Returns: The symmetric key-derivation algorithm.
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the algorithm used to sign and verify asymmetric (handshake) messages.
Returns: The asymmetric (handshake) signature algorithm.
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying this policy's asymmetric signature algorithm.
Returns: The URI identifying this policy's asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used for message bodies (AES-128-CBC).
Returns: The symmetric encryption algorithm (AES-128-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature (MAC) algorithm used for message bodies.
Returns: The symmetric signature (MAC) algorithm.
size_t nonce_length() const override
Returns the length, in bytes, of the nonces exchanged during key derivation.
Returns: The nonce length in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher's plaintext block size, in bytes.
Returns: The symmetric plaintext block size in bytes.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher's ciphertext block size, in bytes.
Returns: The symmetric ciphertext block size in bytes.
size_t symmetric_signature_size() const override
Returns the size, in bytes, of a symmetric message signature (MAC).
Returns: The symmetric signature (MAC) size in bytes.
size_t symmetric_signature_key_size() const override
Returns the size, in bytes, of the symmetric signing (MAC) key.
Returns: The symmetric signing (MAC) key size in bytes.
size_t symmetric_encryption_key_size() const override
Returns the size, in bytes, of the symmetric encryption key.
Returns: The symmetric encryption key size in bytes.
size_t symmetric_iv_size() const override
Returns the size, in bytes, of the symmetric encryption initialization vector.
Returns: The symmetric encryption initialization vector size in bytes.
ua::SecPolEccBrainpoolP384r1
class
The ECC_brainpoolP384r1 elliptic-curve OPC UA security policy.
Implements the cryptographic parameters and key derivation defined by the http://opcfoundation.org/UA/SecurityPolicy#ECC_brainpoolP384r1 profile: ephemeral ECDH and ECDSA (SHA-384) over the Brainpool P-384r1 curve, HKDF-SHA-384 key derivation, AES-256-CBC symmetric encryption, and HMAC-SHA-384 symmetric signatures.
Instances are immutable and stateless; the same policy object may be shared across secure channels and called concurrently from any thread. SecurityPolicy, SecPolEcc, SecPolEccCbc
Functions
SecurityPolicyId id() const override
Returns the policy identifier (SecurityPolicyId::EccBrainpoolP384r1).
Returns: The policy identifier, SecurityPolicyId::EccBrainpoolP384r1.
String uri() const override
Returns the OPC UA security policy URI for this policy.
Returns: The ECC_brainpoolP384r1 security policy URI.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (Brainpool P-384r1 application certificate).
Returns: The required certificate type (Brainpool P-384r1 application certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key-agreement algorithm used by this policy (ECDH over Brainpool P-384r1).
Returns: The ephemeral key-agreement algorithm (ECDH over Brainpool P-384r1).
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the certificate key algorithm required by this policy (Brainpool P-384r1).
Returns: The required certificate key algorithm (Brainpool P-384r1).
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms permitted for remote certificates under this policy.
Returns: A view over a static, single-element list containing only Brainpool P-384r1; the referenced storage outlives the policy and is never reallocated.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used by the key-derivation function (SHA-384).
Returns: The key-derivation hash algorithm (SHA-384).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key-derivation algorithm used by this policy (HKDF-SHA-384).
Returns: The symmetric key-derivation algorithm (HKDF-SHA-384).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (ECDSA, SHA-384).
Returns: The asymmetric signature algorithm (ECDSA, SHA-384).
String asymmetric_signature_algorithm_uri() const override
Returns the OPC UA URI of the asymmetric signature algorithm.
Returns: The URI of the asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (AES-256-CBC).
Returns: The symmetric encryption algorithm (AES-256-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (HMAC-SHA-384).
Returns: The symmetric signature algorithm (HMAC-SHA-384).
size_t nonce_length() const override
Returns the required length, in bytes, of the secure-channel nonce.
Returns: The nonce length in bytes.
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size, in bytes.
Returns: The symmetric plaintext block size in bytes.
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size, in bytes.
Returns: The symmetric ciphertext block size in bytes.
size_t symmetric_signature_size() const override
Returns the symmetric signature (MAC) size, in bytes.
Returns: The symmetric signature (MAC) size in bytes.
size_t symmetric_signature_key_size() const override
Returns the symmetric signing (MAC) key size, in bytes.
Returns: The symmetric signing (MAC) key size in bytes.
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size, in bytes.
Returns: The symmetric encryption key size in bytes.
size_t symmetric_iv_size() const override
Returns the symmetric initialization-vector size, in bytes.
Returns: The symmetric initialization-vector size in bytes.
ua::SecPolEccCbc
class
Base for ECC security policies that protect symmetric messages with a CBC block cipher.
Specialises SecPolEcc for the non-AEAD branch: symmetric chunks are encrypted with a CBC-mode block cipher and authenticated by a separate HMAC, rather than by an authenticated cipher. The AEAD counterpart is SecPolEccAead. Concrete curve policies (NIST P-256/P-384, Brainpool) derive from this class; it is an intermediate base and is not instantiated directly. Instances are immutable and stateless, so a single instance is safe to share across secure channels and threads.
SecPolEcc, SecPolEccAead
Functions
bool uses_aead() const override
Reports whether this policy uses an authenticated cipher (AEAD); always false for CBC.
Returns: Always false; a separate HMAC authenticates each CBC-encrypted chunk.
ua::SecPolEccCurve25519ChaCha20Poly1305
class
The ECC_curve25519_ChaCha20Poly1305 OPC UA security policy.
Implements the ECC AEAD security policy http://opcfoundation.org/UA/SecurityPolicy#ECC_curve25519_ChaCha20Poly1305: X25519 ephemeral key agreement, Ed25519 (PureEdDSA) asymmetric signatures, and ChaCha20-Poly1305 authenticated symmetric encryption, with HKDF-SHA-256 key derivation. As an AEAD policy, confidentiality and integrity are provided together by the single ChaCha20-Poly1305 transform rather than by separate encryption and signing passes. Instances are immutable and stateless; the cryptographic parameters reported by the accessors are fixed by the policy and do not depend on instance state. Obtain one via SecurityPolicy::create rather than constructing it directly.
SecPolEccAead, SecPolEccCurve448ChaCha20Poly1305, SecurityPolicy
Functions
SecurityPolicyId id() const override
Returns the policy identifier, SecurityPolicyId::EccCurve25519ChaCha20Poly1305.
Returns: The identifier SecurityPolicyId::EccCurve25519ChaCha20Poly1305.
String uri() const override
Returns the policy URI, http://opcfoundation.org/UA/SecurityPolicy#ECC_curve25519_ChaCha20Poly1305.
Returns: The URI http://opcfoundation.org/UA/SecurityPolicy#ECC_curve25519_ChaCha20Poly1305.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (Curve25519 application certificate).
Returns: The required certificate type (Curve25519 application certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key-agreement algorithm used by this policy (X25519).
Returns: The ephemeral key-agreement algorithm (X25519).
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the certificate key algorithm required by this policy (Curve25519).
Returns: The required certificate key algorithm (Curve25519).
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms permitted for remote certificates under this policy.
Returns: A span over a static, immutable list; valid for the program lifetime.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used by the key-derivation function (SHA-256).
Returns: The key-derivation hash algorithm (SHA-256).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key-derivation algorithm used by this policy (HKDF-SHA-256).
Returns: The symmetric key-derivation algorithm (HKDF-SHA-256).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (Ed25519, PureEdDSA).
Returns: The asymmetric signature algorithm (Ed25519, PureEdDSA).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying the asymmetric signature algorithm, http://opcfoundation.org/UA/security/PureEdDsa25519.
Returns: The URI http://opcfoundation.org/UA/security/PureEdDsa25519.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (ChaCha20-Poly1305 AEAD).
Returns: The symmetric encryption algorithm (ChaCha20-Poly1305 AEAD).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (Poly1305 authentication tag).
Returns: The symmetric signature algorithm (Poly1305 authentication tag).
size_t nonce_length() const override
Returns the length in bytes of the nonces exchanged during secure-channel setup.
Returns: The nonce length in bytes (32).
size_t symmetric_plaintext_block_size() const override
Returns the symmetric plaintext block size in bytes.
Returns: The symmetric plaintext block size in bytes (1).
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric ciphertext block size in bytes.
Returns: The symmetric ciphertext block size in bytes (1).
size_t symmetric_signature_size() const override
Returns the symmetric signature size in bytes (the 16-byte Poly1305 authentication tag).
Returns: The symmetric signature size in bytes (16).
size_t symmetric_signature_key_size() const override
Returns the size in bytes of the derived symmetric signing key.
Returns: The symmetric signing-key size in bytes (32).
size_t symmetric_encryption_key_size() const override
Returns the size in bytes of the derived symmetric encryption key (32 bytes for ChaCha20).
Returns: The symmetric encryption-key size in bytes (32).
size_t symmetric_iv_size() const override
Returns the size in bytes of the symmetric initialisation vector (12-byte ChaCha20 nonce).
Returns: The symmetric IV size in bytes (12).
ua::SecPolEccCurve448ChaCha20Poly1305
class
The ECC_curve448_ChaCha20Poly1305 OPC UA security policy.
Implements the ECC AEAD policy http://opcfoundation.org/UA/SecurityPolicy#ECC_curve448_ChaCha20Poly1305: Curve448 (X448) ephemeral key agreement, Ed448 (PureEdDSA) asymmetric signatures, and ChaCha20-Poly1305 authenticated symmetric encryption, with HKDF-SHA-256 key derivation. As an AEAD policy, confidentiality and integrity are provided together by the single ChaCha20-Poly1305 transform rather than by separate encryption and signing passes; the AEAD message hooks are inherited from SecPolEccAead. Instances are immutable and stateless, so the same policy object may be shared across secure channels and called concurrently from any thread. Obtain one via SecurityPolicy::create rather than constructing it directly.
SecPolEccAead, SecPolEccCurve25519ChaCha20Poly1305, SecurityPolicy
Functions
SecurityPolicyId id() const override
Returns the policy identifier, SecurityPolicyId::EccCurve448ChaCha20Poly1305.
Returns: The identifier SecurityPolicyId::EccCurve448ChaCha20Poly1305.
String uri() const override
Returns the policy URI, http://opcfoundation.org/UA/SecurityPolicy#ECC_curve448_ChaCha20Poly1305.
Returns: The URI http://opcfoundation.org/UA/SecurityPolicy#ECC_curve448_ChaCha20Poly1305.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (Curve448 application certificate).
Returns: The required certificate type (Curve448 application certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key-agreement algorithm used by this policy (X448).
Returns: The ephemeral key-agreement algorithm (X448).
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the certificate key algorithm required by this policy (Curve448).
Returns: The required certificate key algorithm (Curve448).
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms permitted for remote certificates under this policy.
Returns: A span over a static, immutable list; valid for the program lifetime.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used by the key-derivation function (SHA-256).
Returns: The key-derivation hash algorithm (SHA-256).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key-derivation algorithm used by this policy (HKDF-SHA-256).
Returns: The symmetric key-derivation algorithm (HKDF-SHA-256).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (Ed448, PureEdDSA).
Returns: The asymmetric signature algorithm (Ed448, PureEdDSA).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying the asymmetric signature algorithm, http://opcfoundation.org/UA/security/PureEdDsa448.
Returns: The URI http://opcfoundation.org/UA/security/PureEdDsa448.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (ChaCha20-Poly1305 AEAD).
Returns: The symmetric encryption algorithm (ChaCha20-Poly1305 AEAD).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (Poly1305 authentication tag).
Returns: The symmetric signature algorithm (Poly1305 authentication tag).
size_t nonce_length() const override
Returns the length in bytes of the nonces exchanged during secure-channel setup.
Returns: The nonce length in bytes (56).
size_t symmetric_plaintext_block_size() const override
Returns the symmetric plaintext block size in bytes.
Returns: The symmetric plaintext block size in bytes (1).
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric ciphertext block size in bytes.
Returns: The symmetric ciphertext block size in bytes (1).
size_t symmetric_signature_size() const override
Returns the symmetric signature size in bytes (the 16-byte Poly1305 authentication tag).
Returns: The symmetric signature size in bytes (16).
size_t symmetric_signature_key_size() const override
Returns the size in bytes of the derived symmetric signing key.
Returns: The symmetric signing-key size in bytes (32).
size_t symmetric_encryption_key_size() const override
Returns the size in bytes of the derived symmetric encryption key (32 bytes for ChaCha20).
Returns: The symmetric encryption-key size in bytes (32).
size_t symmetric_iv_size() const override
Returns the size in bytes of the symmetric initialisation vector (12-byte ChaCha20 nonce).
Returns: The symmetric IV size in bytes (12).
ua::SecPolEccNistP256
class
The OPC UA ECC_nistP256 security policy.
A concrete CBC-mode elliptic-curve policy bound to the NIST P-256 (secp256r1, 256-bit) curve, SHA-256 hashing, and AES-128-CBC symmetric encryption. Each method returns a fixed policy parameter prescribed by OPC UA Part 7 for this policy; instances are stateless and the accessors are safe to call from any thread.
Functions
SecurityPolicyId id() const override
Returns the security policy identifier for this policy (ECC_nistP256).
Returns: The identifier SecurityPolicyId::EccNistP256.
String uri() const override
Returns the canonical security policy URI for this policy.
Returns: The URI http://opcfoundation.org/UA/SecurityPolicy#ECC_nistP256.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (a NIST P-256 ECC certificate).
Returns: The required certificate type (NIST P-256 application certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key agreement algorithm used to establish symmetric keys.
Returns: The ephemeral ECDH key-agreement algorithm over NIST P-256.
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the key algorithm a certificate must use to be valid under this policy.
Returns: The required certificate key algorithm (NIST P-256).
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms accepted for a remote peer's certificate.
Returns: The accepted certificate key algorithms (NIST P-256 and P-384), in preference order.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used in symmetric key derivation (SHA-256).
Returns: The key-derivation hash algorithm (SHA-256).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key derivation algorithm used to expand the shared secret.
Returns: The symmetric key-derivation algorithm (HKDF-SHA-256).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the algorithm used to sign and verify asymmetric (handshake) messages.
Returns: The asymmetric handshake signature algorithm (ECDSA, SHA-256).
String asymmetric_signature_algorithm_uri() const override
Returns the URI identifying this policy's asymmetric signature algorithm.
Returns: The URI of this policy's asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used for message bodies (AES-128-CBC).
Returns: The symmetric encryption algorithm (AES-128-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature (MAC) algorithm used for message bodies.
Returns: The symmetric signature (MAC) algorithm (HMAC-SHA-256).
size_t nonce_length() const override
Returns the nonce length in bytes (65 - an uncompressed P-256 public key: 1 + 32 + 32).
Returns: The nonce length in bytes (65).
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher's plaintext block size in bytes (16, the AES block size).
Returns: The symmetric plaintext block size in bytes (16).
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher's ciphertext block size in bytes (16, the AES block size).
Returns: The symmetric ciphertext block size in bytes (16).
size_t symmetric_signature_size() const override
Returns the symmetric message signature (MAC) size in bytes (32, the SHA-256 output).
Returns: The symmetric signature size in bytes (32).
size_t symmetric_signature_key_size() const override
Returns the symmetric signing (MAC) key size in bytes (32).
Returns: The symmetric signing-key size in bytes (32).
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size in bytes (16, for AES-128).
Returns: The symmetric encryption-key size in bytes (16).
size_t symmetric_iv_size() const override
Returns the symmetric encryption IV size in bytes (16, the AES block size).
Returns: The symmetric IV size in bytes (16).
ua::SecPolEccNistP384
class
The ECC_nistP384 elliptic-curve OPC UA security policy.
Implements the cryptographic parameters and key derivation defined by the http://opcfoundation.org/UA/SecurityPolicy#ECC_nistP384 profile: ephemeral ECDH and ECDSA (SHA-384) over the NIST P-384 (secp384r1) curve, HKDF-SHA-384 key derivation, AES-256-CBC symmetric encryption, and HMAC-SHA-384 symmetric signatures.
Instances are immutable and stateless; the same policy object may be shared across secure channels and called concurrently from any thread. SecurityPolicy, SecPolEcc, SecPolEccCbc
Functions
SecurityPolicyId id() const override
Returns the policy identifier (SecurityPolicyId::EccNistP384).
Returns: The identifier SecurityPolicyId::EccNistP384.
String uri() const override
Returns the OPC UA security policy URI for this policy.
Returns: The URI http://opcfoundation.org/UA/SecurityPolicy#ECC_nistP384.
CertificateType certificate_type() const override
Returns the certificate type required by this policy (NIST P-384 application certificate).
Returns: The required certificate type (NIST P-384 application certificate).
EphemeralKeyAlgorithm ephemeral_key_algorithm() const override
Returns the ephemeral key-agreement algorithm used by this policy (ECDH over NIST P-384).
Returns: The ephemeral ECDH key-agreement algorithm over NIST P-384.
CertificateKeyAlgorithm certificate_key_algorithm() const override
Returns the certificate key algorithm required by this policy (NIST P-384).
Returns: The required certificate key algorithm (NIST P-384).
std::span< const CertificateKeyAlgorithm > permitted_certificate_key_algorithms() const override
Returns the certificate key algorithms permitted for remote certificates under this policy.
Returns: A view over a static, single-element list containing only NIST P-384; the referenced storage outlives the policy and is never reallocated.
HashAlgorithm key_derivation_hash() const override
Returns the hash algorithm used by the key-derivation function (SHA-384).
Returns: The key-derivation hash algorithm (SHA-384).
SymmetricKeyDerivationAlgorithm key_derivation_algorithm() const override
Returns the symmetric key-derivation algorithm used by this policy (HKDF-SHA-384).
Returns: The symmetric key-derivation algorithm (HKDF-SHA-384).
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the asymmetric signature algorithm used by this policy (ECDSA, SHA-384).
Returns: The asymmetric signature algorithm (ECDSA, SHA-384).
String asymmetric_signature_algorithm_uri() const override
Returns the OPC UA URI of the asymmetric signature algorithm.
Returns: The URI of this policy's asymmetric signature algorithm.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the symmetric encryption algorithm used by this policy (AES-256-CBC).
Returns: The symmetric encryption algorithm (AES-256-CBC).
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the symmetric signature algorithm used by this policy (HMAC-SHA-384).
Returns: The symmetric signature (MAC) algorithm (HMAC-SHA-384).
size_t nonce_length() const override
Returns the required nonce length in bytes (97 - an uncompressed NIST P-384 ephemeral public key: 1 + 48 + 48).
Returns: The nonce length in bytes (97).
size_t symmetric_plaintext_block_size() const override
Returns the symmetric cipher plaintext block size in bytes (16, the AES block size).
Returns: The symmetric plaintext block size in bytes (16).
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric cipher ciphertext block size in bytes (16, the AES block size).
Returns: The symmetric ciphertext block size in bytes (16).
size_t symmetric_signature_size() const override
Returns the symmetric signature (MAC) size in bytes (48, the SHA-384 output).
Returns: The symmetric signature size in bytes (48).
size_t symmetric_signature_key_size() const override
Returns the symmetric signing (MAC) key size in bytes (48).
Returns: The symmetric signing-key size in bytes (48).
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size in bytes (32, for AES-256).
Returns: The symmetric encryption-key size in bytes (32).
size_t symmetric_iv_size() const override
Returns the symmetric initialization-vector size in bytes (16, the AES block size).
Returns: The symmetric IV size in bytes (16).
ua::SecPolNone
class
The OPC UA SecurityPolicy#None policy: messages are neither signed nor encrypted.
This policy applies no cryptography. Secure channels using it transmit plaintext, perform no certificate-based authentication, and derive no symmetric keys. The signature, key, and nonce accessors report zero and the algorithm accessors report the "no algorithm" variants; the block-size accessors report 1 (a unit block keeps the chunk-size arithmetic well-defined with no cipher). Use it only where confidentiality and integrity are provided by another layer (or are not required).
Instances are obtained through SecurityPolicy::create rather than constructed directly, and are shared via shared_ptr. Like every SecurityPolicy the object is immutable and stateless, so its methods are safe to call concurrently from any thread.
SecurityPolicy
Functions
SecurityPolicyId id() const override
Returns SecurityPolicyId::None.
Returns: The identifier SecurityPolicyId::None.
String uri() const override
Returns the policy URI http://opcfoundation.org/UA/SecurityPolicy#None.
Returns: The URI http://opcfoundation.org/UA/SecurityPolicy#None.
CertificateType certificate_type() const override
Returns the certificate type required by this policy.
Returns: The certificate type, reflecting that no specific certificate type is required.
bool is_authenticated() const override
Returns false: the None policy performs no certificate-based authentication.
Returns: false; the None policy performs no certificate-based authentication.
bool is_rsa() const override
Returns false: the None policy is not an RSA-family policy.
Returns: false; the None policy is not an RSA-family policy.
bool is_ecc() const override
Returns false: the None policy is not an ECC-family policy.
Returns: false; the None policy is not an ECC-family policy.
bool uses_legacy_sequence_no() const override
Returns false: the None policy uses the modern sequence-number scheme.
Returns: false; the None policy uses the modern sequence-number scheme.
size_t nonce_length() const override
Returns the length, in bytes, of the nonce exchanged during channel setup.
Returns: The nonce length in bytes (0).
size_t symmetric_plaintext_block_size() const override
Returns the symmetric plaintext block size in bytes.
Returns: The symmetric plaintext block size in bytes (1).
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric plaintext block size in bytes.
certificate(const X509Certificate *) - Certificate whose key size would normally determine the block size; ignored by this policy and may be null.
Returns: The asymmetric plaintext block size in bytes (1).
size_t symmetric_ciphertext_block_size() const override
Returns the symmetric ciphertext block size in bytes (1; no cipher, a unit block keeps chunk arithmetic well-defined).
Returns: The symmetric ciphertext block size in bytes (1).
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const override
Returns the asymmetric ciphertext block size in bytes (1; no cipher, a unit block keeps chunk arithmetic well-defined).
certificate(const X509Certificate *) - Certificate whose key size would normally determine the block size; ignored by this policy and may be null.
Returns: The asymmetric ciphertext block size in bytes (1).
size_t symmetric_signature_size() const override
Returns the symmetric signature size in bytes (zero; messages are not signed).
Returns: The symmetric signature size in bytes (0).
size_t asymmetric_signature_size(const X509Certificate *certificate) const override
Returns the asymmetric signature size in bytes (zero; messages are not signed).
certificate(const X509Certificate *) - Signing certificate; ignored by this policy and may be null.
Returns: The asymmetric signature size in bytes (0).
size_t symmetric_signature_key_size() const override
Returns the symmetric signature key size in bytes (zero; no key material is derived).
Returns: The symmetric signature-key size in bytes (0).
size_t symmetric_encryption_key_size() const override
Returns the symmetric encryption key size in bytes (zero; no key material is derived).
Returns: The symmetric encryption-key size in bytes (0).
size_t symmetric_iv_size() const override
Returns the symmetric initialization-vector size in bytes (zero; no symmetric encryption).
Returns: The symmetric IV size in bytes (0).
size_t min_asymmetric_key_length() const override
Returns the minimum accepted asymmetric key length in bits (zero; no asymmetric keys are used).
Returns: The minimum accepted asymmetric key length in bits (0).
size_t max_asymmetric_key_length() const override
Returns the maximum accepted asymmetric key length in bits (zero; no asymmetric keys are used).
Returns: The maximum accepted asymmetric key length in bits (0).
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const override
Returns the none/no-encryption asymmetric algorithm.
Returns: The none/no-encryption AsymmetricEncryptionAlgorithm variant.
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const override
Returns the none/no-signature asymmetric algorithm.
Returns: The none/no-signature AsymmetricSignatureAlgorithm variant.
String asymmetric_signature_algorithm_uri() const override
Returns the asymmetric signature algorithm URI, which is empty for the None policy.
Returns: The asymmetric signature algorithm URI, empty for the None policy.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const override
Returns the none/no-encryption symmetric algorithm.
Returns: The none/no-encryption SymmetricEncryptionAlgorithm variant.
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const override
Returns the none/no-signature symmetric algorithm.
Returns: The none/no-signature SymmetricSignatureAlgorithm variant.
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const override
Derives the symmetric key set for a secure channel.
context(shared_ptr< SecureChannelContext >) - Secure channel context the keys belong to; must outlive the call.localNonce(ByteString) - This endpoint's nonce; ignored by the None policy and may be empty.remoteNonce(ByteString) - The peer's nonce; ignored by the None policy and may be empty.role(ChannelRole) - Whether this endpoint is the channel's server or client.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the derived key pair, or an ErrorDetail on failure.
ua::SecPolRsa
class
Common base for the RSA-family security policies.
Fixes the key-type predicates shared by every RSA-based policy (Basic128Rsa15, Basic256, Basic256Sha256, Aes128_Sha256_RsaOaep, Aes256_Sha256_RsaPss): each derives from this base, which reports RSA asymmetric keying. Concrete policies still supply the algorithm-specific virtuals declared on SecurityPolicy. The ECC counterpart is SecPolEcc.
SecurityPolicy, SecPolEcc
Functions
bool is_rsa() const override
Reports that this policy family uses RSA asymmetric keys.
Returns: Always true for every RSA-family policy.
bool is_ecc() const override
Reports that this policy family does not use ECC asymmetric keys.
Returns: Always false for every RSA-family policy.
ua::EndpointSecurityContext
struct
Sanitized, non-secret security context describing the negotiated endpoint.
This core value is constructed once after endpoint and token-policy selection, then shared unchanged by authentication, Role evaluation, namespace authorization and Session state.
Public attributes
MessageSecurityMode mMessageSecurityMode
Negotiated message security mode of the channel.
SecurityPolicyId mSecurityPolicyId
Negotiated security policy of the channel.
std::string mEndpointPolicyId
Mandatory stable endpoint identifier, formatted as "{listenerName}/{endpointName}".
optional< std::string > mUserTokenPolicyId
UA UserTokenPolicy policyId selected by the stack, or empty if none applied.
String mClientApplicationUri
Certificate-verified calling-client application URI, or empty on an unsecured channel.
String mEndpointUrl
Endpoint URL the client connected to.
String mTransportProfileUri
Transport profile URI of the negotiated channel.
ua::UserIdentity
struct
Stable, SDK-owned identity bound to a Session after successful activation.
Public attributes
std::string mUserId
Stable identifier for the authenticated principal.
std::string mDisplayName
Human-readable name for display and audit.
UserTokenKind mKind
Token family used to authenticate the principal.
std::unordered_map< std::string, std::string > mClaims
Application-defined identity claims, keyed by claim name.
ua::CertificateStore
class
Asynchronous PKI store of trusted, issuer, rejected and application certificates plus their CRLs.
Holds the four OPC UA trust-list groups (trusted, issuer, rejected) together with the application's own certificate/key pairs, and validates peer certificates against them. All mutating and querying operations are exposed as a *_async / sync / try_sync trio: the *_async overloads are the canonical, never-throwing surface that deliver a Result to a callback; the sync and try_sync wrappers block until the async operation completes.
Implementations serialize access internally, so callers may invoke any method from any thread. Callbacks run on an unspecified worker thread and must not block. Certificates and CRLs are held by shared_ptr<const>; ownership is shared and the stored objects are immutable. Instances are managed by shared_ptr (enable_shared_from_this); construct accordingly.
Member types
std::function< void(VoidResult)> CompleteCallback
Callback receiving the outcome of a mutating operation; carries an ErrorDetail on failure.
std::function< void(CertificateListResult)> GetCertificatesCallback
Callback receiving a CertificateList, or an ErrorDetail on failure.
std::function< void(CrlListResult)> GetCrlsCallback
Callback receiving a CrlList, or an ErrorDetail on failure.
Result< ApplicationCertificate > ApplicationCertificateResult
A single ApplicationCertificate, or an ErrorDetail on failure.
std::vector< ApplicationCertificate > ApplicationCertificateList
A list of the store's ApplicationCertificate entries.
Result< ApplicationCertificateList > ApplicationCertificateListResult
An ApplicationCertificateList, or an ErrorDetail on failure.
std::function< void(ApplicationCertificateResult)> GetApplicationCertificateCallback
Callback receiving a single ApplicationCertificate, or an ErrorDetail on failure.
std::function< void(ApplicationCertificateListResult)> GetApplicationCertificatesCallback
Callback receiving an ApplicationCertificateList, or an ErrorDetail on failure.
Functions
~CertificateStore()=default
void shutdown()
Gracefully shuts down the store, cancelling any background work such as refresh timers.
void add_to_application_certificates_async(ApplicationCertificate certificate, CompleteCallback callback) noexcept=0
Adds an application instance certificate and its key pair to the store.
certificate(ApplicationCertificate) - The certificate, key pair and type to store; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_application_certificate_async(CertificateType certificateType, GetApplicationCertificateCallback callback) const noexcept=0
Retrieves the application certificate matching the given certificate type.
certificateType(CertificateType) - Cryptographic profile to look up.callback(GetApplicationCertificateCallback) - Receives the matching ApplicationCertificate, or an ErrorDetail if none is found. Never throws.
void get_application_certificates_async(GetApplicationCertificatesCallback callback) const noexcept=0
Retrieves all application certificates held by the store.
callback(GetApplicationCertificatesCallback) - Receives the ApplicationCertificateList, or an ErrorDetail on failure. Never throws.
void add_to_trusted_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept=0
Adds a certificate to the trusted list.
certificate(shared_ptr< const X509Certificate >) - Certificate to trust; must be non-null.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void add_to_trusted_certificates_async(std::vector< shared_ptr< const X509Certificate > > certificates, CompleteCallback callback) noexcept=0
Adds several certificates to the trusted list in one operation.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Certificates to trust; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_trusted_certificates_async(GetCertificatesCallback callback) const noexcept=0
Retrieves the current trusted certificate list.
callback(GetCertificatesCallback) - Receives the CertificateList, or an ErrorDetail on failure. Never throws.
void add_to_issuer_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept=0
Adds a certificate to the issuer (intermediate CA) list.
certificate(shared_ptr< const X509Certificate >) - Issuer certificate to store; must be non-null.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void add_to_issuer_certificates_async(std::vector< shared_ptr< const X509Certificate > > certificates, CompleteCallback callback) noexcept=0
Adds several certificates to the issuer (intermediate CA) list in one operation.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Issuer certificates to store; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_issuer_certificates_async(GetCertificatesCallback callback) const noexcept=0
Retrieves the current issuer certificate list.
callback(GetCertificatesCallback) - Receives the CertificateList, or an ErrorDetail on failure. Never throws.
void add_to_rejected_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept=0
Records a certificate that failed validation in the rejected list.
certificate(shared_ptr< const X509Certificate >) - Certificate to record as rejected; must be non-null.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_rejected_certificates_async(GetCertificatesCallback callback) const noexcept=0
Retrieves the current rejected certificate list.
callback(GetCertificatesCallback) - Receives the CertificateList, or an ErrorDetail on failure. Never throws.
void add_to_trusted_crls_async(shared_ptr< const X509Crl > crl, CompleteCallback callback) noexcept=0
Adds a CRL to the trusted CRL set.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void add_to_trusted_crls_async(std::vector< shared_ptr< const X509Crl > > crls, CompleteCallback callback) noexcept=0
Adds several CRLs to the trusted CRL set in one operation.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_trusted_crls_async(GetCrlsCallback callback) const noexcept=0
Retrieves the current trusted CRL set.
callback(GetCrlsCallback) - Receives the CrlList, or an ErrorDetail on failure. Never throws.
void add_to_issuer_crls_async(shared_ptr< const X509Crl > crl, CompleteCallback callback) noexcept=0
Adds a CRL to the issuer CRL set.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void add_to_issuer_crls_async(std::vector< shared_ptr< const X509Crl > > crls, CompleteCallback callback) noexcept=0
Adds several CRLs to the issuer CRL set in one operation.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void get_issuer_crls_async(GetCrlsCallback callback) const noexcept=0
Retrieves the current issuer CRL set.
callback(GetCrlsCallback) - Receives the CrlList, or an ErrorDetail on failure. Never throws.
void replace_trusted_certificates_async(CertificateList certificates, CrlList crls, CompleteCallback callback) noexcept=0
Atomically replaces the entire trusted certificate and CRL set.
certificates(CertificateList) - Replacement trusted certificate list; consumed by value.crls(CrlList) - Replacement trusted CRL set; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void replace_issuer_certificates_async(CertificateList certificates, CrlList crls, CompleteCallback callback) noexcept=0
Atomically replaces the entire issuer certificate and CRL set.
certificates(CertificateList) - Replacement issuer certificate list; consumed by value.crls(CrlList) - Replacement issuer CRL set; consumed by value.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void remove_from_trusted_certificates_async(const std::string &thumbprint, CompleteCallback callback) noexcept=0
Removes a single certificate from the trusted list by its SHA-1 thumbprint.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void remove_from_issuer_certificates_async(const std::string &thumbprint, CompleteCallback callback) noexcept=0
Removes a single certificate from the issuer list by its SHA-1 thumbprint.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure. Never throws.
void set_validation_options(TrustListValidationOptions validationOptions)=0
Sets the default validation options applied by validate_certificate_async.
validationOptions(TrustListValidationOptions) - Trust-list validation policy to use as the store default.
void refresh_cache(CompleteCallback callback)=0
Refreshes any cached view of the trust lists from the underlying backing store.
callback(CompleteCallback) - Receives the outcome; carries an ErrorDetail on failure.
void validate_certificate_async(shared_ptr< const X509Certificate > certificate, std::vector< shared_ptr< const X509Certificate > > additionalIssuerCertificates, optional< TrustListValidationOptions > validationOptions, optional< std::string > applicationUri, optional< std::string > endpointUrl, Crypto::CertificateValidationCompleteCallback callback) noexcept=0
Validates a certificate against the store's trusted and issuer lists.
certificate(shared_ptr< const X509Certificate >) - Certificate to validate; must be non-null.additionalIssuerCertificates(std::vector< shared_ptr< const X509Certificate > >) - Extra issuer certificates to consider for chain building beyond those held by the store.validationOptions(optional< TrustListValidationOptions >) - Per-call options; when empty the store default set via set_validation_options applies.applicationUri(optional< std::string >) - Expected application URI to match against the certificate, when present.endpointUrl(optional< std::string >) - Expected endpoint URL to match against the certificate, when present.callback(Crypto::CertificateValidationCompleteCallback) - Receives the outcome; carries an ErrorDetail with the rejection reason on failure. Never throws.
VoidResult try_add_to_application_certificates_sync(ApplicationCertificate certificate) noexcept
Adds an application instance certificate, blocking until complete.
certificate(ApplicationCertificate) - Certificate, key pair and type to store; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_application_certificates_sync(ApplicationCertificate certificate)
Adds an application instance certificate, blocking until complete.
certificate(ApplicationCertificate) - Certificate, key pair and type to store; consumed by value.
ApplicationCertificateResult try_get_application_certificate_sync(CertificateType certificateType) const noexcept
Retrieves the application certificate of the given type, blocking until complete.
certificateType(CertificateType) - Cryptographic profile to look up.
Returns: The matching ApplicationCertificate, or an ErrorDetail on failure. Never throws.
ApplicationCertificate get_application_certificate_sync(CertificateType certificateType) const
Retrieves the application certificate of the given type, blocking until complete.
certificateType(CertificateType) - Cryptographic profile to look up.
Returns: The matching ApplicationCertificate.
ApplicationCertificateListResult try_get_application_certificates_sync() const noexcept
Retrieves all application certificates, blocking until complete.
Returns: The ApplicationCertificateList, or an ErrorDetail on failure. Never throws.
ApplicationCertificateList get_application_certificates_sync() const
Retrieves all application certificates, blocking until complete.
Returns: The ApplicationCertificateList.
VoidResult try_add_to_trusted_certificates_sync(shared_ptr< const X509Certificate > certificate) noexcept
Adds a certificate to the trusted list, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to trust; must be non-null.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_trusted_certificates_sync(shared_ptr< const X509Certificate > certificate)
Adds a certificate to the trusted list, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to trust; must be non-null.
VoidResult try_add_to_trusted_certificates_sync(std::vector< shared_ptr< const X509Certificate > > certificates) noexcept
Adds several certificates to the trusted list, blocking until complete.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Certificates to trust; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_trusted_certificates_sync(std::vector< shared_ptr< const X509Certificate > > certificates)
Adds several certificates to the trusted list, blocking until complete.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Certificates to trust; consumed by value.
CertificateListResult try_get_trusted_certificates_sync() const noexcept
Retrieves the trusted certificate list, blocking until complete.
Returns: The CertificateList, or an ErrorDetail on failure. Never throws.
CertificateList get_trusted_certificates_sync() const
Retrieves the trusted certificate list, blocking until complete.
Returns: The CertificateList.
VoidResult try_add_to_issuer_certificates_sync(shared_ptr< const X509Certificate > certificate) noexcept
Adds a certificate to the issuer list, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Issuer certificate to store; must be non-null.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_issuer_certificates_sync(shared_ptr< const X509Certificate > certificate)
Adds a certificate to the issuer list, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Issuer certificate to store; must be non-null.
VoidResult try_add_to_issuer_certificates_sync(std::vector< shared_ptr< const X509Certificate > > certificates) noexcept
Adds several certificates to the issuer list, blocking until complete.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Issuer certificates to store; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_issuer_certificates_sync(std::vector< shared_ptr< const X509Certificate > > certificates)
Adds several certificates to the issuer list, blocking until complete.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Issuer certificates to store; consumed by value.
CertificateListResult try_get_issuer_certificates_sync() const noexcept
Retrieves the issuer certificate list, blocking until complete.
Returns: The CertificateList, or an ErrorDetail on failure. Never throws.
CertificateList get_issuer_certificates_sync() const
Retrieves the issuer certificate list, blocking until complete.
Returns: The CertificateList.
VoidResult try_add_to_rejected_certificates_sync(shared_ptr< const X509Certificate > certificate) noexcept
Records a rejected certificate, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to record as rejected; must be non-null.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_rejected_certificates_sync(shared_ptr< const X509Certificate > certificate)
Records a rejected certificate, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to record as rejected; must be non-null.
CertificateListResult try_get_rejected_certificates_sync() const noexcept
Retrieves the rejected certificate list, blocking until complete.
Returns: The CertificateList, or an ErrorDetail on failure. Never throws.
CertificateList get_rejected_certificates_sync() const
Retrieves the rejected certificate list, blocking until complete.
Returns: The CertificateList.
VoidResult try_add_to_trusted_crls_sync(shared_ptr< const X509Crl > crl) noexcept
Adds a CRL to the trusted CRL set, blocking until complete.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_trusted_crls_sync(shared_ptr< const X509Crl > crl)
Adds a CRL to the trusted CRL set, blocking until complete.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.
VoidResult try_add_to_trusted_crls_sync(std::vector< shared_ptr< const X509Crl > > crls) noexcept
Adds several CRLs to the trusted CRL set, blocking until complete.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_trusted_crls_sync(std::vector< shared_ptr< const X509Crl > > crls)
Adds several CRLs to the trusted CRL set, blocking until complete.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.
CrlListResult try_get_trusted_crls_sync() const noexcept
Retrieves the trusted CRL set, blocking until complete.
Returns: The CrlList, or an ErrorDetail on failure. Never throws.
CrlList get_trusted_crls_sync() const
Retrieves the trusted CRL set, blocking until complete.
Returns: The CrlList.
VoidResult try_add_to_issuer_crls_sync(shared_ptr< const X509Crl > crl) noexcept
Adds a CRL to the issuer CRL set, blocking until complete.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_issuer_crls_sync(shared_ptr< const X509Crl > crl)
Adds a CRL to the issuer CRL set, blocking until complete.
crl(shared_ptr< const X509Crl >) - Revocation list to store; must be non-null.
VoidResult try_add_to_issuer_crls_sync(std::vector< shared_ptr< const X509Crl > > crls) noexcept
Adds several CRLs to the issuer CRL set, blocking until complete.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void add_to_issuer_crls_sync(std::vector< shared_ptr< const X509Crl > > crls)
Adds several CRLs to the issuer CRL set, blocking until complete.
crls(std::vector< shared_ptr< const X509Crl > >) - Revocation lists to store; consumed by value.
CrlListResult try_get_issuer_crls_sync() const noexcept
Retrieves the issuer CRL set, blocking until complete.
Returns: The CrlList, or an ErrorDetail on failure. Never throws.
CrlList get_issuer_crls_sync() const
Retrieves the issuer CRL set, blocking until complete.
Returns: The CrlList.
VoidResult try_replace_trusted_certificates_sync(CertificateList certificates, CrlList crls) noexcept
Atomically replaces the trusted certificate and CRL set, blocking until complete.
certificates(CertificateList) - Replacement trusted certificate list; consumed by value.crls(CrlList) - Replacement trusted CRL set; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void replace_trusted_certificates_sync(CertificateList certificates, CrlList crls)
Atomically replaces the trusted certificate and CRL set, blocking until complete.
certificates(CertificateList) - Replacement trusted certificate list; consumed by value.crls(CrlList) - Replacement trusted CRL set; consumed by value.
VoidResult try_replace_issuer_certificates_sync(CertificateList certificates, CrlList crls) noexcept
Atomically replaces the issuer certificate and CRL set, blocking until complete.
certificates(CertificateList) - Replacement issuer certificate list; consumed by value.crls(CrlList) - Replacement issuer CRL set; consumed by value.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void replace_issuer_certificates_sync(CertificateList certificates, CrlList crls)
Atomically replaces the issuer certificate and CRL set, blocking until complete.
certificates(CertificateList) - Replacement issuer certificate list; consumed by value.crls(CrlList) - Replacement issuer CRL set; consumed by value.
VoidResult try_remove_from_trusted_certificates_sync(const std::string &thumbprint) noexcept
Removes a trusted certificate by SHA-1 thumbprint, blocking until complete.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void remove_from_trusted_certificates_sync(const std::string &thumbprint)
Removes a trusted certificate by SHA-1 thumbprint, blocking until complete.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.
VoidResult try_remove_from_issuer_certificates_sync(const std::string &thumbprint) noexcept
Removes an issuer certificate by SHA-1 thumbprint, blocking until complete.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.
Returns: A VoidResult that carries an ErrorDetail on failure. Never throws.
void remove_from_issuer_certificates_sync(const std::string &thumbprint)
Removes an issuer certificate by SHA-1 thumbprint, blocking until complete.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.
VoidResult try_validate_certificate_sync(shared_ptr< const X509Certificate > certificate, const std::vector< shared_ptr< const X509Certificate > > &additionalIssuerCertificates, optional< TrustListValidationOptions > validationOptions, optional< std::string > applicationUri=std::nullopt, optional< std::string > endpointUrl=std::nullopt) noexcept
Validates a certificate against the store's trust lists, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to validate; must be non-null.additionalIssuerCertificates(const std::vector< shared_ptr< const X509Certificate > > &) - Extra issuer certificates to consider for chain building.validationOptions(optional< TrustListValidationOptions >) - Per-call options; when empty the store default applies.applicationUri(optional< std::string >) - Expected application URI to match, when present.endpointUrl(optional< std::string >) - Expected endpoint URL to match, when present.
Returns: A VoidResult that carries the rejection reason as an ErrorDetail on failure. Never throws.
void validate_certificate_sync(shared_ptr< const X509Certificate > certificate, const std::vector< shared_ptr< const X509Certificate > > &additionalIssuerCertificates, optional< TrustListValidationOptions > validationOptions, optional< std::string > applicationUri=std::nullopt, optional< std::string > endpointUrl=std::nullopt)
Validates a certificate against the store's trust lists, blocking until complete.
certificate(shared_ptr< const X509Certificate >) - Certificate to validate; must be non-null.additionalIssuerCertificates(const std::vector< shared_ptr< const X509Certificate > > &) - Extra issuer certificates to consider for chain building.validationOptions(optional< TrustListValidationOptions >) - Per-call options; when empty the store default applies.applicationUri(optional< std::string >) - Expected application URI to match, when present.endpointUrl(optional< std::string >) - Expected endpoint URL to match, when present.
ua::CertificateStoreFiles
class
A CertificateStore that persists each store as a directory tree on the file system.
Application certificates and keys, trusted certificates, issuer certificates, rejected certificates, and their CRLs are each kept in a dedicated subdirectory beneath a single trust list root path. The store reads those directories into an in-memory cache and, when a non-zero refresh period is configured, periodically re-scans the file system so that out-of-band changes (certificates dropped in or removed by an operator or by the OPC UA TrustList file type) are picked up automatically.
This is a strand-serialized component: every public method posts its work to a private strand, so callers may invoke it from any thread and the store serializes all access to its caches and to the file system internally. The *_async overloads deliver their outcome on an unspecified worker thread; do not block that thread.
Instances are created through create and are owned via shared_ptr. The store keeps the injected executor and Crypto alive for as long as it lives.
CertificateStore
Static functions
shared_ptr< CertificateStore > create(std::filesystem::path trustListPath, boost::asio::any_io_executor executor, shared_ptr< const Crypto > crypto, TrustListValidationOptions validationOptions, optional< std::chrono::seconds > refreshPeriod, bool storeRejectedCertificates=true, Logger logger=Logger{}, size_t maxRejectedCertificates=100, CertificateListPurpose purpose=CertificateListPurpose::ApplicationInstance)
Creates a file-system-backed certificate store rooted at trustListPath.
trustListPath(std::filesystem::path) - Root directory holding the store's subdirectories; created if missing.executor(boost::asio::any_io_executor) - Executor on which the store's strand and background refresh run; kept alive for the store's lifetime.crypto(shared_ptr< const Crypto >) - Cryptographic provider used for parsing and validation; kept alive for the store's lifetime; must not be null.validationOptions(TrustListValidationOptions) - Initial trust-list validation options.refreshPeriod(optional< std::chrono::seconds >) - Interval between automatic file system re-scans; nullopt or a non-positive value disables automatic refresh.storeRejectedCertificates(bool) - When true, certificates that fail validation are persisted to the rejected store; otherwise tracked only in memory.logger(Logger) - Logger for diagnostics; defaults to a no-op logger.maxRejectedCertificates(size_t) - Upper bound on the rejected-certificate store. A pre-auth peer can present unlimited distinct certificates during OpenSecureChannel; once this many are held the store evicts oldest-first, so it cannot grow without bound (disk + memory DoS). 0 disables the bound. Defaults to 100.purpose(CertificateListPurpose) - Which OPC 10000-6 section 6.2 certificate table governs this list. Defaults to CertificateListPurpose::ApplicationInstance, which is what an application trust list holds; a DefaultUserTokenGroup trust list must pass CertificateListPurpose::UserToken, or Table 43's keyUsage and extendedKeyUsage requirements will be applied to user certificates that Table 44 does not ask them of.
Returns: A shared, ready-to-use CertificateStore.
Functions
Destroys the store, cancelling any pending background refresh.
void shutdown() override
Gracefully shuts down the store, cancelling the background refresh timer.
void add_to_application_certificates_async(ApplicationCertificate certificate, CompleteCallback callback) noexcept override
Stores an application certificate together with its key pair, writing them to disk.
certificate(ApplicationCertificate) - Application certificate plus key pair to persist; the key material is written to the application keys directory.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void get_application_certificate_async(CertificateType certificateType, GetApplicationCertificateCallback callback) const noexcept override
Retrieves the application certificate (and key pair) for a given certificate type.
certificateType(CertificateType) - Selects which application certificate to return.callback(GetApplicationCertificateCallback) - Receives the outcome: on success the Result holds the matching CertificateStore::ApplicationCertificate; on failure it carries an ErrorDetail (e.g. when no certificate of that type is present). Never throws.
void get_application_certificates_async(GetApplicationCertificatesCallback callback) const noexcept override
Retrieves all stored application certificates.
callback(GetApplicationCertificatesCallback) - Receives the outcome: on success the Result holds the list of CertificateStore::ApplicationCertificate entries (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void add_to_trusted_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept override
Adds a single certificate to the trusted certificates store, writing it to disk.
certificate(shared_ptr< const X509Certificate >) - Certificate to trust; must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void add_to_trusted_certificates_async(std::vector< shared_ptr< const X509Certificate > > certificates, CompleteCallback callback) noexcept override
Adds several certificates to the trusted certificates store in one operation.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Certificates to trust; entries must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if any write fails. This overload never throws.
void get_trusted_certificates_async(GetCertificatesCallback callback) const noexcept override
Retrieves all certificates in the trusted certificates store.
callback(GetCertificatesCallback) - Receives the outcome: on success the Result holds the list of trusted certificates (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void add_to_issuer_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept override
Adds a single certificate to the issuer certificates store, writing it to disk.
certificate(shared_ptr< const X509Certificate >) - Issuer certificate to store; must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void add_to_issuer_certificates_async(std::vector< shared_ptr< const X509Certificate > > certificates, CompleteCallback callback) noexcept override
Adds several certificates to the issuer certificates store in one operation.
certificates(std::vector< shared_ptr< const X509Certificate > >) - Issuer certificates to store; entries must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if any write fails. This overload never throws.
void get_issuer_certificates_async(GetCertificatesCallback callback) const noexcept override
Retrieves all certificates in the issuer certificates store.
callback(GetCertificatesCallback) - Receives the outcome: on success the Result holds the list of issuer certificates (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void add_to_rejected_certificates_async(shared_ptr< const X509Certificate > certificate, CompleteCallback callback) noexcept override
Adds a certificate to the rejected certificates store.
certificate(shared_ptr< const X509Certificate >) - Rejected certificate to record; must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void get_rejected_certificates_async(GetCertificatesCallback callback) const noexcept override
Retrieves all certificates in the rejected certificates store.
callback(GetCertificatesCallback) - Receives the outcome: on success the Result holds the list of rejected certificates (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void add_to_trusted_crls_async(shared_ptr< const X509Crl > crl, CompleteCallback callback) noexcept override
Adds a single certificate revocation list to the trusted CRL store, writing it to disk.
crl(shared_ptr< const X509Crl >) - CRL to store; must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void add_to_trusted_crls_async(std::vector< shared_ptr< const X509Crl > > crls, CompleteCallback callback) noexcept override
Adds several certificate revocation lists to the trusted CRL store in one operation.
crls(std::vector< shared_ptr< const X509Crl > >) - CRLs to store; entries must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if any write fails. This overload never throws.
void get_trusted_crls_async(GetCrlsCallback callback) const noexcept override
Retrieves all certificate revocation lists in the trusted CRL store.
callback(GetCrlsCallback) - Receives the outcome: on success the Result holds the list of trusted CRLs (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void add_to_issuer_crls_async(shared_ptr< const X509Crl > crl, CompleteCallback callback) noexcept override
Adds a single certificate revocation list to the issuer CRL store, writing it to disk.
crl(shared_ptr< const X509Crl >) - CRL to store; must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the write fails. This overload never throws.
void add_to_issuer_crls_async(std::vector< shared_ptr< const X509Crl > > crls, CompleteCallback callback) noexcept override
Adds several certificate revocation lists to the issuer CRL store in one operation.
crls(std::vector< shared_ptr< const X509Crl > >) - CRLs to store; entries must not be null.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if any write fails. This overload never throws.
void get_issuer_crls_async(GetCrlsCallback callback) const noexcept override
Retrieves all certificate revocation lists in the issuer CRL store.
callback(GetCrlsCallback) - Receives the outcome: on success the Result holds the list of issuer CRLs (possibly empty); on failure it carries an ErrorDetail. This overload never throws.
void replace_trusted_certificates_async(CertificateList certificates, CrlList crls, CompleteCallback callback) noexcept override
Atomically replaces the entire trusted certificate and CRL set on disk and in the cache.
certificates(CertificateList) - New trusted certificate set, replacing the current one.crls(CrlList) - New trusted CRL set, replacing the current one.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the update fails. This overload never throws.
void replace_issuer_certificates_async(CertificateList certificates, CrlList crls, CompleteCallback callback) noexcept override
Atomically replaces the entire issuer certificate and CRL set on disk and in the cache.
certificates(CertificateList) - New issuer certificate set, replacing the current one.crls(CrlList) - New issuer CRL set, replacing the current one.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the update fails. This overload never throws.
void remove_from_trusted_certificates_async(const std::string &thumbprint, CompleteCallback callback) noexcept override
Removes one certificate from the trusted certificates store by SHA-1 thumbprint.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if no such certificate exists or the removal fails. This overload never throws.
void remove_from_issuer_certificates_async(const std::string &thumbprint, CompleteCallback callback) noexcept override
Removes one certificate from the issuer certificates store by SHA-1 thumbprint.
thumbprint(const std::string &) - Hex-encoded SHA-1 thumbprint of the certificate to remove.callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if no such certificate exists or the removal fails. This overload never throws.
void set_validation_options(TrustListValidationOptions validationOptions) override
Sets the validation options applied to subsequent certificate validations.
validationOptions(TrustListValidationOptions) - Trust-list validation behaviour to use from now on.
void refresh_cache(CompleteCallback callback) override
Re-scans the trust list directories and rebuilds the in-memory cache.
callback(CompleteCallback) - Receives the outcome: a successful VoidResult, or one carrying an ErrorDetail if the rescan fails. This overload never throws.
void validate_certificate_async(shared_ptr< const X509Certificate > certificate, std::vector< shared_ptr< const X509Certificate > > additionalIssuerCertificates, optional< TrustListValidationOptions > validationOptions, optional< std::string > applicationUri, optional< std::string > endpointUrl, Crypto::CertificateValidationCompleteCallback callback) noexcept override
Validates a certificate against this store's trust and issuer material.
certificate(shared_ptr< const X509Certificate >) - Certificate to validate; must not be null.additionalIssuerCertificates(std::vector< shared_ptr< const X509Certificate > >) - Extra issuer certificates to consider for chain building, in addition to the store's issuer set.validationOptions(optional< TrustListValidationOptions >) - Options overriding the store's configured options for this call; pass nullopt to use the store's options.applicationUri(optional< std::string >) - Expected application URI to check against the certificate's subject alternative name, or nullopt to skip that check.endpointUrl(optional< std::string >) - Endpoint URL to check the certificate's host name against, or nullopt to skip that check.callback(Crypto::CertificateValidationCompleteCallback) - Receives the validation outcome; carries an ErrorDetail describing the reason on rejection. This overload never throws.
ua::AsymmetricKeyPair
class
An asymmetric public/private key pair, owned by a Crypto provider.
Instances are produced by a Crypto and shared as shared_ptr<const AsymmetricKeyPair>; they are immutable and safe to share across threads. A key pair may be public-key-only (see Crypto::get_public_key_from_der), in which case the private-key accessors fail.
Functions
~AsymmetricKeyPair()=default
CertificateKeyAlgorithm algorithm() const =0
Returns the key algorithm (e.g.
Returns: The key algorithm (RSA or an elliptic-curve variant) of this pair.
ByteString public_key_der() const =0
Returns the DER-encoded SubjectPublicKeyInfo for the public key.
Returns: The DER-encoded SubjectPublicKeyInfo of the public key.
ByteString private_key_pem() const =0
Returns the PEM-encoded private key.
Returns: The private key in PEM encoding.
ua::Crypto
class
Cryptographic provider for OPC UA security operations.
Crypto is the abstraction over a concrete crypto backend (e.g. OpenSSL, or a hardware secure element). It supplies entropy, hashing, symmetric and asymmetric cipher/signature primitives, key derivation and agreement, and X.509 certificate/CRL creation, parsing, and validation.
Most operations expose an async variant (callback receives a Result) plus a blocking _sync convenience. The async callback runs on an unspecified worker thread and must not block. Implementations are immutable after construction and safe to call concurrently from any thread; instances are shared as shared_ptr<const Crypto>.
Buffer parameters passed as span are borrowed for the duration of the call only: for async operations the caller must keep the referenced storage alive until the callback fires. Several async overloads additionally take an owning resource handle whose sole purpose is to pin such caller-owned storage for the lifetime of the operation.
Member types
Result< EphemeralKeyPair > EphemeralKeyPairResult
Result of generating an EphemeralKeyPair; carries an ErrorDetail on failure.
std::function< std::vector< byte >(SecurityPolicyId securityPolicyId)> PrivateKeyCredentialCallback
Callback supplying credential material required to access private key material.
Returns: Credential bytes. When a credential is required, this must be non-empty.
PrivateKeyCredentialCallback PrivateKeyPasswordCallback
Backward-compatible alias for PrivateKeyCredentialCallback (older PEM/passphrase naming).
std::function< void(VoidResult)> GenericCompleteCallback
Completion callback for operations whose only outcome is success or an ErrorDetail.
std::function< void(ByteStringResult)> GetEntropyCompleteCallback
Completion callback for get_entropy_async; receives the random bytes or an ErrorDetail.
Result< CalculateDigestOutput > CalculateDigestOutputResult
Result of calculate_digest_async; carries an ErrorDetail on failure.
std::function< void(CalculateDigestOutputResult)> CalculateDigestCompleteCallback
Completion callback for calculate_digest_async.
GenericCompleteCallback SymmetricEncryptCompleteCallback
Completion callback for symmetric_encrypt_async; the ciphertext is written in place.
GenericCompleteCallback SymmetricDecryptCompleteCallback
Completion callback for symmetric_decrypt_async; the plaintext is written in place.
Result< SymmetricEncryptAndSignOutput > SymmetricEncryptAndSignOutputResult
Result of symmetric_encrypt_and_sign_async; carries an ErrorDetail on failure.
std::function< void(SymmetricEncryptAndSignOutputResult)> SymmetricEncryptAndSignCompleteCallback
Completion callback for symmetric_encrypt_and_sign_async.
Result< SymmetricVerifyAndDecryptOutput > SymmetricVerifyAndDecryptOutputResult
Result of symmetric_verify_and_decrypt_async; carries an ErrorDetail on failure.
std::function< void(SymmetricVerifyAndDecryptOutputResult)> SymmetricVerifyAndDecryptCompleteCallback
Completion callback for symmetric_verify_and_decrypt_async.
std::function< void(ByteStringResult)> SymmetricSignCompleteCallback
Completion callback for symmetric_sign_async; receives the signature or an ErrorDetail.
GenericCompleteCallback SymmetricVerifyCompleteCallback
Completion callback for symmetric_verify_async; success means the signature is valid.
GenericCompleteCallback AsymmetricEncryptCompleteCallback
Completion callback for asymmetric_encrypt_async; the ciphertext is written in place.
Result< span< const byte > > ByteSpanResult
Result holding a borrowed view of bytes (a sub-span of a caller-supplied buffer).
std::function< void(ByteSpanResult)> AsymmetricDecryptCompleteCallback
Completion callback for asymmetric_decrypt_async; receives the recovered plaintext view.
std::function< void(ByteStringResult)> AsymmetricSignCompleteCallback
Completion callback for asymmetric_sign_async; receives the signature or an ErrorDetail.
GenericCompleteCallback AsymmetricVerifyCompleteCallback
Completion callback for asymmetric_verify_async; success means the signature is valid.
std::function< void(KeyPairResult)> CreateAsymmetricKeyPairCompleteCallback
Completion callback for create_asymmetric_key_pair_async.
std::function< void(ByteStringResult)> DeriveSymmetricKeysCompleteCallback
Completion callback for the derive_symmetric_keys_async overloads.
std::function< void(EphemeralKeyPairResult)> CreateEphemeralKeysCompleteCallback
Completion callback for create_ephemeral_keys_async.
std::function< void(ByteStringResult)> CalculateSharedSecretCompleteCallback
Completion callback for calculate_shared_secret_async.
std::function< void(CertificateResult)> CreateCertificateCompleteCallback
Completion callback for create_certificate_async.
std::function< void(SelfSignedCertResult)> CreateSelfSignedApplicationInstanceCertificateCompleteCallback
Completion callback for create_self_signed_application_instance_certificate_async.
std::function< void(ByteStringResult)> CreateCertificateSigningRequestCompleteCallback
Completion callback for create_certificate_signing_request_async; receives the DER CSR.
std::function< void(CrlResult)> CreateCrlCompleteCallback
Completion callback for create_crl_async.
std::function< void(VoidResult)> CertificateValidationCompleteCallback
Completion callback for validate_certificate_async; success means the certificate is trusted.
std::function< void(CertificateResult)> SignCsrCompleteCallback
Completion callback for sign_certificate_request_async.
Functions
bool has_secure_element() const =0
Returns true if the provider uses a secure element (HSM/TPM) for private key storage.
Returns: true if a secure element (HSM/TPM) backs private-key storage; false for software-only providers.
~Crypto()=default
void get_entropy_async(size_t numberOfBytes, GetEntropyCompleteCallback callback) const noexcept=0
Generates cryptographically secure random bytes.
numberOfBytes(size_t) - Number of random bytes to produce.callback(GetEntropyCompleteCallback) - Receives the random bytes, or an ErrorDetail on failure. Never throws.
ByteString get_entropy_sync(size_t numberOfBytes) const =0
Generates cryptographically secure random bytes, blocking until complete.
numberOfBytes(size_t) - Number of random bytes to produce.
Returns: The random bytes.
void calculate_digest_async(HashAlgorithm algorithm, ByteString inputBuffer, span< const byte > input, CalculateDigestCompleteCallback callback) const noexcept=0
Computes a message digest over input using algorithm.
algorithm(HashAlgorithm) - Hash algorithm to apply.inputBuffer(ByteString) - Owning copy of the input that is returned alongside the digest, keeping the hashed bytes valid for the duration of the async call.input(span< const byte >) - View of the bytes to hash (typically a view into inputBuffer).callback(CalculateDigestCompleteCallback) - Receives the input buffer and digest, or an ErrorDetail on failure. Never throws.
ByteString calculate_digest_sync(HashAlgorithm algorithm, span< const byte > input) const =0
Computes a message digest over input, blocking until complete.
algorithm(HashAlgorithm) - Hash algorithm to apply.input(span< const byte >) - Bytes to hash.
Returns: The computed digest.
void derive_symmetric_keys_async(SymmetricKeyDerivationAlgorithm algorithm, size_t numberOfBytes, ByteString secret, ByteString seed, DeriveSymmetricKeysCompleteCallback callback) const noexcept=0
Derives numberOfBytes of key material from a secret and seed (P-SHA pseudo-random function).
algorithm(SymmetricKeyDerivationAlgorithm) - Key-derivation algorithm to use.numberOfBytes(size_t) - Length of the derived key material, in bytes.secret(ByteString) - Shared secret input (kept alive for the async call).seed(ByteString) - Seed input (kept alive for the async call).callback(DeriveSymmetricKeysCompleteCallback) - Receives the derived key material, or an ErrorDetail on failure. Never throws.
ByteString derive_symmetric_keys_sync(SymmetricKeyDerivationAlgorithm algorithm, size_t numberOfBytes, span< const byte > secret, span< const byte > seed) const =0
Derives key material from a secret and seed, blocking until complete.
algorithm(SymmetricKeyDerivationAlgorithm) - Key-derivation algorithm to use.numberOfBytes(size_t) - Length of the derived key material, in bytes.secret(span< const byte >) - Shared secret input.seed(span< const byte >) - Seed input.
Returns: The derived key material, of length numberOfBytes.
void derive_symmetric_keys_async(SymmetricKeyDerivationAlgorithm algorithm, size_t numberOfBytes, ByteString secret, ByteString salt, ByteString info, DeriveSymmetricKeysCompleteCallback callback) const noexcept=0
Derives numberOfBytes of key material from a secret using an HKDF-style salt and info.
algorithm(SymmetricKeyDerivationAlgorithm) - Key-derivation algorithm to use.numberOfBytes(size_t) - Length of the derived key material, in bytes.secret(ByteString) - Shared secret input (kept alive for the async call).salt(ByteString) - Salt input (kept alive for the async call).info(ByteString) - Context/info input binding the key to its use (kept alive for the call).callback(DeriveSymmetricKeysCompleteCallback) - Receives the derived key material, or an ErrorDetail on failure. Never throws.
ByteString derive_symmetric_keys_sync(SymmetricKeyDerivationAlgorithm algorithm, size_t numberOfBytes, span< const byte > secret, span< const byte > salt, span< const byte > info) const =0
Derives key material from a secret, salt, and info, blocking until complete.
algorithm(SymmetricKeyDerivationAlgorithm) - Key-derivation algorithm to use.numberOfBytes(size_t) - Length of the derived key material, in bytes.secret(span< const byte >) - Shared secret input.salt(span< const byte >) - Salt input.info(span< const byte >) - Context/info input binding the key to its use.
Returns: The derived key material, of length numberOfBytes.
void symmetric_encrypt_async(shared_ptr< const void > resource, SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > plainText, span< byte > cipherText, SymmetricEncryptCompleteCallback callback) const noexcept=0
Encrypts plainText into cipherText using a symmetric cipher.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.plainText(span< const byte >) - Plaintext input.cipherText(span< byte >) - Output buffer; the ciphertext is written here in place and must be large enough to hold it.callback(SymmetricEncryptCompleteCallback) - Receives success or an ErrorDetail on failure. Never throws.
void symmetric_encrypt_sync(SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > plainText, span< byte > cipherText) const =0
Encrypts plainText into cipherText, blocking until complete.
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.plainText(span< const byte >) - Plaintext input.cipherText(span< byte >) - Output buffer written in place; must be large enough for the ciphertext.
void symmetric_decrypt_async(shared_ptr< const void > resource, SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > cipherText, span< byte > plainText, SymmetricDecryptCompleteCallback callback) const noexcept=0
Decrypts cipherText into plainText using a symmetric cipher.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.cipherText(span< const byte >) - Ciphertext input.plainText(span< byte >) - Output buffer; the plaintext is written here in place.callback(SymmetricDecryptCompleteCallback) - Receives success or an ErrorDetail on failure. Never throws.
void symmetric_decrypt_sync(SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > cipherText, span< byte > plainText) const =0
Decrypts cipherText into plainText, blocking until complete.
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.cipherText(span< const byte >) - Ciphertext input.plainText(span< byte >) - Output buffer written in place.
void symmetric_encrypt_and_sign_async(SymmetricEncryptionAlgorithm algorithm, ByteString iv, ByteString key, ByteString plainTextBuffer, span< const byte > plainText, span< const byte > additionalData, optional< ByteString > cipherTextBuffer, span< byte > cipherText, SymmetricEncryptAndSignCompleteCallback callback) const =0
Encrypts and authenticates plainText, producing ciphertext and a signature (MAC).
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(ByteString) - Initialization vector (owning, kept alive for the async call).key(ByteString) - Symmetric key (owning, kept alive for the async call).plainTextBuffer(ByteString) - Owning copy of the plaintext, returned in the result.plainText(span< const byte >) - View of the plaintext to encrypt (typically into plainTextBuffer).additionalData(span< const byte >) - Additional authenticated data covered by the signature but not encrypted.cipherTextBuffer(optional< ByteString >) - Optional owning output buffer for out-of-place ciphertext; pass empty for in-place encryption into cipherText.cipherText(span< byte >) - Output view for the ciphertext when produced in place.callback(SymmetricEncryptAndSignCompleteCallback) - Receives the buffers and signature, or an ErrorDetail on failure. Never throws.
ByteString symmetric_encrypt_and_sign_sync(SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > plainText, span< const byte > additionalData, span< byte > cipherText) const =0
Encrypts and authenticates plainText, blocking until complete.
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.plainText(span< const byte >) - Plaintext input to encrypt.additionalData(span< const byte >) - Additional authenticated data covered by the signature but not encrypted.cipherText(span< byte >) - Output buffer written in place; must be large enough for the ciphertext.
Returns: The authentication signature (MAC) over the ciphertext and additional data.
void symmetric_verify_and_decrypt_async(SymmetricEncryptionAlgorithm algorithm, ByteString iv, ByteString key, ByteString cipherTextBuffer, span< const byte > cipherText, span< const byte > additionalData, span< const byte > signature, optional< ByteString > plainTextBuffer, span< byte > plainText, SymmetricVerifyAndDecryptCompleteCallback callback) const =0
Verifies signature and, on success, decrypts cipherText into plaintext.
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(ByteString) - Initialization vector (owning, kept alive for the async call).key(ByteString) - Symmetric key (owning, kept alive for the async call).cipherTextBuffer(ByteString) - Owning copy of the ciphertext, returned in the result.cipherText(span< const byte >) - View of the ciphertext to verify and decrypt.additionalData(span< const byte >) - Additional authenticated data covered by the signature.signature(span< const byte >) - Signature (MAC) to verify before decrypting.plainTextBuffer(optional< ByteString >) - Optional owning output buffer for out-of-place plaintext; pass empty for in-place decryption into plainText.plainText(span< byte >) - Output view for the plaintext when produced in place.callback(SymmetricVerifyAndDecryptCompleteCallback) - Receives the buffers, or an ErrorDetail if verification or decryption fails. Never throws.
void symmetric_verify_and_decrypt_sync(SymmetricEncryptionAlgorithm algorithm, span< const byte > iv, span< const byte > key, span< const byte > cipherText, span< const byte > additionalData, span< const byte > signature, span< byte > plainText) const =0
Verifies signature and decrypts cipherText, blocking until complete.
algorithm(SymmetricEncryptionAlgorithm) - Symmetric encryption algorithm.iv(span< const byte >) - Initialization vector.key(span< const byte >) - Symmetric key.cipherText(span< const byte >) - Ciphertext input to verify and decrypt.additionalData(span< const byte >) - Additional authenticated data covered by the signature.signature(span< const byte >) - Authentication tag (MAC) checked against the ciphertext and additionalData.plainText(span< byte >) - Output buffer written in place; valid only if the call returns normally.
void symmetric_sign_async(shared_ptr< const void > resource, SymmetricSignatureAlgorithm algorithm, span< const byte > key, span< const byte > input, SymmetricSignCompleteCallback callback) const =0
Computes a symmetric signature (MAC) over input.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(SymmetricSignatureAlgorithm) - Symmetric signature algorithm.key(span< const byte >) - Symmetric key.input(span< const byte >) - Data to sign.callback(SymmetricSignCompleteCallback) - Receives the signature, or an ErrorDetail on failure. Never throws.
ByteString symmetric_sign_sync(SymmetricSignatureAlgorithm algorithm, span< const byte > key, span< const byte > input) const =0
Computes a symmetric signature (MAC) over input, blocking until complete.
algorithm(SymmetricSignatureAlgorithm) - Symmetric signature algorithm.key(span< const byte >) - Symmetric key.input(span< const byte >) - Data to sign.
Returns: The signature.
void symmetric_verify_async(shared_ptr< const void > resource, SymmetricSignatureAlgorithm algorithm, span< const byte > key, span< const byte > input, span< const byte > signature, SymmetricVerifyCompleteCallback callback) const =0
Verifies a symmetric signature (MAC) over input.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(SymmetricSignatureAlgorithm) - Symmetric signature algorithm.key(span< const byte >) - Symmetric key.input(span< const byte >) - Data the signature covers.signature(span< const byte >) - Signature to verify.callback(SymmetricVerifyCompleteCallback) - Receives success if the signature is valid, or an ErrorDetail otherwise. Never throws.
void symmetric_verify_sync(SymmetricSignatureAlgorithm algorithm, span< const byte > key, span< const byte > input, span< const byte > signature) const =0
Verifies a symmetric signature (MAC) over input, blocking until complete.
algorithm(SymmetricSignatureAlgorithm) - Symmetric signature algorithm.key(span< const byte >) - Symmetric key.input(span< const byte >) - Data the signature covers.signature(span< const byte >) - Signature to verify.
void asymmetric_encrypt_async(shared_ptr< const void > resource, AsymmetricEncryptionAlgorithm algorithm, span< const byte > publicKey, span< const byte > plainText, span< byte > cipherText, AsymmetricEncryptCompleteCallback callback) const =0
Encrypts plainText into cipherText with a public key.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(AsymmetricEncryptionAlgorithm) - Asymmetric encryption algorithm (and padding).publicKey(span< const byte >) - Recipient's public key.plainText(span< const byte >) - Plaintext input.cipherText(span< byte >) - Output buffer written in place; must be large enough for the ciphertext.callback(AsymmetricEncryptCompleteCallback) - Receives success or an ErrorDetail on failure. Never throws.
void asymmetric_encrypt_sync(AsymmetricEncryptionAlgorithm algorithm, span< const byte > publicKey, span< const byte > plainText, span< byte > cipherText) const =0
Encrypts plainText into cipherText with a public key, blocking until complete.
algorithm(AsymmetricEncryptionAlgorithm) - Asymmetric encryption algorithm (and padding).publicKey(span< const byte >) - Recipient's public key.plainText(span< const byte >) - Plaintext input.cipherText(span< byte >) - Output buffer written in place; must be large enough for the ciphertext.
void asymmetric_decrypt_async(shared_ptr< const void > resource, AsymmetricEncryptionAlgorithm algorithm, shared_ptr< const AsymmetricKeyPair > privateKey, span< const byte > cipherText, span< byte > plainText, AsymmetricDecryptCompleteCallback callback) const =0
Decrypts cipherText with a private key, writing the plaintext into plainText.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(AsymmetricEncryptionAlgorithm) - Asymmetric encryption algorithm (and padding).privateKey(shared_ptr< const AsymmetricKeyPair >) - Key pair holding the private key to decrypt with.cipherText(span< const byte >) - Ciphertext input.plainText(span< byte >) - Output buffer the plaintext is written into.callback(AsymmetricDecryptCompleteCallback) - Receives a view of the recovered plaintext within plainText, or an ErrorDetail on failure. Never throws.
span< const byte > asymmetric_decrypt_sync(AsymmetricEncryptionAlgorithm algorithm, shared_ptr< const AsymmetricKeyPair > privateKey, span< const byte > cipherText, span< byte > plainText) const =0
Decrypts cipherText with a private key, blocking until complete.
algorithm(AsymmetricEncryptionAlgorithm) - Asymmetric encryption algorithm (and padding).privateKey(shared_ptr< const AsymmetricKeyPair >) - Key pair holding the private key to decrypt with.cipherText(span< const byte >) - Ciphertext input.plainText(span< byte >) - Output buffer the plaintext is written into.
Returns: A view of the recovered plaintext within plainText.
void asymmetric_sign_async(shared_ptr< const void > resource, AsymmetricSignatureAlgorithm algorithm, shared_ptr< const AsymmetricKeyPair > privateKey, span< const byte > input, AsymmetricSignCompleteCallback callback) const =0
Signs input with a private key.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(AsymmetricSignatureAlgorithm) - Asymmetric signature algorithm.privateKey(shared_ptr< const AsymmetricKeyPair >) - Key pair holding the private key to sign with.input(span< const byte >) - Data to sign.callback(AsymmetricSignCompleteCallback) - Receives the signature, or an ErrorDetail on failure. Never throws.
ByteString asymmetric_sign_sync(AsymmetricSignatureAlgorithm algorithm, shared_ptr< const AsymmetricKeyPair > privateKey, span< const byte > input) const =0
Signs input with a private key, blocking until complete.
algorithm(AsymmetricSignatureAlgorithm) - Asymmetric signature algorithm.privateKey(shared_ptr< const AsymmetricKeyPair >) - Key pair holding the private key to sign with.input(span< const byte >) - Data to sign.
Returns: The signature.
void asymmetric_verify_async(shared_ptr< const void > resource, AsymmetricSignatureAlgorithm algorithm, span< const byte > publicKey, span< const byte > input, span< const byte > signature, AsymmetricVerifyCompleteCallback callback) const =0
Verifies signature over input against a public key.
resource(shared_ptr< const void >) - Owning handle that pins the caller-supplied buffers for the operation's lifetime; may be empty if the caller guarantees the spans outlive the call.algorithm(AsymmetricSignatureAlgorithm) - Asymmetric signature algorithm.publicKey(span< const byte >) - Signer's public key.input(span< const byte >) - Data the signature covers.signature(span< const byte >) - Signature to verify.callback(AsymmetricVerifyCompleteCallback) - Receives success if the signature is valid, or an ErrorDetail otherwise. Never throws.
void asymmetric_verify_sync(AsymmetricSignatureAlgorithm algorithm, span< const byte > publicKey, span< const byte > input, span< const byte > signature) const =0
Verifies signature over input against a public key, blocking until complete.
algorithm(AsymmetricSignatureAlgorithm) - Asymmetric signature algorithm.publicKey(span< const byte >) - Signer's public key.input(span< const byte >) - Data the signature covers.signature(span< const byte >) - Signature to verify.
void create_asymmetric_key_pair_async(CertificateKeyAlgorithm algorithm, optional< size_t > keyLengthInBits, CreateAsymmetricKeyPairCompleteCallback callback) const =0
Generates a new long-term asymmetric key pair.
algorithm(CertificateKeyAlgorithm) - Key algorithm to generate.keyLengthInBits(optional< size_t >) - Key length in bits; unset selects the algorithm's default (and is ignored for fixed-size elliptic curves).callback(CreateAsymmetricKeyPairCompleteCallback) - Receives the new key pair, or an ErrorDetail on failure. Never throws.
shared_ptr< const AsymmetricKeyPair > create_asymmetric_key_pair_sync(CertificateKeyAlgorithm algorithm, optional< size_t > keyLengthInBits) const =0
Generates a new long-term asymmetric key pair, blocking until complete.
algorithm(CertificateKeyAlgorithm) - Key algorithm to generate.keyLengthInBits(optional< size_t >) - Key length in bits; unset selects the algorithm's default (and is ignored for fixed-size elliptic curves).
Returns: The generated key pair.
void create_ephemeral_keys_async(EphemeralKeyAlgorithm algorithm, CreateEphemeralKeysCompleteCallback callback) const =0
Generates an ephemeral key-agreement key pair for a single handshake.
algorithm(EphemeralKeyAlgorithm) - Ephemeral key-agreement algorithm.callback(CreateEphemeralKeysCompleteCallback) - Receives the ephemeral key pair, or an ErrorDetail on failure. Never throws.
EphemeralKeyPair create_ephemeral_keys_sync(EphemeralKeyAlgorithm algorithm) const =0
Generates an ephemeral key-agreement key pair, blocking until complete.
algorithm(EphemeralKeyAlgorithm) - Ephemeral key-agreement algorithm.
Returns: The ephemeral key pair.
void calculate_shared_secret_async(EphemeralKeyAlgorithm algorithm, ByteString localPrivateKey, ByteString remotePublicKey, CalculateSharedSecretCompleteCallback callback) const =0
Computes the shared secret from a local private key and the peer's public key.
algorithm(EphemeralKeyAlgorithm) - Key-agreement algorithm.localPrivateKey(ByteString) - Local ephemeral private key (kept alive for the async call).remotePublicKey(ByteString) - Peer's ephemeral public key (kept alive for the async call).callback(CalculateSharedSecretCompleteCallback) - Receives the shared secret, or an ErrorDetail on failure. Never throws.
ByteString calculate_shared_secret_sync(EphemeralKeyAlgorithm algorithm, span< const byte > localPrivateKey, span< const byte > remotePublicKey) const =0
Computes the key-agreement shared secret, blocking until complete.
algorithm(EphemeralKeyAlgorithm) - Key-agreement algorithm.localPrivateKey(span< const byte >) - Local ephemeral private key.remotePublicKey(span< const byte >) - Peer's ephemeral public key.
Returns: The shared secret.
shared_ptr< const X509Certificate > read_certificate_from_der(span< const byte > der) const =0
Parses a single DER-encoded X.509 certificate.
der(span< const byte >) - DER bytes of one certificate.
Returns: The parsed certificate.
std::vector< shared_ptr< const X509Certificate > > read_certificates_from_der(span< const byte > der) const =0
Parses a concatenation of DER-encoded X.509 certificates (e.g.
der(span< const byte >) - DER bytes of one or more concatenated certificates.
Returns: The parsed certificates, in encounter order.
shared_ptr< const X509Crl > read_crl_from_der(span< const byte > der) const =0
Parses a single DER-encoded X.509 CRL.
der(span< const byte >) - DER bytes of one CRL.
Returns: The parsed CRL.
std::vector< shared_ptr< const X509Crl > > read_crls_from_der(span< const byte > der) const =0
Parses a concatenation of DER-encoded X.509 CRLs.
der(span< const byte >) - DER bytes of one or more concatenated CRLs.
Returns: The parsed CRLs, in encounter order.
shared_ptr< const AsymmetricKeyPair > get_private_key_from_pem(CertificateKeyAlgorithm keyAlgorithm, span< byte > pem) const =0
Loads a key pair (including its private key) from PEM-encoded bytes.
keyAlgorithm(CertificateKeyAlgorithm) - Expected key algorithm of the PEM key.pem(span< byte >) - Mutable PEM bytes; the buffer may be scrubbed in place after parsing so private-key material does not linger in caller memory.
Returns: The loaded key pair.
void create_certificate_async(const CreateCertificateParameters ¶meters, CreateCertificateCompleteCallback callback) const =0
Issues an X.509 certificate signed by the issuer described in parameters.
parameters(const CreateCertificateParameters &) - Subject, issuer, validity, and extension parameters for the certificate.callback(CreateCertificateCompleteCallback) - Receives the issued certificate, or an ErrorDetail on failure. Never throws.
void create_self_signed_application_instance_certificate_async(Name subject, UtcTime expiry, SubjectAlternateName subjectAlternateName, CertificateType certificateType, optional< size_t > keyLengthInBits, CreateSelfSignedApplicationInstanceCertificateCompleteCallback callback) const
Generates a key pair and a matching self-signed application instance certificate.
subject(Name) - Subject distinguished name for the certificate.expiry(UtcTime) - notAfter validity end (validity starts at issuance).subjectAlternateName(SubjectAlternateName) - SubjectAlternativeName entries, including the application URI.certificateType(CertificateType) - Certificate/key type to generate (e.g. RSA or an ECC variant).keyLengthInBits(optional< size_t >) - Key length in bits; unset uses the type's default.callback(CreateSelfSignedApplicationInstanceCertificateCompleteCallback) - Receives the generated key pair and certificate, or an ErrorDetail on failure. Never throws.
SelfSignedCertResult try_create_self_signed_application_instance_certificate_sync(Name subject, UtcTime expiry, SubjectAlternateName subjectAlternateName, CertificateType certificateType, optional< size_t > keyLengthInBits) const noexcept
Generates a self-signed application instance certificate, blocking until complete.
subject(Name) - Subject distinguished name for the certificate.expiry(UtcTime) - notAfter validity end (validity starts at issuance).subjectAlternateName(SubjectAlternateName) - SubjectAlternativeName entries, including the application URI.certificateType(CertificateType) - Certificate/key type to generate (e.g. RSA or an ECC variant).keyLengthInBits(optional< size_t >) - Key length in bits; unset uses the type's default.
Returns: The generated key pair and certificate, or an ErrorDetail on failure. Never throws.
std::pair< shared_ptr< const AsymmetricKeyPair >, shared_ptr< const X509Certificate > > create_self_signed_application_instance_certificate_sync(Name subject, UtcTime expiry, SubjectAlternateName subjectAlternateName, CertificateType certificateType, optional< size_t > keyLengthInBits) const
Generates a self-signed application instance certificate, blocking until complete.
subject(Name) - Subject distinguished name for the certificate.expiry(UtcTime) - notAfter validity end (validity starts at issuance).subjectAlternateName(SubjectAlternateName) - SubjectAlternativeName entries, including the application URI.certificateType(CertificateType) - Certificate/key type to generate (e.g. RSA or an ECC variant).keyLengthInBits(optional< size_t >) - Key length in bits; unset uses the type's default.
Returns: The generated key pair and certificate.
void create_certificate_signing_request_async(const CreateCsrParameters ¶meters, CreateCertificateSigningRequestCompleteCallback callback) const =0
Builds a PKCS#10 certificate signing request (CSR) from parameters.
parameters(const CreateCsrParameters &) - Subject, key, and extension parameters for the CSR.callback(CreateCertificateSigningRequestCompleteCallback) - Receives the DER-encoded CSR, or an ErrorDetail on failure. Never throws.
shared_ptr< const AsymmetricKeyPair > get_public_key_from_der(CertificateKeyAlgorithm keyAlgorithm, span< const byte > der) const =0
Loads a public-key-only AsymmetricKeyPair from DER-encoded public key bytes.
keyAlgorithm(CertificateKeyAlgorithm) - Expected key algorithm of the encoded public key.der(span< const byte >) - DER-encoded public key (SubjectPublicKeyInfo).
Returns: A public-key-only key pair.
void sign_certificate_request_async(const SignCsrParameters ¶meters, SignCsrCompleteCallback callback) const =0
Signs a PKCS#10 CSR, issuing the requested certificate.
parameters(const SignCsrParameters &) - CSR, issuer, validity, and extension parameters.callback(SignCsrCompleteCallback) - Receives the issued certificate, or an ErrorDetail on failure. Never throws.
CertificateResult try_sign_certificate_request_sync(const SignCsrParameters ¶meters) const noexcept
Signs a PKCS#10 CSR, blocking until complete.
parameters(const SignCsrParameters &) - CSR, issuer, validity, and extension parameters.
Returns: The issued certificate, or an ErrorDetail on failure. Never throws.
shared_ptr< const X509Certificate > sign_certificate_request_sync(const SignCsrParameters ¶meters) const
Signs a PKCS#10 CSR, blocking until complete.
parameters(const SignCsrParameters &) - CSR, issuer, validity, and extension parameters.
Returns: The issued certificate.
void create_crl_async(shared_ptr< const X509Certificate > issuer, shared_ptr< const AsymmetricKeyPair > issuerKeys, std::vector< std::string > revokedSerialNumbers, CreateCrlCompleteCallback callback) const =0
Creates an X.509 CRL revoking the given serial numbers, signed by the issuer.
issuer(shared_ptr< const X509Certificate >) - Issuing CA certificate.issuerKeys(shared_ptr< const AsymmetricKeyPair >) - Issuer key pair used to sign the CRL.revokedSerialNumbers(std::vector< std::string >) - Serial numbers (as strings) to mark revoked.callback(CreateCrlCompleteCallback) - Receives the new CRL, or an ErrorDetail on failure. Never throws.
shared_ptr< const X509Crl > create_crl_sync(shared_ptr< const X509Certificate > issuer, shared_ptr< const AsymmetricKeyPair > issuerKeys, const std::vector< std::string > &revokedSerialNumbers) const
Creates an X.509 CRL, blocking until complete.
issuer(shared_ptr< const X509Certificate >) - Issuing CA certificate.issuerKeys(shared_ptr< const AsymmetricKeyPair >) - Issuer key pair used to sign the CRL.revokedSerialNumbers(const std::vector< std::string > &) - Serial numbers (as strings) to mark revoked.
Returns: The new CRL.
CrlResult try_create_crl_sync(shared_ptr< const X509Certificate > issuer, shared_ptr< const AsymmetricKeyPair > issuerKeys, const std::vector< std::string > &revokedSerialNumbers) const noexcept
Creates an X.509 CRL, blocking until complete.
issuer(shared_ptr< const X509Certificate >) - Issuing CA certificate.issuerKeys(shared_ptr< const AsymmetricKeyPair >) - Issuer key pair used to sign the CRL.revokedSerialNumbers(const std::vector< std::string > &) - Serial numbers (as strings) to mark revoked.
Returns: The new CRL, or an ErrorDetail on failure. Never throws.
void validate_certificate_async(TrustListValidationOptions validationOptions, shared_ptr< const X509Certificate > certificate, std::vector< shared_ptr< const X509Certificate > > trustedCertificates, std::vector< shared_ptr< const X509Crl > > trustedCrls, std::vector< shared_ptr< const X509Certificate > > issuerCertificates, std::vector< shared_ptr< const X509Crl > > issuerCrls, optional< std::string > applicationUri, optional< std::string > endpointUrl, CertificateValidationCompleteCallback callback) const =0
Validates a certificate against a trust list and the configured validation options.
validationOptions(TrustListValidationOptions) - Options controlling which validation checks are applied.certificate(shared_ptr< const X509Certificate >) - Certificate to validate.trustedCertificates(std::vector< shared_ptr< const X509Certificate > >) - Explicitly trusted certificates (trust anchors and trusted peers).trustedCrls(std::vector< shared_ptr< const X509Crl > >) - CRLs for the trusted certificates.issuerCertificates(std::vector< shared_ptr< const X509Certificate > >) - Intermediate issuer certificates used only to complete the chain.issuerCrls(std::vector< shared_ptr< const X509Crl > >) - CRLs for the issuer certificates.applicationUri(optional< std::string >) - Expected application URI to match against the certificate, if any.endpointUrl(optional< std::string >) - Expected endpoint URL (hostname) to match, if any.callback(CertificateValidationCompleteCallback) - Receives success if the certificate is trusted, or an ErrorDetail describing the rejection. Never throws.
ua::SecureChannelContext
struct
Mutable per-connection state of a single UASC secure channel.
Aggregates the cryptographic material, negotiated parameters, security tokens, and in-flight message state that the secure-channel state machine reads and mutates as a channel is opened, renewed, and closed. One instance backs one transport connection for its lifetime.
All access is serialized through the channel's mStrand - members are mutated and read only from within that strand, so the struct itself carries no internal locking.
Member types
State (enum)
Lifecycle phase of the secure channel.
Uninitialised- No OpenSecureChannel has completed yet; no usable token.Open- Channel is established and an active security token is in force.Closed- Channel has been torn down and must not carry further messages.
Functions
void initialise_sequence_numbers(bool legacy)
Establish the policy-specific initial sequence state for a newly negotiated channel.
legacy(bool) - true for a policy whose first chunk is numbered 1, which is expressed by seeding the last-sent number with 0. false seeds it with UINT32_MAX so the pre-increment wraps to 0 for the first chunk.
bool is_uninitialised() const
Returns true while the channel has not yet completed its initial open.
Returns: true while no OpenSecureChannel has completed and the channel holds no usable token.
bool is_open() const
Returns true while the channel is open and able to carry secured messages.
Returns: true while the channel is open and can carry secured messages.
Public attributes
std::optional< boost::asio::strand< boost::asio::any_io_executor > > mStrand
Strand serializing all access to this context; engaged once the channel is bound to its executor.
ua::Logger mLogger
Logger for the security-policy async work serialized on mStrand, seeded by the owning channel where it binds the strand.
shared_ptr< const Crypto > mCrypto
Crypto provider for the negotiated security policy; shared, immutable. Null until negotiated.
std::weak_ptr< CertificateStore > mCertStore
Certificate store used to validate the peer chain; weak to avoid extending its lifetime.
NamespaceIndexResolver mNamespaceIndexCallback
Resolves namespace URIs to runtime indices when (de)serializing channel-level messages.
State mState
Current lifecycle phase of the channel.
ChannelRole mRole
Which side of the channel this participant is.
shared_ptr< SecurityPolicy > mSecurityPolicy
Negotiated security policy (signing/encryption algorithms). Null until negotiated.
MessageSecurityMode mMessageSecurityMode
Negotiated message security mode (None, Sign, or SignAndEncrypt).
uint32_t mSecureChannelId
Server-assigned identifier of this secure channel.
optional< uint32_t > mLastRxSequenceNumber
Sequence number of the most recently received message; empty before the first message.
uint32_t mLastTxSequenceNumber
Sequence number of the most recently transmitted message.
unique_ptr< SecurityToken > mActiveSecurityToken
Token currently in force for securing traffic. Null until the channel opens.
unique_ptr< SecurityToken > mPendingSecurityToken
Token issued by a renewal but not yet activated by the peer. Null when no renewal is pending.
connection_protocol::NegotiatedLimits mNegotiatedLimits
Transport limits agreed during the HEL/ACK handshake (buffer/message/chunk sizes).
ua::EncodingLimits mEncodingLimits
Encoding limits applied to messages on this channel (nesting depth, array/string sizes).
shared_ptr< const X509Certificate > mLocalCertificate
This endpoint's own certificate presented during channel setup. Null if unused.
shared_ptr< const AsymmetricKeyPair > mLocalKeyPair
Private/public key pair matching mLocalCertificate. Null if unused.
shared_ptr< const X509Certificate > mRemoteCertificate
Peer's certificate received during channel setup. Null if unused.
std::vector< shared_ptr< const X509Certificate > > mRemoteIssuerCertificates
Peer's issuer (intermediate/CA) chain accompanying mRemoteCertificate.
std::string mEndpointUrl
Endpoint URL this channel was opened against.
ByteString mLocalEphemeralPrivateKey
Ephemeral private key for ECC key agreement on this channel; empty for non-ECC policies.
ByteString mReceivedMessageBody
Reassembled body of the message currently being processed.
uint32_t mReceivedRequestId
Request id of the message currently being processed, correlating request and response.
uint32_t mReceivedChunkCount
Number of chunks accumulated into mReceivedMessageBody for the message currently being reassembled.
std::optional< std::pair< uint32_t, ua::StatusCode > > mReceivedAbort
Set by the decode finalizers when an abort chunk (IsFinal='A', Part 6 6.7.3) is received: {RequestId, decoded Error StatusCode}.
ua::SecureString
class
A string that holds secret material and zeroes its buffer when destroyed.
Intended for short-lived secrets such as decrypted passwords. The underlying storage is overwritten with zeros on destruction, using a non-elidable scrub so a compiler cannot optimise the wipe away. A moved-from instance is left empty (std::string::clear()); its bytes are not scrubbed at the move but when that instance is later destroyed. This bounds the time secret bytes remain resident in memory; it is not a guarantee against all disclosure (the value is plain in memory while live and may be paged or duplicated by lower layers).
Move-assignment is deleted: a value may be constructed, copied, or move-from, but not reassigned in place. The type is not thread-safe.
Functions
SecureString(const char *value)
Constructs from a null-terminated C string, copying its bytes.
value(const char *) - Null-terminated source string. Must not be null. The pointed-to bytes are copied; no ownership of value is taken.
SecureString(const SecureString &)=default
Copy-constructs, duplicating the secret into independent storage.
SecureString(SecureString &&other) noexcept
Move-constructs, transferring the value out of other.
other(SecureString &&) - Source instance, left empty on return.
SecureString & operator=(const SecureString &other)=default
Copy-assigns, duplicating the secret into independent storage.
other(const SecureString &) - Source instance whose secret is duplicated into independent storage.
Returns: Reference to this string.
~SecureString()
Destroys the string, zeroing its buffer so the secret does not linger.
const char * c_str() const
Returns a pointer to the null-terminated value.
Returns: Null-terminated buffer owned by this object. Valid until the string is destroyed, moved from, or assigned; never null (empty yields "").
bool empty() const
Reports whether the value is empty.
Returns: True if the string holds no characters.
ua::SecurityPolicy
class
Public security policy API.
Member types
std::function< void(ByteString)> SendMessageChunk
Sink that emits one encoded outgoing message chunk to the transport.
Result< std::pair< SecurityToken::Keys, SecurityToken::Keys > > DeriveSymmetricKeysResult
Pair of derived key sets: the local (signing/encrypting) keys and the remote (verifying/ decrypting) keys, or an ErrorDetail on failure.
Static functions
shared_ptr< SecurityPolicy > create(SecurityPolicyId id)
Creates the policy implementation for the given enumerated identifier.
id(SecurityPolicyId) - Policy identifier to instantiate.
Returns: A shared instance of the matching policy. Never null.
span< const SecurityPolicyId > supported_policy_ids() noexcept
Returns every SecurityPolicy implemented by the secure-channel factory.
Returns: A stable, process-lifetime view of the implemented policy identifiers.
shared_ptr< SecurityPolicy > create(string_view uri)
Creates the policy implementation for the given OPC UA SecurityPolicy URI.
uri(string_view) - Policy URI to instantiate.
Returns: A shared instance of the matching policy. Never null.
Functions
SecurityPolicyId id() const =0
Returns the enumerated identifier of this policy.
Returns: The enumerated identifier of this policy.
String uri() const =0
Returns the OPC UA SecurityPolicy URI of this policy.
Returns: The OPC UA SecurityPolicy URI of this policy.
CertificateType certificate_type() const =0
Returns the certificate type this policy requires (RSA or one of the ECC curve types).
Returns: The certificate type this policy requires (RSA or an ECC curve type).
bool is_authenticated() const =0
Returns whether this policy uses authenticated encryption (an AEAD construction).
Returns: true if this policy uses authenticated encryption (an AEAD construction).
bool is_rsa() const =0
Returns whether this policy is an RSA-family policy.
Returns: true if this is an RSA-family policy.
bool is_ecc() const =0
Returns whether this policy is an ECC-family policy.
Returns: true if this is an ECC-family policy.
bool uses_legacy_sequence_no() const
Returns whether this policy uses the legacy (pre-1.04) sequence-number wrapping rules.
Returns: true if this policy uses the legacy sequence-number wrapping rules.
bool is_deprecated() const
Returns whether this policy is deprecated by the OPC UA specification.
Returns: true if this policy is deprecated by the OPC UA specification.
size_t nonce_length() const =0
Returns the length, in bytes, of the nonce this policy uses for key derivation.
Returns: The nonce length, in bytes, used for key derivation.
size_t symmetric_plaintext_block_size() const =0
Returns the symmetric cipher plaintext block size, in bytes.
Returns: The symmetric cipher plaintext block size, in bytes.
size_t asymmetric_plaintext_block_size(const X509Certificate *certificate) const =0
Returns the asymmetric plaintext block size, in bytes, for the given peer certificate.
certificate(const X509Certificate *) - Peer certificate whose key determines the block size; must not be null.
Returns: The asymmetric plaintext block size, in bytes, for certificate.
size_t symmetric_ciphertext_block_size() const =0
Returns the symmetric cipher ciphertext block size, in bytes.
Returns: The symmetric cipher ciphertext block size, in bytes.
size_t asymmetric_ciphertext_block_size(const X509Certificate *certificate) const =0
Returns the asymmetric ciphertext block size, in bytes, for the given peer certificate.
certificate(const X509Certificate *) - Peer certificate whose key determines the block size; must not be null.
Returns: The asymmetric ciphertext block size, in bytes, for certificate.
size_t symmetric_signature_size() const =0
Returns the symmetric signature (MAC) size, in bytes.
Returns: The symmetric signature (MAC) size, in bytes.
size_t asymmetric_signature_size(const X509Certificate *certificate) const =0
Returns the asymmetric signature size, in bytes, for the given peer certificate.
certificate(const X509Certificate *) - Peer certificate whose key determines the signature size; must not be null.
Returns: The asymmetric signature size, in bytes, for certificate.
size_t symmetric_signature_key_size() const =0
Returns the symmetric signing key size, in bytes.
Returns: The symmetric signing key size, in bytes.
size_t symmetric_encryption_key_size() const =0
Returns the symmetric encryption key size, in bytes.
Returns: The symmetric encryption key size, in bytes.
size_t symmetric_iv_size() const =0
Returns the symmetric initialization-vector size, in bytes.
Returns: The symmetric initialization-vector size, in bytes.
size_t min_asymmetric_key_length() const =0
Returns the minimum acceptable asymmetric key length, in bits.
Returns: The minimum acceptable asymmetric key length, in bits.
size_t max_asymmetric_key_length() const =0
Returns the maximum acceptable asymmetric key length, in bits.
Returns: The maximum acceptable asymmetric key length, in bits.
AsymmetricEncryptionAlgorithm asymmetric_encryption_algorithm() const =0
Returns the asymmetric encryption algorithm used during channel open.
Returns: The asymmetric encryption algorithm used during channel open.
AsymmetricSignatureAlgorithm asymmetric_signature_algorithm() const =0
Returns the asymmetric signature algorithm used during channel open.
Returns: The asymmetric signature algorithm used during channel open.
String asymmetric_signature_algorithm_uri() const =0
Returns the URI of the asymmetric signature algorithm, as carried on the wire.
Returns: The URI of the asymmetric signature algorithm, as carried on the wire.
SymmetricEncryptionAlgorithm symmetric_encryption_algorithm() const =0
Returns the symmetric encryption algorithm used for established-channel traffic.
Returns: The symmetric encryption algorithm for established-channel traffic.
SymmetricSignatureAlgorithm symmetric_signature_algorithm() const =0
Returns the symmetric signature algorithm used for established-channel traffic.
Returns: The symmetric signature algorithm for established-channel traffic.
void decode_message_chunk_async(shared_ptr< SecureChannelContext > context, ByteString messageChunk, std::function< void(DecodedMessageChunkResult)> callback) const
Decodes one received secure channel message chunk, completing asynchronously.
context(shared_ptr< SecureChannelContext >) - Per-channel secure channel state; must outlive the operation.messageChunk(ByteString) - The raw received chunk; ownership is taken for the flow's duration.callback(std::function< void(DecodedMessageChunkResult)>) - Receives the outcome: on success the DecodedMessageChunkResult holds the request id and assembled body once the final chunk arrives, and is empty for intermediate chunks; on failure it carries an ErrorDetail. Never throws.
void encode_message_async(shared_ptr< SecureChannelContext > context, uint32_t requestId, shared_ptr< Structure > message, SendMessageChunk sendMessageChunk, std::function< void(VoidResult)> callback) const
Encodes an outgoing message into one or more secure channel chunks, completing asynchronously.
context(shared_ptr< SecureChannelContext >) - Per-channel secure channel state; must outlive the operation.requestId(uint32_t) - Request id stamped into each chunk's sequence header.message(shared_ptr< Structure >) - Message to encode.sendMessageChunk(SendMessageChunk) - Sink invoked once per finished outgoing chunk.callback(std::function< void(VoidResult)>) - Receives the outcome as a VoidResult - success, or an ErrorDetail on failure. Never throws.
void derive_symmetric_keys_async(shared_ptr< SecureChannelContext > context, ByteString localNonce, ByteString remoteNonce, ChannelRole role, std::function< void(DeriveSymmetricKeysResult)> callback) const =0
Derives the symmetric session keys for an established channel, completing asynchronously.
context(shared_ptr< SecureChannelContext >) - Per-channel secure channel state; must outlive the operation.localNonce(ByteString) - Nonce generated by this participant.remoteNonce(ByteString) - Nonce received from the peer.role(ChannelRole) - Whether this participant is the server or the client.callback(std::function< void(DeriveSymmetricKeysResult)>) - Receives the outcome as a DeriveSymmetricKeysResult - the (local, remote) key-set pair, or an ErrorDetail on failure. Never throws.
void check_sequence_header(SecureChannelContext &context, const stack_utils::SequenceHeader &sequenceHeader) const
Validates a received chunk's sequence header against the channel's accumulated state.
context(SecureChannelContext &) - Per-channel secure channel state; updated in place.sequenceHeader(const stack_utils::SequenceHeader &) - Sequence header decoded from the current chunk.
void copy_message_body(SecureChannelContext &context, const UaBinaryDecoder &decoder) const
Appends the remaining decoder bytes to the channel's accumulated message body.
context(SecureChannelContext &) - Per-channel secure channel state; its message body buffer is extended.decoder(const UaBinaryDecoder &) - Decoder positioned at the start of this chunk's body.
bool is_encrypted(const SecureChannelContext &context) const
Returns whether the channel is operating in SignAndEncrypt mode.
context(const SecureChannelContext &) - Per-channel secure channel state.
Returns: true if the channel is in SignAndEncrypt mode.
void asymmetric_decrypt_async(SecureChannelContext &context, span< const byte > messageChunk, size_t sequenceHeaderOffset, std::function< void(ByteStringResult)> callback) const
Asymmetrically decrypts a received OpenSecureChannel chunk, completing asynchronously.
context(SecureChannelContext &) - Per-channel secure channel state; must outlive the operation.messageChunk(span< const byte >) - Encrypted chunk bytes; caller retains ownership for the flow.sequenceHeaderOffset(size_t) - Offset, in bytes, to the encrypted region within messageChunk.callback(std::function< void(ByteStringResult)>) - Receives the decrypted bytes, or an ErrorDetail on failure. Never throws.
void asymmetric_encrypt_async(SecureChannelContext &context, span< const byte > plainText, span< byte > ciphertext, std::function< void(VoidResult)> callback) const
Asymmetrically encrypts an outgoing OpenSecureChannel chunk, completing asynchronously.
context(SecureChannelContext &) - Per-channel secure channel state; must outlive the operation.plainText(span< const byte >) - Plaintext to encrypt; caller retains ownership for the flow.ciphertext(span< byte >) - Output buffer receiving the ciphertext; must be sized by the caller and remain valid until the callback runs.callback(std::function< void(VoidResult)>) - Receives the outcome as a VoidResult - success, or an ErrorDetail on failure. Never throws.
void symmetric_decrypt_async(SecureChannelContext &context, span< const byte > messageChunk, size_t sequenceHeaderOffset, std::function< void(ByteStringResult)> callback) const
Symmetrically decrypts a received established-channel chunk, completing asynchronously.
context(SecureChannelContext &) - Per-channel secure channel state; must outlive the operation.messageChunk(span< const byte >) - Encrypted chunk bytes; caller retains ownership for the flow.sequenceHeaderOffset(size_t) - Offset, in bytes, to the encrypted region within messageChunk.callback(std::function< void(ByteStringResult)>) - Receives the decrypted bytes, or an ErrorDetail on failure. Never throws.
void symmetric_encrypt_async(SecureChannelContext &context, span< const byte > plainText, span< byte > ciphertext, std::function< void(VoidResult)> callback) const
Symmetrically encrypts an outgoing established-channel chunk, completing asynchronously.
context(SecureChannelContext &) - Per-channel secure channel state; must outlive the operation.plainText(span< const byte >) - Plaintext to encrypt; caller retains ownership for the flow.ciphertext(span< byte >) - Output buffer receiving the ciphertext; must be sized by the caller and remain valid until the callback runs.callback(std::function< void(VoidResult)>) - Receives the outcome as a VoidResult - success, or an ErrorDetail on failure. Never throws.
void validate_certificate_async(SecureChannelContext &context, std::function< void(VoidResult)> callback) const
Validates the peer certificate against this policy and the channel's certificate store.
context(SecureChannelContext &) - Per-channel secure channel state; must outlive the operation.callback(std::function< void(VoidResult)>) - Receives the outcome as a VoidResult - success, or an ErrorDetail describing why the certificate was rejected. Never throws.
size_t append_padding(const EncodingLimits &limits, UaBinaryEncoder &encoder, size_t keyLengthInBits, size_t headerSize, size_t signatureSize, size_t plaintextBlockSize, size_t ciphertextBlockSize) const
Appends padding bytes to the encoder so the message satisfies the cipher's block alignment.
limits(const EncodingLimits &) - Encoding limits applied while writing the padding.encoder(UaBinaryEncoder &) - Encoder positioned at the end of the message body; padding is written here.keyLengthInBits(size_t) - Asymmetric key length, in bits; selects whether extra padding is required.headerSize(size_t) - Size, in bytes, of the headers preceding the encrypted region.signatureSize(size_t) - Size, in bytes, of the trailing signature.plaintextBlockSize(size_t) - Cipher plaintext block size, in bytes.ciphertextBlockSize(size_t) - Cipher ciphertext block size, in bytes.
Returns: The total ciphertext size, in bytes, after padding and encryption.
ua::SecurityToken
class
A UASC secure-channel security token holding the symmetric keys and lifetime negotiated for one keyset generation.
A token bundles the directional key material derived from the local and remote nonces during an OpenSecureChannel (Issue) or renewal (Renew), together with its server-assigned id and revised lifetime. A countdown timer started from created_at fires the supplied timeout callback when the token expires, signalling that the channel must roll over to a renewed token. Instances are created through create_async and are owned by the SecureChannelContext they are installed on; they are not constructed directly.
Member types
std::function< void()> TokenTimeoutCallback
Invoked, with no arguments, when the token's revised lifetime elapses.
Result< SecurityToken * > CreateResult
Outcome of create_async - the newly installed token (owned by the context) or an error.
Static functions
void create_async(SecurityTokenRequestType requestType, shared_ptr< SecureChannelContext > context, uint32_t id, std::chrono::milliseconds revisedLifetime, ByteString localNonce, ByteString remoteNonce, ChannelRole role, TokenTimeoutCallback tokenTimeoutCallback, std::function< void(CreateResult)> callback)
Derives the symmetric keys and constructs a token installed on the secure-channel context.
requestType(SecurityTokenRequestType) - Whether this is an initial Issue or a Renew of an existing channel; selects the install slot on context.context(shared_ptr< SecureChannelContext >) - Secure-channel context that supplies the security policy and takes ownership of the created token. Must outlive the operation.id(uint32_t) - Server-assigned token identifier to embed in secured messages.revisedLifetime(std::chrono::milliseconds) - Negotiated token lifetime, in milliseconds, used to arm the expiry timer.localNonce(ByteString) - This side's nonce contributed to key derivation.remoteNonce(ByteString) - The peer's nonce contributed to key derivation.role(ChannelRole) - Whether this participant acts as server or client, fixing the nonce ordering used during key derivation.tokenTimeoutCallback(TokenTimeoutCallback) - Invoked when the token's lifetime elapses; see TokenTimeoutCallback.callback(std::function< void(CreateResult)>) - Receives the outcome: on success the CreateResult holds a raw pointer to the installed token (owned by context); on failure it carries the originating status and ErrorDetail from key derivation. This function never throws.
Functions
uint32_t id() const
Returns the server-assigned token identifier carried in every secured message header.
Returns: The server-assigned token identifier.
const Keys & local_keys() const
Returns the key material used to secure messages this side sends.
Returns: The local (sending) key material.
const Keys & remote_keys() const
Returns the key material used to verify and decrypt messages received from the peer.
Returns: The remote (receiving) key material.
DateTime created_at() const
Returns the timestamp at which the token was created and its lifetime countdown began.
Returns: The token creation timestamp.
std::chrono::milliseconds revised_lifetime() const
Returns the negotiated token lifetime, in milliseconds, after which the token expires.
Returns: The negotiated token lifetime, in milliseconds.
ua::X509Certificate
class
A parsed, read-only X.509 v3 certificate.
Exposes the fields and extensions of a DER-encoded certificate (per RFC 5280) as already-decoded accessors: subject and issuer distinguished-name components, validity window, public key, key-usage / extended-key-usage flags, subject alternative names, and basic constraints. Instances are immutable once parsed and the accessors are pure (side-effect-free) - they are safe to call concurrently from any thread.
This is an abstract interface; a concrete certificate is produced by the security backend (for example from a ByteString DER blob). Implementations own the underlying parsed certificate for their lifetime.
Functions
~X509Certificate()=default
bool operator==(const X509Certificate &obj) const =0
Compares two certificates for equality.
obj(const X509Certificate &) - Certificate to compare against.
Returns: true if the certificates are equal.
int version() const =0
Returns the zero-indexed X.509 format version: 0 for v1, 1 for v2, 2 for v3.
Returns: The zero-indexed X.509 version (0=v1, 1=v2, 2=v3).
std::string serial_number() const =0
Returns the certificate serial number as a base-10 decimal string.
Returns: The serial number as a base-10 decimal string.
ByteString signature() const =0
Returns the raw signature value over the certificate's TBS data.
Returns: The raw signature value over the certificate's TBS data.
std::string issuer() const =0
Returns the issuer name as the raw DER encoding of the X.509 Name (bytes in a string).
Returns: The issuer Name as its raw DER encoding.
std::string issuer_country() const =0
Returns the issuer country (C) attribute, or an empty string if absent.
Returns: The issuer country (C) attribute, or empty if absent.
std::string issuer_organization() const =0
Returns the issuer organization (O) attribute, or an empty string if absent.
Returns: The issuer organization (O) attribute, or empty if absent.
std::string issuer_organizational_unit() const =0
Returns the issuer organizational unit (OU) attribute, or an empty string if absent.
Returns: The issuer organizational unit (OU) attribute, or empty if absent.
std::string issuer_distinguished_name() const =0
Returns the issuer distinguishedName (DN, OID 2.5.4.49) attribute, or empty if absent.
Returns: The issuer distinguishedName (DN) attribute, or empty if absent.
std::string issuer_state() const =0
Returns the issuer state or province (ST) attribute, or an empty string if absent.
Returns: The issuer state or province (ST) attribute, or empty if absent.
std::string issuer_common_name() const =0
Returns the issuer common name (CN) attribute, or an empty string if absent.
Returns: The issuer common name (CN) attribute, or empty if absent.
std::string issuer_domain_component() const =0
Returns the issuer domain component (DC) attribute, or an empty string if absent.
Returns: The issuer domain component (DC) attribute, or empty if absent.
std::string issuer_locality() const =0
Returns the issuer locality (L) attribute, or an empty string if absent.
Returns: The issuer locality (L) attribute, or empty if absent.
UtcTime validity_from() const =0
Returns the start of the validity window (notBefore) in UTC.
Returns: The start of the validity window (notBefore) in UTC.
UtcTime validity_to() const =0
Returns the end of the validity window (notAfter) in UTC.
Returns: The end of the validity window (notAfter) in UTC.
std::string subject() const =0
Returns the subject name as the raw DER encoding of the X.509 Name (bytes in a string).
Returns: The subject Name as its raw DER encoding.
std::string subject_country() const =0
Returns the subject country (C) attribute, or an empty string if absent.
Returns: The subject country (C) attribute, or empty if absent.
std::string subject_organization() const =0
Returns the subject organization (O) attribute, or an empty string if absent.
Returns: The subject organization (O) attribute, or empty if absent.
std::string subject_organizational_unit() const =0
Returns the subject organizational unit (OU) attribute, or an empty string if absent.
Returns: The subject organizational unit (OU) attribute, or empty if absent.
std::string subject_distinguished_name() const =0
Returns the subject distinguishedName (DN, OID 2.5.4.49) attribute, or empty if absent.
Returns: The subject distinguishedName (DN) attribute, or empty if absent.
std::string subject_state() const =0
Returns the subject state or province (ST) attribute, or an empty string if absent.
Returns: The subject state or province (ST) attribute, or empty if absent.
std::string subject_common_name() const =0
Returns the subject common name (CN) attribute, or an empty string if absent.
Returns: The subject common name (CN) attribute, or empty if absent.
std::string subject_domain_component() const =0
Returns the subject domain component (DC) attribute, or an empty string if absent.
Returns: The subject domain component (DC) attribute, or empty if absent.
std::string subject_locality() const =0
Returns the subject locality (L) attribute, or an empty string if absent.
Returns: The subject locality (L) attribute, or empty if absent.
ByteString public_key() const =0
Returns the subject public key in DER-encoded form.
Returns: The subject public key in DER-encoded form.
size_t public_key_bit_length() const =0
Returns the size of the subject public key in bits.
Returns: The subject public key size in bits.
CertificateKeyAlgorithm key_algorithm() const =0
Returns the public-key algorithm of the subject key.
Returns: The public-key algorithm of the subject key.
ByteString authority_key_identifier() const =0
Returns the Authority Key Identifier extension value.
Returns: The Authority Key Identifier extension value, or empty if absent.
ByteString subject_key_identifier() const =0
Returns the Subject Key Identifier extension value.
Returns: The Subject Key Identifier extension value, or empty if absent.
bool key_usage_digital_signature() const =0
Returns true if the digitalSignature key-usage bit is set.
Returns: true if the digitalSignature key-usage bit is set.
bool key_usage_non_repudiation() const =0
Returns true if the nonRepudiation (contentCommitment) key-usage bit is set.
Returns: true if the nonRepudiation (contentCommitment) key-usage bit is set.
bool key_usage_key_encipherment() const =0
Returns true if the keyEncipherment key-usage bit is set.
Returns: true if the keyEncipherment key-usage bit is set.
bool key_usage_data_encipherment() const =0
Returns true if the dataEncipherment key-usage bit is set.
Returns: true if the dataEncipherment key-usage bit is set.
bool key_usage_key_agreement() const =0
Returns true if the keyAgreement key-usage bit is set.
Returns: true if the keyAgreement key-usage bit is set.
bool key_usage_key_cert_sign() const =0
Returns true if the keyCertSign key-usage bit is set.
Returns: true if the keyCertSign key-usage bit is set.
bool key_usage_crl_sign() const =0
Returns true if the cRLSign key-usage bit is set.
Returns: true if the cRLSign key-usage bit is set.
bool key_usage_encipher_only() const =0
Returns true if the encipherOnly key-usage bit is set.
Returns: true if the encipherOnly key-usage bit is set.
bool key_usage_decipher_only() const =0
Returns true if the decipherOnly key-usage bit is set.
Returns: true if the decipherOnly key-usage bit is set.
std::vector< asio::ip::address > san_ip_addresses() const =0
Returns the IP addresses listed in the Subject Alternative Name extension.
Returns: The IP addresses from the Subject Alternative Name extension.
std::vector< std::string > san_hostnames() const =0
Returns the DNS host names listed in the Subject Alternative Name extension.
Returns: The DNS host names from the Subject Alternative Name extension.
std::vector< std::string > san_uris() const =0
Returns the URIs listed in the Subject Alternative Name extension.
Returns: The URIs from the Subject Alternative Name extension.
bool basic_constraints_ca() const =0
Returns true if the Basic Constraints cA flag marks this as a CA certificate.
Returns: true if the Basic Constraints cA flag is set.
uint32_t basic_constraints_path_length() const =0
Returns the Basic Constraints pathLenConstraint value.
Returns: The Basic Constraints pathLenConstraint value.
bool extended_key_usage_client_auth() const =0
Returns true if the Extended Key Usage extension permits TLS client authentication.
Returns: true if Extended Key Usage permits TLS client authentication.
bool extended_key_usage_server_auth() const =0
Returns true if the Extended Key Usage extension permits TLS server authentication.
Returns: true if Extended Key Usage permits TLS server authentication.
ByteString thumbprint() const =0
Returns the certificate thumbprint (SHA-1 digest of the DER encoding).
Returns: The certificate thumbprint (SHA-1 digest of the DER encoding).
ByteString der_encoding() const =0
Returns the full DER encoding of the certificate.
Returns: The full DER encoding of the certificate.
bool issued_by(const X509Certificate &issuer) const =0
Returns true if this certificate was issued (signed) by issuer.
issuer(const X509Certificate &) - Candidate issuing certificate.
Returns: true if this certificate was issued (signed) by issuer.
bool issuer_of(const X509Certificate &issued) const =0
Returns true if this certificate issued (signed) issued.
issued(const X509Certificate &) - Candidate certificate signed by this one.
Returns: true if this certificate issued (signed) issued.
bool self_signed() const =0
Returns true if the certificate is self-signed (subject equals issuer and the certificate signs itself).
Returns: true if the certificate is self-signed.
CertificateSignatureAlgorithm signature_algorithm() const =0
Returns the algorithm with which the issuer signed this certificate.
Returns: The algorithm with which the issuer signed this certificate.
ua::X509Crl
class
A parsed X.509 Certificate Revocation List.
Models a CRL issued by a certificate authority that enumerates the certificates the authority has revoked. The interface is read-only: implementations wrap an already-parsed CRL and expose its canonical encoding and identity. Construction and parsing are performed by the crypto backend (see Crypto); this type is the value handle passed around the SDK. Instances are immutable and the accessors are safe to call from any thread.
X509Certificate, CertificateStore
Functions
~X509Crl()=default
bool operator==(const X509Crl &obj) const =0
Returns whether this CRL is byte-for-byte equal to obj.
obj(const X509Crl &) - CRL to compare against.
Returns: true if both CRLs have identical DER encodings.
ByteString der_encoding() const =0
Returns the canonical DER (binary) encoding of the CRL.
Returns: The DER-encoded CRL bytes.
ByteString thumbprint() const =0
Returns the thumbprint (digest) identifying the CRL.
Returns: The CRL thumbprint bytes.
ua::server::AnonymousAuthenticator
class
Built-in authenticator that approves anonymous tokens and rejects all others.
Install this as the server's UserAuthenticator to permit only anonymous access: an AuthnRequest whose presented identity is UserTokenKind::Anonymous succeeds with an anonymous UserIdentity; every other token kind fails. The authenticator is stateless and immutable, so a single instance may be shared across all sessions and called concurrently from any thread.
UserAuthenticator
Functions
void authenticate_async(AuthnRequest req, AuthnComplete completion) noexcept override
Approves anonymous identities and rejects every other token kind.
req(AuthnRequest) - Authentication request; only its presented identity kind is inspected.completion(AuthnComplete) - Receives the outcome as an AuthnResult. Invoked exactly once. This override never throws.
ua::server::SimpleUserPasswordAuthenticator
class
Built-in UserAuthenticator for username/password identity tokens.
Holds no credential store and never persists plaintext passwords. Credential verification is delegated to a user-supplied ValidateFn callback, which may use bcrypt, an LDAP lookup, or any other mechanism. The authenticator only handles username/password tokens; other token kinds are rejected.
UserAuthenticator
Member types
std::function< bool(std::string_view username, const ua::SecureString &password)> ValidateFn
Predicate that decides whether a username/password pair is valid.
Functions
SimpleUserPasswordAuthenticator(ValidateFn validate)
Constructs an authenticator that defers credential checks to validate.
validate(ValidateFn) - Validation callback invoked for each username/password token. Stored and owned by the authenticator; must be non-empty and outlives every authenticate_async call for the authenticator's lifetime.
void authenticate_async(AuthnRequest req, AuthnComplete completion) noexcept override
Authenticates a presented identity token via the validation callback.
req(AuthnRequest) - Authentication request: the presented identity and the non-secret endpoint security context.completion(AuthnComplete) - Receives the AuthnResult. Invoked exactly once.
ua::server::X509UserAuthenticator
class
Built-in authenticator that validates X.509 user identity tokens against a CertificateStore.
On success, the resulting ua::server::UserIdentity uses the certificate's subject common name as both the user ID and display name, falling back to the hex-encoded thumbprint when the certificate has no common name; the thumbprint is always stored under ClaimKeys::sThumbprint. Every non-X.509 token kind is rejected. Validation is delegated to a CertificateStore, so trust, revocation, and chain rules are governed entirely by that store: either one supplied at construction, or - when none was - the server's own user-token store, offered on each request as AuthnRequest::mUserTokenCertificateStore.
ua::server::UserAuthenticator
Functions
X509UserAuthenticator()=default
Constructs an authenticator that validates against the server's user-token certificate store.
X509UserAuthenticator(std::shared_ptr< ua::CertificateStore > userCertificateStore)
Constructs an authenticator backed by the given user-certificate store.
userCertificateStore(std::shared_ptr< ua::CertificateStore >) - Store against which presented user certificates are validated. Ownership is shared and retained for the authenticator's lifetime; must not be null.
void authenticate_async(AuthnRequest req, AuthnComplete completion) noexcept override
Validates the request's X.509 user identity token against the certificate store.
req(AuthnRequest) - Authentication request; only X.509 presented identities are accepted.completion(AuthnComplete) - Receives the AuthnResult outcome. Invoked exactly once; do not block it.
ua::server::CompositeAuthenticator
class
A UserAuthenticator that dispatches each request to a delegate chosen by token kind.
Holds an ordered list of registered delegates. On each request the first delegate registered for the presented UserTokenKind handles it; later delegates for the same kind are not consulted. When no delegate matches the kind, the request is rejected with BadIdentityTokenRejected.
Delegates are shared-owned for the lifetime of this authenticator. Registration via add() is not synchronized against concurrent authenticate_async() calls and is expected to complete during setup, before the authenticator is published to the request path.
UserAuthenticator
Functions
void add(UserTokenKind kind, std::shared_ptr< UserAuthenticator > authenticator)
Registers a delegate to handle requests of a given token kind.
kind(UserTokenKind) - Token kind this delegate handles.authenticator(std::shared_ptr< UserAuthenticator >) - Delegate to dispatch matching requests to; shared-owned for the lifetime of this authenticator. Must not be null.
void authenticate_async(AuthnRequest req, AuthnComplete completion) noexcept override
Dispatches the request to the first delegate registered for its token kind.
req(AuthnRequest) - Authentication request; the token kind selects the delegate.completion(AuthnComplete) - Receives the outcome as an AuthnResult - on success it holds an AuthnSuccess; on failure it carries the status code and an ErrorDetail cause chain. Invoked exactly once.
ua::server::RoleConfiguration
class
Identity-to-role mapping configuration used to commit immutable AccessIdentity snapshots.
Owns the role definitions, the dense uint64_t role-bit slot assignment, and the per-mutation epoch paired with each coherent access-identity evaluation.
Thread-safety: a shared_mutex guards the role list (shared on reads, unique on mutations); the epoch is a separate atomic counter so the hot-path staleness check needs no lock. All public methods are internally synchronised and callable from any thread. The type is non-copyable and non-movable; share it via std::shared_ptr, normally through ServerSecurityHooks::mRoleConfiguration.
Static functions
std::shared_ptr< RoleConfiguration > from_well_known_grants(std::initializer_list< WellKnownRoleGrant > grants)
Builds a Role configuration from a declarative list of well-known Role grants.
grants(std::initializer_list< WellKnownRoleGrant >) - Identity-to-Role grants to configure.
Returns: A shareable Role configuration ready for ServerSecurityHooks::mRoleConfiguration.
std::shared_ptr< RoleConfiguration > from_well_known_grants(std::span< const WellKnownRole > roles, IdentityCriteriaType criteriaType, String criteria={})
Builds one shared identity rule across an explicit set of well-known Roles.
roles(std::span< const WellKnownRole >) - Well-known Roles that receive the shared rule, in declaration order.criteriaType(IdentityCriteriaType) - Identity predicate shared by every Role.criteria(String) - Optional predicate value, such as a user name or certificate thumbprint.
Returns: A shareable Role configuration ready for ServerSecurityHooks::mRoleConfiguration.
Functions
RoleConfiguration()=default
Constructs an empty configuration with epoch 1 and no roles registered.
~RoleConfiguration()=default
Default destructor; completes the rule-of-five for the deleted copy/move set.
VoidResult grant_role_management_access(std::vector< NodeId > roleIds) noexcept
Requests ordinary RolePermissions for registered Roles on the Part-18 Role-management surface.
roleIds(std::vector< NodeId >) - Registered Role Object NodeIds to grant Role-management access.
Returns: Good on success; otherwise BadInvalidArgument, BadNodeIdUnknown or BadInvalidState with rich ErrorDetail. Never throws.
bool add_role(RoleDefinition definition)
Replaces or inserts a role.
definition(RoleDefinition) - Role to store (taken by value); its mRoleId keys the slot, overwriting an existing role with the same id.
Returns: true if the role was stored; false if mRoleBit collides with a different already-registered role or any identity rule fails to canonicalise.
bool remove_role(const NodeId &roleId) noexcept
Removes a role by id.
roleId(const NodeId &) - Node id of the role to remove.
Returns: true if the role was removed; false if no role had that id.
void add_well_known_defaults()
Seeds the well-known Anonymous (bit 0) and AuthenticatedUser (bit 1) roles with their default identity mapping rules.
std::optional< uint8_t > add_custom_role(RoleDefinition definition)
Allocates a free bit slot in [0, 63] and registers a new custom role.
definition(RoleDefinition) - Role to register (taken by value); its mRoleBit is ignored and replaced with the allocated slot.
Returns: The allocated bit slot on success, or nullopt if all 64 slots are in use, the roleId is already registered, or any rule in mIdentities fails canonicalisation.
VoidResult add_identity_rule(const NodeId &roleId, IdentityMappingRuleType rule)
Appends an IdentityMappingRule to a role.
roleId(const NodeId &) - Role to append to.rule(IdentityMappingRuleType) - Identity mapping rule to append (taken by value).
Returns: A success VoidResult on success; otherwise an ErrorDetail carrying one of: BadNotFound (role not registered), BadEntryExists (criteria_type + criteria pair already present), or BadInvalidArgument (format-discipline failure for Thumbprint with non-hex characters, or X509Subject containing a " in a value or no parseable RDN tokens; Part 18 4.4.3 L766-769 + L793-808). Never throws.
bool remove_identity_rule(const NodeId &roleId, const IdentityMappingRuleType &rule) noexcept
Removes an IdentityMappingRule from a role.
roleId(const NodeId &) - Role to remove the rule from.rule(const IdentityMappingRuleType &) - Identity mapping rule to remove, matched by criteria type and criteria string.
Returns: true if the rule was removed; false if the role or rule was not found.
Appends a permitted-application URI to a role.
roleId(const NodeId &) - Role to append the URI to.applicationUri(String) - Application URI to permit (taken by value).
Returns: true if appended; false if the role is unknown or the URI is already present (duplicates are rejected).
Removes a permitted-application URI from a role.
roleId(const NodeId &) - Role to remove the URI from.applicationUri(const String &) - Application URI to remove.
Returns: true if removed; false if the role or URI was not found.
bool add_endpoint(const NodeId &roleId, EndpointType endpoint) noexcept
Appends an EndpointType filter entry to a role.
roleId(const NodeId &) - Role to append the entry to.endpoint(EndpointType) - Endpoint filter entry to add (taken by value).
Returns: true if appended; false if the role is unknown or an entry with full 4-field equality is already present (duplicates are rejected).
bool remove_endpoint(const NodeId &roleId, const EndpointType &endpoint) noexcept
Removes an EndpointType filter entry from a role.
roleId(const NodeId &) - Role to remove the entry from.endpoint(const EndpointType &) - Endpoint filter entry to remove, matched by full 4-field equality.
Returns: true if removed; false if the role or entry was not found.
bool set_applications_exclude(const NodeId &roleId, bool exclude) noexcept
Replaces the applications include/exclude flag for a role.
roleId(const NodeId &) - Role whose flag is updated.exclude(bool) - true to treat the applications list as an exclude list; false as an include list.
Returns: true if the role exists and the flag was set; false otherwise.
bool set_endpoints_exclude(const NodeId &roleId, bool exclude) noexcept
Replaces the endpoints include/exclude flag for a role.
roleId(const NodeId &) - Role whose flag is updated.exclude(bool) - true to treat the endpoints list as an exclude list; false as an include list.
Returns: true if the role exists and the flag was set; false otherwise.
uint64_t evaluate_roles(const UserIdentity &user, const EndpointSecurityContext &security) const
Resolves the granted-role bitmask for a (user, security) pair.
user(const UserIdentity &) - Authenticated user identity to evaluate against the rules.security(const EndpointSecurityContext &) - Endpoint security context the request arrived on; feeds the application/endpoint pre-scan filters.
Returns: A bitmask with bit mRoleBit set for each granted role.
std::vector< NodeId > evaluate_role_ids(const UserIdentity &user, const EndpointSecurityContext &security) const
Resolves the Role NodeIds granted to a caller under the same rules as evaluate_roles.
user(const UserIdentity &) - Authenticated user identity to evaluate.security(const EndpointSecurityContext &) - Endpoint security context used by application and endpoint filters.
Returns: Granted Role NodeIds in configuration order.
AccessEvaluation evaluate_access_identity(const UserIdentity &user, const EndpointSecurityContext &security) const
Resolves granted Roles and snapshots the complete registered Role set under one shared lock.
user(const UserIdentity &) - the authenticated user whose Roles are being resolved.security(const EndpointSecurityContext &) - the endpoint's security context, which some criteria types test.
Returns: the granted Roles, the registered Role set and the epoch all read together.
std::vector< NodeId > role_ids() const
Returns the NodeIds of every registered Role in configuration order.
Returns: the NodeId of every registered Role, in configuration order.
std::optional< uint8_t > role_bit(const NodeId &roleId) const noexcept
Maps a role node id to its dense bit slot.
roleId(const NodeId &) - Node id of the role to look up.
Returns: The role's bit slot, or nullopt if no role with that id is registered.
uint64_t epoch() const noexcept
Returns the current configuration epoch, bumped on every mutation.
Returns: The current configuration epoch.
void bump_epoch() noexcept
Advances the epoch without mutating any Role, separating later access-identity evaluations from identities committed against the earlier policy.
size_t role_count() const noexcept
Returns the number of roles currently registered.
Returns: The number of registered roles.
std::optional< RoleDefinition > get_role(const NodeId &roleId) const noexcept
Returns a snapshot copy of a role definition by id.
roleId(const NodeId &) - Node id of the role to snapshot.
Returns: A copy of the role definition, or nullopt if no role with that id is registered.
std::vector< RoleDefinition > roles() const
Returns a stable snapshot of every configured role.
Returns: A copy of every registered role definition. A snapshot rather than a view, so it stays valid and self-consistent while the configuration is concurrently modified.
ua::server::PresentedIdentity
struct
Normalized, pre-validated view of the identity token a client presented.
Before handing this to the application, the stack has decrypted any password and enforced the endpoint and user-token policy rules; the authenticator sees only sanitized, ready-to-evaluate fields. The optional fields are populated according to mKind.
Public attributes
UserTokenKind mKind
Which token family the remaining fields describe.
optional< std::string > mUserName
Username, when mKind is UserName.
optional< ua::SecureString > mPassword
Password, already decrypted, when mKind is UserName.
optional< std::shared_ptr< const ua::X509Certificate > > mX509Certificate
User certificate, when mKind is X509.
optional< ua::ByteString > mIssuedToken
Opaque issued-token bytes, when mKind is IssuedToken; validation is application-defined.
ua::server::AuthnRequest
struct
One authentication request handed to a UserAuthenticator.
Aggregates the negotiated security context, the presented identity, and non-secret correlation data for a single activation attempt. Owned by the stack and passed by value into UserAuthenticator::authenticate_async.
Public attributes
std::shared_ptr< const EndpointSecurityContext > mSecurity
Security context of the negotiated endpoint; the pointee is non-null and outlives the call.
PresentedIdentity mIdentity
The normalized identity token to evaluate.
ua::NodeId mSessionId
Session being activated, for correlation and audit (non-secret).
uint32_t mRequestHandle
Service request handle, for correlation and audit (non-secret).
optional< std::string > mRemotePeer
Remote peer address, when known (non-secret).
optional< std::chrono::steady_clock::time_point > mDeadline
Deadline by which the authenticator should complete, on the steady clock; absent if unbounded.
std::shared_ptr< ua::CertificateStore > mUserTokenCertificateStore
The server's user-token certificate store, or null when the deployment configured none.
ua::server::AuthnSuccess
struct
Payload returned on successful authentication.
Public attributes
UserIdentity mUser
The authenticated identity to bind to the session.
std::string mAudit
Human-readable audit string describing the successful outcome.
ua::server::UserAuthenticator
class
Server-side extension point that decides whether a presented identity may activate a session.
Implement this interface to plug application authentication policy (username lookup, certificate trust, issued-token validation) into the server. The stack invokes the authenticator once per activation attempt, after it has decrypted secrets and enforced endpoint and user-token policy.
Functions
~UserAuthenticator()=default
void authenticate_async(AuthnRequest req, AuthnComplete completion) noexcept=0
Authenticates a presented identity asynchronously.
req(AuthnRequest) - The request to evaluate; consumed by value.completion(AuthnComplete) - Receives the outcome exactly once: a good AuthnResult carrying an AuthnSuccess on success, or a bad result carrying a ua::StatusCode and ua::ErrorDetail on failure. Build the result with make_authn_success or make_authn_failure.
ua::server::ServerSecurityHooks
struct
Host-supplied security wiring installed on a Server at construction.
Bundles pluggable authentication and the Part-18 Role configuration used when sessions activate. Namespace-owned access control consumes the resulting immutable AccessIdentity for every per-item decision; there is no separate host-supplied authorization object. The SDK takes shared ownership of installed components. Every member is optional and defaults to a secure-by-default posture: with no mAuthenticator set, all session activation is rejected.
Public attributes
std::shared_ptr< UserAuthenticator > mAuthenticator
Authenticator that validates user identity tokens during session activation.
std::shared_ptr< RoleConfiguration > mRoleConfiguration
Optional Part-18 RoleSet configuration wired into NS0 at server bring-up.
std::shared_ptr< ua::CertificateStore > mUserTokenCertificateStore
Certificate store holding the trusted issuers for X.509 user identity tokens.
std::chrono::milliseconds mAuthnTimeout
Deadline for an authentication check before it is abandoned, in milliseconds.
ua::server::SessionSecurityContext
class
Read-only view of a session's security state, exposed to service handlers.
Implemented by server sessions to surface the identity, negotiated endpoint, and authorization state that services need for per-item access gating. The interface is intentionally minimal and never exposes stack secrets (no passwords, private keys, or channel secrets).
Accessors are called on the session's service-dispatch path. The returned shared_ptrs are snapshots: services should use them within a single service call and must not cache them across calls, because the underlying identity may be replaced on re-activation.
EndpointSecurityContext, UserIdentity
Functions
~SessionSecurityContext()=default
ua::NodeId session_id() const =0
Returns the NodeId identifying this session, as assigned at CreateSession.
Returns: The NodeId identifying this session.
std::shared_ptr< const ua::server::EndpointSecurityContext > endpoint_security() const =0
Returns the negotiated, non-secret endpoint security context.
Returns: Shared snapshot of the endpoint security context.
std::shared_ptr< const ua::server::UserIdentity > user_identity() const =0
Returns the SDK-owned identity bound to the session at the last activation.
Returns: Shared snapshot of the active user identity, or null pre-activation.
std::shared_ptr< const ua::AccessIdentity > access_identity() const
Returns the complete access identity interned at the last successful activation.
Returns: the interned access identity, or null before a successful activation.
Result< std::shared_ptr< const ua::AccessIdentity > > access_identity_result() const
Acquires the access identity for a new authorization operation.
Returns: the access identity to authorize against, or the failure that prevented refreshing it.
Enumerations
ua::UserTokenKind
enum
Normalized kind of user identity token presented by a client.
Anonymous- No credentials presented (anonymous identity token).UserName- Username/password identity token.X509- X.509 certificate identity token.IssuedToken- Opaque issued identity token, validated by the application.Unsupported- Token kind the stack could not normalize; never used post-authentication.
ua::CertificateListPurpose
enum
The kind of certificate a CertificateStore's trust list is used to validate.
ApplicationInstance- The list validates ApplicationInstance Certificates: peers on a SecureChannel, certificates presented in CreateSession/ActivateSession, and certificates supplied to UpdateCertificate.UserToken- The list validates User Certificates presented in an X509IdentityToken.
ua::ChannelRole
enum
Identifies whether a secure channel participant is the server or the client.
Server- This participant is the secure channel server.Client- This participant is the secure channel client.
ua::SymmetricEncryptionAlgorithm
enum
Symmetric (bulk) encryption algorithm used to encrypt secure-channel message bodies.
Invalid- No algorithm / unset.Aes128Cbc- AES-128 in CBC mode.Aes256Cbc- AES-256 in CBC mode.ChaCha20Poly1305- ChaCha20-Poly1305 authenticated encryption (AEAD).
ua::AsymmetricEncryptionAlgorithm
enum
Asymmetric encryption algorithm used to protect the secrets exchanged during channel establishment (the OpenSecureChannel handshake).
Invalid- No algorithm / unset.RsaPkcs15- RSA with PKCS#1 v1.5 padding.RsaOaepSha1- RSA-OAEP with SHA-1.RsaOaepSha2256- RSA-OAEP with SHA-256.
ua::AsymmetricSignatureAlgorithm
enum
Asymmetric signature algorithm used to sign the handshake messages with the application's private key.
Invalid- No algorithm / unset.RsaPkcs15Sha1- RSASSA-PKCS1-v1_5 with SHA-1.RsaPkcs15Sha2256- RSASSA-PKCS1-v1_5 with SHA-256.RsaPssSha2256- RSASSA-PSS with SHA-256.EcDsaSha2256- ECDSA with SHA-256.EcDsaSha2384- ECDSA with SHA-384.EcDsaSha2512- ECDSA with SHA-512.PureEdDsa25519- Pure EdDSA over Curve25519 (Ed25519).PureEdDsa448- Pure EdDSA over Curve448 (Ed448).
ua::CertificateSignatureAlgorithm
enum
Signature algorithm with which an X.509 certificate was signed by its issuer.
Invalid- No algorithm / unset.RsaPkcs15Sha1- RSASSA-PKCS1-v1_5 with SHA-1.RsaPkcs15Sha2256- RSASSA-PKCS1-v1_5 with SHA-256.EcDsaSha2256- ECDSA with SHA-256.EcDsaSha2384- ECDSA with SHA-384.EcDsaSha2512- ECDSA with SHA-512.PureEdDsa25519- Pure EdDSA over Curve25519 (Ed25519).PureEdDsa448- Pure EdDSA over Curve448 (Ed448).
ua::CertificateKeyAlgorithm
enum
Public-key algorithm and curve/parameters of the key carried by an X.509 certificate.
Invalid- No algorithm / unset.Rsa- RSA key.EccNistP256- ECC key on the NIST P-256 curve.EccNistP384- ECC key on the NIST P-384 curve.EccNistP521- ECC key on the NIST P-521 curve.EccBrainpoolP256r1- ECC key on the Brainpool P-256r1 curve.EccBrainpoolP384r1- ECC key on the Brainpool P-384r1 curve.EccBrainpoolP512r1- ECC key on the Brainpool P-512r1 curve.EccCurve25519- ECC key on Curve25519.EccCurve448- ECC key on Curve448.
ua::EphemeralKeyAlgorithm
enum
Algorithm and curve of the ephemeral key pair generated per ECC key exchange.
Invalid- No algorithm / unset.EccNistP256- Ephemeral ECDH key on the NIST P-256 curve.EccNistP384- Ephemeral ECDH key on the NIST P-384 curve.EccBrainpoolP256r1- Ephemeral ECDH key on the Brainpool P-256r1 curve.EccBrainpoolP384r1- Ephemeral ECDH key on the Brainpool P-384r1 curve.EccCurve25519- Ephemeral X25519 key.EccCurve448- Ephemeral X448 key.
ua::HashAlgorithm
enum
Cryptographic hash function.
ua::SecurityPolicyId
enum
Identifier of an OPC UA security policy, bundling the algorithm suite negotiated for a secure channel.
Invalid- No policy / unset.None- No security (messages neither signed nor encrypted).Basic128Rsa15- Deprecated Basic128Rsa15 policy.Basic256- Deprecated Basic256 policy.Basic256Sha256- Basic256Sha256 policy.Aes128Sha256RsaOaep- Aes128_Sha256_RsaOaep policy.Aes256Sha256RsaPss- Aes256_Sha256_RsaPss policy.PubSubAes128Ctr- PubSub-Aes128-CTR policy (PubSub message security).PubSubAes256Ctr- PubSub-Aes256-CTR policy (PubSub message security).EccNistP256- ECC_nistP256 policy.EccNistP384- ECC_nistP384 policy.EccBrainpoolP256r1- ECC_brainpoolP256r1 policy.EccBrainpoolP384r1- ECC_brainpoolP384r1 policy.EccCurve25519ChaCha20Poly1305- ECC_curve25519 policy using ChaCha20-Poly1305.EccCurve448ChaCha20Poly1305- ECC_curve448 policy using ChaCha20-Poly1305.
ua::CertificateType
enum
Purpose-based classification of an application instance certificate.
Invalid- No type / unset.Application- Generic application instance certificate.Https- Certificate used for HTTPS transport.RsaMinApplication- Application certificate with a minimum-strength RSA key.RsaSha256Application- Application certificate with an RSA key signed using SHA-256.EccApplication- Generic ECC application certificate.EccNistP256Application- ECC application certificate on the NIST P-256 curve.EccNistP384Application- ECC application certificate on the NIST P-384 curve.EccBrainpoolP256r1Application- ECC application certificate on the Brainpool P-256r1 curve.EccBrainpoolP384r1Application- ECC application certificate on the Brainpool P-384r1 curve.EccCurve25519Application- ECC application certificate on Curve25519.EccCurve448Application- ECC application certificate on Curve448.
ua::server::AccessOperation
enum
Protected operation a per-node access decision is made about.
Browse- Browse a node or read an Attribute other than Value or RolePermissions (bit 0).ReadRolePermissions- Read the RolePermissions Attribute (bit 1).WriteAttribute- Write an Attribute other than Value, Historizing or RolePermissions (bit 2).WriteRolePermissions- Write the RolePermissions Attribute (bit 3).WriteHistorizing- Write the Historizing Attribute (bit 4).Read- Read a Variable Value (also gates a data MonitoredItem, Part 4 5.12.2.1).Write- Write a Variable Value.HistoryRead- Read historical values or events.InsertHistory- Insert new history (Part 3 Table 37 InsertHistory bit).ModifyHistory- Replace/update existing history (Part 3 Table 37 ModifyHistory bit).DeleteHistory- Delete history (Part 3 Table 37 DeleteHistory bit).Call- Invoke a Method.TranslateBrowsePaths- Translate a BrowsePath to NodeIds.ReceiveEvents- Receive events from an event-notifier node (gates an event MonitoredItem).AddNodes- Add a node to the address space.DeleteNodes- Delete a node from the address space.AddReferences- Add a reference between nodes.DeleteReferences- Delete a reference between nodes.

