Ignition 8.1 gateway sat in the server room, KEPServerEX 6.x on a box out in the plant, OPC UA between the two. From my laptop on the plant network the endpoint opc.tcp://kep01:49320 connects fine and the tags browse.
From the gateway, IT insist on the full name, opc. removed link , and that connection sits at Faulted with BadCertificateHostNameInvalid in the gateway log.
I turned the Windows firewall off on the KEP box for a few minutes, no change there, and I trusted the server certificate in the gateway's OPC UA Security tab, where it now shows as trusted, and it still faults. I pinged kep01.plant.local from the gateway too and it resolves to the right IP, so DNS is doing its bit.
Why would the same server take one name and not the other? Same certificate either way. Has the KEP box only got kep01 in its certificate, and if it has, is that something I fix on the KEP side or on the gateway?
Could be the certificate rather than anything on the network. On the KEP box open the OPC UA Configuration Manager, Instance Certificates, select the server certificate, View. What's in the Subject Alternative Name list? Post the DNS names and the IPs.
SAN says DNS kep01, IP 10.20.5.14. Nothing with plant.local in it anywhere.
So the gateway asks for kep01.plant.local and the cert doesn't claim that name. Right?
Right. The client checks the hostname it connected with against the certificate's SAN, and kep01.plant.local isn't there. Your laptop uses the short name, which is, so it passes. Not the firewall and not the policy.
Two things.
1. On the KEP box, OPC UA Configuration Manager, Instance Certificates, Server, Reissue certificate. It builds the SAN from the machine's name and DNS suffix. Restart the runtime after.
2. In the gateway, delete the old trusted certificate, reconnect, and trust the new one when it shows up in the quarantine.
Someone did a decent article on the certificate side of OPC UA: https://plctr.com/introduction-to-opc-open-platform-communications-for-plc-integration/
Reissued it, restarted the runtime. The new cert SAN is still DNS kep01 and 10.20.5.14, no FQDN in it at all, and the gateway still faults. Three days on one connection and I'm out of ideas.
Then the box has no primary DNS suffix set in Windows, so a reissue has nothing to build the long name from. System Properties, Computer Name, Change, More, Primary DNS suffix, put plant.local in, reboot. Reissue again after the reboot and check the SAN before you go near the gateway.
Suffix was blank. Set it, rebooted, reissued, and the SAN now has kep01 and kep01.plant.local on it. Deleted the old cert in the gateway, reconnected, trusted the new one, Connected.
So the certificate only ever claimed the short hostname, and the reason the first reissue changed nothing is that the box had no DNS suffix to build the long one from. Suffix, reboot, reissue, re-trust, and the 8.1 gateway connects.
The endpoint list on the server shows both names now and I haven't worked out which one it advertises first. Not sure it matters either way. Thanks northbay, mira88.
A blank DNS suffix. Wouldn't have guessed that from the fault message.