You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OPCFoundation/UA-.NETStandard组件连接OPC Server时证书密钥长度报错

OPC UA .NETStandard组件连接失败问题排查

问题场景

我们内部测试环境使用版本1.4.371.60的OPCFoundation/UA-.NETStandard组件连接OPC Server,系统处于独立网段,无安全顾虑,一直采用SecurityMode=none & SecurityPolicy=none的方式连接。近期部分产品版本出现连接失败,报错信息为:
OpcException: Certificate validation failed with error code 0x8114000
提示未满足2048位的最小密钥长度要求。使用UaExpert可成功连接该服务器,但不清楚其依赖库。已尝试设置以下配置但未解决问题:

application.ApplicationConfiguration.SecurityConfiguration.AutoAcceptUntrustedCertificates = true;
application.ApplicationConfiguration.SecurityConfiguration.MinimumCertificateKeySize = 1024;
application.ApplicationConfiguration.SecurityConfiguration.RejectSHA1SignedCertificates = false;

解决方案

你遗漏了两个关键配置项——即使SecurityMode设为none,UA-.NETStandard组件仍会执行基础证书校验,需手动禁用相关逻辑:

  • 强制跳过证书校验
    给证书校验器添加强制接受的委托,直接跳过所有证书校验步骤:

    application.ApplicationConfiguration.SecurityConfiguration.CertificateValidator.CertificateValidation += (sender, e) =>
    {
        e.Accept = true;
    };
    
  • 启用证书校验跳过开关
    开启组件内置的跳过证书校验配置:

    application.ApplicationConfiguration.SecurityConfiguration.SkipCertificateValidation = true;
    

补充说明

SecurityMode=none理论上不需要证书交互,但部分版本的UA-.NETStandard组件在该模式下仍会默认执行证书密钥长度校验。UaExpert能成功连接,是因为它在无安全模式下默认完全跳过了证书校验环节。

内容的提问来源于stack exchange,提问作者paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 09:10:20