{"id":451694,"date":"2024-10-20T09:19:37","date_gmt":"2024-10-20T09:19:37","guid":{"rendered":"https:\/\/pdfstandards.shop\/product\/uncategorized\/bsi-24-30484404-dc-2024\/"},"modified":"2024-10-26T17:22:52","modified_gmt":"2024-10-26T17:22:52","slug":"bsi-24-30484404-dc-2024","status":"publish","type":"product","link":"https:\/\/pdfstandards.shop\/product\/publishers\/bsi\/bsi-24-30484404-dc-2024\/","title":{"rendered":"BSI 24\/30484404 DC 2024"},"content":{"rendered":"
PDF Pages<\/th>\n | PDF Title<\/th>\n<\/tr>\n | ||||||
---|---|---|---|---|---|---|---|
9<\/td>\n | FIGURES <\/td>\n<\/tr>\n | ||||||
10<\/td>\n | TABLES <\/td>\n<\/tr>\n | ||||||
13<\/td>\n | FOREWORD <\/td>\n<\/tr>\n | ||||||
15<\/td>\n | 1 Scope 2 Normative references <\/td>\n<\/tr>\n | ||||||
16<\/td>\n | 3 Terms, definitions, and conventions 3.1 Terms and definitions <\/td>\n<\/tr>\n | ||||||
18<\/td>\n | 3.2 Abbreviations and symbols <\/td>\n<\/tr>\n | ||||||
19<\/td>\n | 4 The Discovery Process 4.1 Overview 4.2 Registration and Announcement of Applications 4.2.1 Overview 4.2.2 Hosts with a LocalDiscoveryServer <\/td>\n<\/tr>\n | ||||||
20<\/td>\n | 4.2.3 Hosts without a LocalDiscoveryServer 4.3 The Discovery Process for Clients to Find Servers 4.3.1 Overview <\/td>\n<\/tr>\n | ||||||
21<\/td>\n | 4.3.2 Simple Discovery with a DiscoveryUrl 4.3.3 Local Discovery <\/td>\n<\/tr>\n | ||||||
22<\/td>\n | 4.3.4 MulticastSubnet Discovery 4.3.5 Global Discovery <\/td>\n<\/tr>\n | ||||||
23<\/td>\n | 4.3.6 Combined Discovery Process for Clients <\/td>\n<\/tr>\n | ||||||
24<\/td>\n | 4.4 The Discovery Process for Reverse Connections 4.4.1 Overview 4.4.2 Out-of-band Discovery 4.4.3 Global Discovery for Reverse Connections <\/td>\n<\/tr>\n | ||||||
25<\/td>\n | 5 Local Discovery Server 5.1 Overview 5.2 Security Considerations for Multicast DNS 5.3 Network Architectures 5.3.1 Overview 5.3.2 Single MulticastSubnet <\/td>\n<\/tr>\n | ||||||
26<\/td>\n | 5.3.3 Multiple MulticastSubnet <\/td>\n<\/tr>\n | ||||||
27<\/td>\n | 5.3.4 No MulticastSubnet 5.3.5 Domain Names and MulticastSubnets <\/td>\n<\/tr>\n | ||||||
28<\/td>\n | 6 Global Discovery Server 6.1 Overview 6.2 Roles and Privileges 6.3 Client connections to global services <\/td>\n<\/tr>\n | ||||||
29<\/td>\n | 6.4 Local Discovery <\/td>\n<\/tr>\n | ||||||
30<\/td>\n | 6.5 Application Registration Workflow <\/td>\n<\/tr>\n | ||||||
32<\/td>\n | 6.6 Information Model 6.6.1 Overview <\/td>\n<\/tr>\n | ||||||
33<\/td>\n | 6.6.2 Directory 6.6.3 DirectoryType <\/td>\n<\/tr>\n | ||||||
34<\/td>\n | 6.6.4 FindApplications <\/td>\n<\/tr>\n | ||||||
35<\/td>\n | 6.6.5 ApplicationRecordDataType 6.6.6 RegisterApplication <\/td>\n<\/tr>\n | ||||||
36<\/td>\n | 6.6.7 UpdateApplication <\/td>\n<\/tr>\n | ||||||
37<\/td>\n | 6.6.8 UnregisterApplication 6.6.9 GetApplication <\/td>\n<\/tr>\n | ||||||
38<\/td>\n | 6.6.10 QueryApplications <\/td>\n<\/tr>\n | ||||||
39<\/td>\n | 6.6.11 QueryServers (deprecated) <\/td>\n<\/tr>\n | ||||||
41<\/td>\n | 6.6.12 ApplicationRegistrationChangedAuditEventType 7 Certificate Management 7.1 Overview <\/td>\n<\/tr>\n | ||||||
42<\/td>\n | 7.2 Roles and Privileges <\/td>\n<\/tr>\n | ||||||
43<\/td>\n | 7.3 Pull Management <\/td>\n<\/tr>\n | ||||||
44<\/td>\n | 7.4 Push Management 7.5 Application Setup <\/td>\n<\/tr>\n | ||||||
45<\/td>\n | 7.6 Pull Management Workflow <\/td>\n<\/tr>\n | ||||||
48<\/td>\n | 7.7 Push Management Workflow <\/td>\n<\/tr>\n | ||||||
50<\/td>\n | 7.8 Common Information Model 7.8.1 Overview 7.8.2 TrustLists 7.8.2.1 TrustListType <\/td>\n<\/tr>\n | ||||||
51<\/td>\n | 7.8.2.2 OpenWithMasks <\/td>\n<\/tr>\n | ||||||
52<\/td>\n | 7.8.2.3 CloseAndUpdate <\/td>\n<\/tr>\n | ||||||
53<\/td>\n | 7.8.2.4 AddCertificate <\/td>\n<\/tr>\n | ||||||
54<\/td>\n | 7.8.2.5 RemoveCertificate <\/td>\n<\/tr>\n | ||||||
55<\/td>\n | 7.8.2.6 TrustListDataType 7.8.2.7 TrustListMasks <\/td>\n<\/tr>\n | ||||||
56<\/td>\n | 7.8.2.8 TrustListValidationOptions 7.8.2.9 TrustListOutOfDateAlarmType <\/td>\n<\/tr>\n | ||||||
57<\/td>\n | 7.8.2.10 TrustListUpdateRequestedAuditEventType 7.8.2.11 TrustListUpdatedAuditEventType <\/td>\n<\/tr>\n | ||||||
58<\/td>\n | 7.8.3 CertificateGroups 7.8.3.1 CertificateGroupType <\/td>\n<\/tr>\n | ||||||
59<\/td>\n | 7.8.3.2 GetRejectedList 7.8.3.3 CertificateGroupFolderType <\/td>\n<\/tr>\n | ||||||
60<\/td>\n | 7.8.4 CertificateTypes 7.8.4.1 CertificateType 7.8.4.2 ApplicationCertificateType <\/td>\n<\/tr>\n | ||||||
61<\/td>\n | 7.8.4.3 HttpsCertificateType 7.8.4.4 RsaMinApplicationCertificateType 7.8.4.5 RsaSha256ApplicationCertificateType <\/td>\n<\/tr>\n | ||||||
62<\/td>\n | 7.8.4.6 EccApplicationCertificateType 7.8.4.7 EccNistP256ApplicationCertificateType 7.8.4.8 EccNistP384ApplicationCertificateType 7.8.4.9 EccBrainpoolP256r1ApplicationCertificateType <\/td>\n<\/tr>\n | ||||||
63<\/td>\n | 7.8.4.10 EccBrainpoolP384r1ApplicationCertificateType 7.8.4.11 EccCurve25519ApplicationCertificateType 7.8.4.12 EccCurve448ApplicationCertificateType <\/td>\n<\/tr>\n | ||||||
64<\/td>\n | 7.9 Information Model for Pull Certificate Management 7.9.1 Overview 7.9.2 CertificateDirectoryType <\/td>\n<\/tr>\n | ||||||
65<\/td>\n | 7.9.3 StartSigningRequest <\/td>\n<\/tr>\n | ||||||
67<\/td>\n | 7.9.4 StartNewKeyPairRequest <\/td>\n<\/tr>\n | ||||||
68<\/td>\n | 7.9.5 FinishRequest <\/td>\n<\/tr>\n | ||||||
69<\/td>\n | 7.9.6 RevokeCertificate <\/td>\n<\/tr>\n | ||||||
70<\/td>\n | 7.9.7 GetCertificateGroups 7.9.8 GetCertificates <\/td>\n<\/tr>\n | ||||||
71<\/td>\n | 7.9.9 GetTrustList <\/td>\n<\/tr>\n | ||||||
72<\/td>\n | 7.9.10 GetCertificateStatus 7.9.11 CheckRevocationStatus <\/td>\n<\/tr>\n | ||||||
73<\/td>\n | 7.9.12 CertificateRequestedAuditEventType <\/td>\n<\/tr>\n | ||||||
74<\/td>\n | 7.9.13 CertificateDeliveredAuditEventType 7.10 Information Model for Push Certificate Management 7.10.1 Overview <\/td>\n<\/tr>\n | ||||||
76<\/td>\n | 7.10.2 ServerConfiguration <\/td>\n<\/tr>\n | ||||||
77<\/td>\n | 7.10.3 ServerConfigurationType <\/td>\n<\/tr>\n | ||||||
78<\/td>\n | 7.10.4 UpdateCertificate <\/td>\n<\/tr>\n | ||||||
79<\/td>\n | 7.10.5 GetCertificates <\/td>\n<\/tr>\n | ||||||
80<\/td>\n | 7.10.6 ApplyChanges 7.10.7 CreateSigningRequest <\/td>\n<\/tr>\n | ||||||
81<\/td>\n | 7.10.8 CancelChanges <\/td>\n<\/tr>\n | ||||||
82<\/td>\n | 7.10.9 GetRejectedList 7.10.10 ResetToServerDefaults <\/td>\n<\/tr>\n | ||||||
83<\/td>\n | 7.10.11 TransactionDiagnosticsType <\/td>\n<\/tr>\n | ||||||
84<\/td>\n | 7.10.12 TransactionErrorType 7.10.13 CertificateUpdateRequestedAuditEventType 7.10.14 CertificateUpdatedAuditEventType <\/td>\n<\/tr>\n | ||||||
85<\/td>\n | 8 KeyCredential Management 8.1 Overview 8.2 Roles and Privileges <\/td>\n<\/tr>\n | ||||||
86<\/td>\n | 8.3 Pull Management <\/td>\n<\/tr>\n | ||||||
87<\/td>\n | 8.4 Push Management 8.5 Information Model for Pull Management 8.5.1 Overview <\/td>\n<\/tr>\n | ||||||
88<\/td>\n | 8.5.2 KeyCredentialManagementFolderType 8.5.3 KeyCredentialManagement 8.5.4 KeyCredentialServiceType <\/td>\n<\/tr>\n | ||||||
89<\/td>\n | 8.5.5 StartRequest <\/td>\n<\/tr>\n | ||||||
90<\/td>\n | 8.5.6 FinishRequest <\/td>\n<\/tr>\n | ||||||
91<\/td>\n | 8.5.7 Revoke 8.5.8 KeyCredentialAuditEventType <\/td>\n<\/tr>\n | ||||||
92<\/td>\n | 8.5.9 KeyCredentialRequestedAuditEventType 8.5.10 KeyCredentialDeliveredAuditEventType 8.5.11 KeyCredentialRevokedAuditEventType <\/td>\n<\/tr>\n | ||||||
93<\/td>\n | 8.6 Information Model for Push Management 8.6.1 KeyCredentialConfigurationFolderType <\/td>\n<\/tr>\n | ||||||
94<\/td>\n | 8.6.2 CreateCredential 8.6.3 KeyCredentialConfiguration 8.6.4 KeyCredentialConfigurationType <\/td>\n<\/tr>\n | ||||||
95<\/td>\n | 8.6.5 GetEncryptingKey <\/td>\n<\/tr>\n | ||||||
96<\/td>\n | 8.6.6 UpdateCredential 8.6.7 DeleteCredential <\/td>\n<\/tr>\n | ||||||
97<\/td>\n | 8.6.8 KeyCredentialUpdatedAuditEventType 8.6.9 KeyCredentialDeletedAuditEventType <\/td>\n<\/tr>\n | ||||||
98<\/td>\n | 9 AuthorizationServices 9.1 Overview 9.2 Roles and Privileges <\/td>\n<\/tr>\n | ||||||
99<\/td>\n | 9.3 Implicit <\/td>\n<\/tr>\n | ||||||
100<\/td>\n | 9.4 Explicit 9.5 Chained <\/td>\n<\/tr>\n | ||||||
101<\/td>\n | 9.6 Information Model for Requesting Access Tokens 9.6.1 Overview <\/td>\n<\/tr>\n | ||||||
102<\/td>\n | 9.6.2 AuthorizationServicesFolderType 9.6.3 AuthorizationServices 9.6.4 AuthorizationServiceType <\/td>\n<\/tr>\n | ||||||
103<\/td>\n | 9.6.5 RequestAccessToken <\/td>\n<\/tr>\n | ||||||
104<\/td>\n | 9.6.6 GetServiceDescription 9.6.7 AccessTokenIssuedAuditEventType <\/td>\n<\/tr>\n | ||||||
105<\/td>\n | 9.7 Information Model for Configuring Servers 9.7.1 Overview 9.7.2 AuthorizationServiceConfigurationFolderType <\/td>\n<\/tr>\n | ||||||
106<\/td>\n | 9.7.3 AuthorizationServices 9.7.4 AuthorizationServiceConfigurationType 10 Namespaces 10.1 Namespace Metadata <\/td>\n<\/tr>\n | ||||||
107<\/td>\n | 10.2 Handling of OPC UA Namespaces <\/td>\n<\/tr>\n | ||||||
108<\/td>\n | Annex A (informative) Deployment and Configuration A.1 Firewalls and Discovery <\/td>\n<\/tr>\n | ||||||
110<\/td>\n | A.2 Resolving References to Remote Servers <\/td>\n<\/tr>\n | ||||||
111<\/td>\n | Annex B (normative) NodeSet and Constants B.1 NodeSet B.2 Numeric Node Ids <\/td>\n<\/tr>\n | ||||||
112<\/td>\n | Annex C (normative) OPC UA Mapping to mDNS C.1 DNS Server (SRV) Record Syntax C.2 DNS Text (TXT) Record Syntax <\/td>\n<\/tr>\n | ||||||
113<\/td>\n | C.3 DiscoveryUrl Mapping <\/td>\n<\/tr>\n | ||||||
114<\/td>\n | Annex D (normative) Server Capability Identifiers <\/td>\n<\/tr>\n | ||||||
115<\/td>\n | Annex E (normative) DirectoryServices E.1 Global Discovery via Other Directory Services E.2 UDDI <\/td>\n<\/tr>\n | ||||||
116<\/td>\n | E.3 LDAP <\/td>\n<\/tr>\n | ||||||
118<\/td>\n | Annex F (normative) Local Discovery Server F.1 Certificate Store Directory Layout F.2 Installation Directories on Windows <\/td>\n<\/tr>\n | ||||||
120<\/td>\n | Annex G (normative) Application Setup G.1 Application Setup with Pull Management G.2 Application Setup with the Push Management <\/td>\n<\/tr>\n | ||||||
121<\/td>\n | G.3 Setting Permissions <\/td>\n<\/tr>\n | ||||||
122<\/td>\n | Annex H (informative) Comparison with RFC 7030 H.1 Overview H.2 Obtaining CA Certificates H.3 Initial Enrolment H.4 Client Certificate Reissuance <\/td>\n<\/tr>\n | ||||||
123<\/td>\n | H.5 Server Key Generation H.6 Certificate Signing Request (CSR) Attributes Request <\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":" BS EN IEC 62541-12. OPC Unified Architecture – Part 12. Discovery and global services<\/b><\/p>\n |