ua_config_default.c 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740
  1. /* This work is licensed under a Creative Commons CCZero 1.0 Universal License.
  2. * See http://creativecommons.org/publicdomain/zero/1.0/ for more information.
  3. *
  4. * Copyright 2017 (c) Fraunhofer IOSB (Author: Julius Pfrommer)
  5. * Copyright 2017 (c) Julian Grothoff
  6. * Copyright 2017-2018 (c) Mark Giraud, Fraunhofer IOSB
  7. * Copyright 2017 (c) Stefan Profanter, fortiss GmbH
  8. * Copyright 2017 (c) Thomas Stalder, Blue Time Concept SA
  9. * Copyright 2018 (c) Daniel Feist, Precitec GmbH & Co. KG
  10. * Copyright 2018 (c) Fabian Arndt, Root-Core
  11. */
  12. #include "ua_config_default.h"
  13. #include "ua_client_config.h"
  14. #include "ua_log_stdout.h"
  15. #include "ua_network_tcp.h"
  16. #include "ua_accesscontrol_default.h"
  17. #include "ua_pki_certificate.h"
  18. #include "ua_nodestore_default.h"
  19. #include "ua_securitypolicies.h"
  20. #include "ua_plugin_securitypolicy.h"
  21. /* Struct initialization works across ANSI C/C99/C++ if it is done when the
  22. * variable is first declared. Assigning values to existing structs is
  23. * heterogeneous across the three. */
  24. static UA_INLINE UA_UInt32Range
  25. UA_UINT32RANGE(UA_UInt32 min, UA_UInt32 max) {
  26. UA_UInt32Range range = {min, max};
  27. return range;
  28. }
  29. static UA_INLINE UA_DurationRange
  30. UA_DURATIONRANGE(UA_Duration min, UA_Duration max) {
  31. UA_DurationRange range = {min, max};
  32. return range;
  33. }
  34. /*******************************/
  35. /* Default Connection Settings */
  36. /*******************************/
  37. const UA_ConnectionConfig UA_ConnectionConfig_default = {
  38. 0, /* .protocolVersion */
  39. 65535, /* .sendBufferSize, 64k per chunk */
  40. 65535, /* .recvBufferSize, 64k per chunk */
  41. 0, /* .maxMessageSize, 0 -> unlimited */
  42. 0 /* .maxChunkCount, 0 -> unlimited */
  43. };
  44. /***************************/
  45. /* Default Server Settings */
  46. /***************************/
  47. #define MANUFACTURER_NAME "open62541"
  48. #define PRODUCT_NAME "open62541 OPC UA Server"
  49. #define PRODUCT_URI "http://open62541.org"
  50. #define APPLICATION_NAME "open62541-based OPC UA Application"
  51. #define APPLICATION_URI "urn:unconfigured:application"
  52. #define STRINGIFY(arg) #arg
  53. #define VERSION(MAJOR, MINOR, PATCH, LABEL) \
  54. STRINGIFY(MAJOR) "." STRINGIFY(MINOR) "." STRINGIFY(PATCH) LABEL
  55. static UA_StatusCode
  56. createSecurityPolicyNoneEndpoint(UA_ServerConfig *conf, UA_Endpoint *endpoint,
  57. const UA_ByteString localCertificate) {
  58. UA_EndpointDescription_init(&endpoint->endpointDescription);
  59. UA_SecurityPolicy_None(&endpoint->securityPolicy, NULL, localCertificate, &conf->logger);
  60. endpoint->endpointDescription.securityMode = UA_MESSAGESECURITYMODE_NONE;
  61. endpoint->endpointDescription.securityPolicyUri =
  62. UA_STRING_ALLOC("http://opcfoundation.org/UA/SecurityPolicy#None");
  63. endpoint->endpointDescription.transportProfileUri =
  64. UA_STRING_ALLOC("http://opcfoundation.org/UA-Profile/Transport/uatcp-uasc-uabinary");
  65. /* Enable all login mechanisms from the access control plugin */
  66. UA_StatusCode retval = UA_Array_copy(conf->accessControl.userTokenPolicies,
  67. conf->accessControl.userTokenPoliciesSize,
  68. (void **)&endpoint->endpointDescription.userIdentityTokens,
  69. &UA_TYPES[UA_TYPES_USERTOKENPOLICY]);
  70. if(retval != UA_STATUSCODE_GOOD)
  71. return retval;
  72. endpoint->endpointDescription.userIdentityTokensSize =
  73. conf->accessControl.userTokenPoliciesSize;
  74. UA_String_copy(&localCertificate, &endpoint->endpointDescription.serverCertificate);
  75. UA_ApplicationDescription_copy(&conf->applicationDescription,
  76. &endpoint->endpointDescription.server);
  77. return UA_STATUSCODE_GOOD;
  78. }
  79. void
  80. UA_ServerConfig_set_customHostname(UA_ServerConfig *config, const UA_String customHostname) {
  81. if(!config)
  82. return;
  83. UA_String_deleteMembers(&config->customHostname);
  84. UA_String_copy(&customHostname, &config->customHostname);
  85. }
  86. #ifdef UA_ENABLE_ENCRYPTION
  87. static UA_StatusCode
  88. createSecurityPolicyBasic128Rsa15Endpoint(UA_ServerConfig *const conf,
  89. UA_Endpoint *endpoint,
  90. UA_MessageSecurityMode securityMode,
  91. const UA_ByteString localCertificate,
  92. const UA_ByteString localPrivateKey) {
  93. UA_EndpointDescription_init(&endpoint->endpointDescription);
  94. UA_StatusCode retval =
  95. UA_SecurityPolicy_Basic128Rsa15(&endpoint->securityPolicy, &conf->certificateVerification,
  96. localCertificate, localPrivateKey, &conf->logger);
  97. if(retval != UA_STATUSCODE_GOOD) {
  98. endpoint->securityPolicy.deleteMembers(&endpoint->securityPolicy);
  99. return retval;
  100. }
  101. endpoint->endpointDescription.securityMode = securityMode;
  102. endpoint->endpointDescription.securityPolicyUri =
  103. UA_STRING_ALLOC("http://opcfoundation.org/UA/SecurityPolicy#Basic128Rsa15");
  104. endpoint->endpointDescription.transportProfileUri =
  105. UA_STRING_ALLOC("http://opcfoundation.org/UA-Profile/Transport/uatcp-uasc-uabinary");
  106. /* Enable all login mechanisms from the access control plugin */
  107. retval = UA_Array_copy(conf->accessControl.userTokenPolicies,
  108. conf->accessControl.userTokenPoliciesSize,
  109. (void **)&endpoint->endpointDescription.userIdentityTokens,
  110. &UA_TYPES[UA_TYPES_USERTOKENPOLICY]);
  111. if(retval != UA_STATUSCODE_GOOD)
  112. return retval;
  113. endpoint->endpointDescription.userIdentityTokensSize =
  114. conf->accessControl.userTokenPoliciesSize;
  115. UA_String_copy(&localCertificate, &endpoint->endpointDescription.serverCertificate);
  116. UA_ApplicationDescription_copy(&conf->applicationDescription,
  117. &endpoint->endpointDescription.server);
  118. return UA_STATUSCODE_GOOD;
  119. }
  120. static UA_StatusCode
  121. createSecurityPolicyBasic256Sha256Endpoint(UA_ServerConfig *const conf,
  122. UA_Endpoint *endpoint,
  123. UA_MessageSecurityMode securityMode,
  124. const UA_ByteString localCertificate,
  125. const UA_ByteString localPrivateKey) {
  126. UA_EndpointDescription_init(&endpoint->endpointDescription);
  127. UA_StatusCode retval =
  128. UA_SecurityPolicy_Basic256Sha256(&endpoint->securityPolicy,
  129. &conf->certificateVerification, localCertificate,
  130. localPrivateKey, &conf->logger);
  131. if(retval != UA_STATUSCODE_GOOD) {
  132. endpoint->securityPolicy.deleteMembers(&endpoint->securityPolicy);
  133. return retval;
  134. }
  135. endpoint->endpointDescription.securityMode = securityMode;
  136. endpoint->endpointDescription.securityPolicyUri =
  137. UA_STRING_ALLOC("http://opcfoundation.org/UA/SecurityPolicy#Basic256Sha256");
  138. endpoint->endpointDescription.transportProfileUri =
  139. UA_STRING_ALLOC("http://opcfoundation.org/UA-Profile/Transport/uatcp-uasc-uabinary");
  140. /* Enable all login mechanisms from the access control plugin */
  141. retval = UA_Array_copy(conf->accessControl.userTokenPolicies,
  142. conf->accessControl.userTokenPoliciesSize,
  143. (void **)&endpoint->endpointDescription.userIdentityTokens,
  144. &UA_TYPES[UA_TYPES_USERTOKENPOLICY]);
  145. if(retval != UA_STATUSCODE_GOOD)
  146. return retval;
  147. endpoint->endpointDescription.userIdentityTokensSize =
  148. conf->accessControl.userTokenPoliciesSize;
  149. UA_String_copy(&localCertificate, &endpoint->endpointDescription.serverCertificate);
  150. UA_ApplicationDescription_copy(&conf->applicationDescription,
  151. &endpoint->endpointDescription.server);
  152. return UA_STATUSCODE_GOOD;
  153. }
  154. #endif
  155. const size_t usernamePasswordsSize = 2;
  156. UA_UsernamePasswordLogin usernamePasswords[2] = {
  157. {UA_STRING_STATIC("user1"), UA_STRING_STATIC("password")},
  158. {UA_STRING_STATIC("user2"), UA_STRING_STATIC("password1")}};
  159. static UA_ServerConfig *
  160. createDefaultConfig(void) {
  161. UA_ServerConfig *conf = (UA_ServerConfig *)UA_malloc(sizeof(UA_ServerConfig));
  162. if(!conf)
  163. return NULL;
  164. /* Zero out.. All members have a valid initial value */
  165. memset(conf, 0, sizeof(UA_ServerConfig));
  166. /* --> Start setting the default static config <-- */
  167. conf->nThreads = 1;
  168. conf->logger = UA_Log_Stdout_;
  169. /* Server Description */
  170. conf->buildInfo.productUri = UA_STRING_ALLOC(PRODUCT_URI);
  171. conf->buildInfo.manufacturerName = UA_STRING_ALLOC(MANUFACTURER_NAME);
  172. conf->buildInfo.productName = UA_STRING_ALLOC(PRODUCT_NAME);
  173. conf->buildInfo.softwareVersion =
  174. UA_STRING_ALLOC(VERSION(UA_OPEN62541_VER_MAJOR, UA_OPEN62541_VER_MINOR,
  175. UA_OPEN62541_VER_PATCH, UA_OPEN62541_VER_LABEL));
  176. #ifdef UA_PACK_DEBIAN
  177. conf->buildInfo.buildNumber = UA_STRING_ALLOC("deb");
  178. #else
  179. conf->buildInfo.buildNumber = UA_STRING_ALLOC(__DATE__ " " __TIME__);
  180. #endif
  181. conf->buildInfo.buildDate = 0;
  182. conf->applicationDescription.applicationUri = UA_STRING_ALLOC(APPLICATION_URI);
  183. conf->applicationDescription.productUri = UA_STRING_ALLOC(PRODUCT_URI);
  184. conf->applicationDescription.applicationName =
  185. UA_LOCALIZEDTEXT_ALLOC("en", APPLICATION_NAME);
  186. conf->applicationDescription.applicationType = UA_APPLICATIONTYPE_SERVER;
  187. /* conf->applicationDescription.gatewayServerUri = UA_STRING_NULL; */
  188. /* conf->applicationDescription.discoveryProfileUri = UA_STRING_NULL; */
  189. /* conf->applicationDescription.discoveryUrlsSize = 0; */
  190. /* conf->applicationDescription.discoveryUrls = NULL; */
  191. #ifdef UA_ENABLE_DISCOVERY
  192. /* conf->mdnsServerName = UA_STRING_NULL; */
  193. /* conf->serverCapabilitiesSize = 0; */
  194. /* conf->serverCapabilities = NULL; */
  195. #endif
  196. /* Custom DataTypes */
  197. /* conf->customDataTypesSize = 0; */
  198. /* conf->customDataTypes = NULL; */
  199. /* Networking */
  200. /* conf->networkLayersSize = 0; */
  201. /* conf->networkLayers = NULL; */
  202. /* conf->customHostname = UA_STRING_NULL; */
  203. /* Endpoints */
  204. /* conf->endpoints = {0, NULL}; */
  205. /* Certificate Verification that accepts every certificate. Can be
  206. * overwritten when the policy is specialized. */
  207. UA_CertificateVerification_AcceptAll(&conf->certificateVerification);
  208. /* Global Node Lifecycle */
  209. conf->nodeLifecycle.constructor = NULL;
  210. conf->nodeLifecycle.destructor = NULL;
  211. /* Access Control. Anonymous Login only. */
  212. if (UA_AccessControl_default(&conf->accessControl, true, usernamePasswordsSize,
  213. usernamePasswords) != UA_STATUSCODE_GOOD) {
  214. UA_ServerConfig_delete(conf);
  215. return NULL;
  216. }
  217. /* Relax constraints for the InformationModel */
  218. conf->relaxEmptyValueConstraint = true; /* Allow empty values */
  219. /* Limits for SecureChannels */
  220. conf->maxSecureChannels = 40;
  221. conf->maxSecurityTokenLifetime = 10 * 60 * 1000; /* 10 minutes */
  222. /* Limits for Sessions */
  223. conf->maxSessions = 100;
  224. conf->maxSessionTimeout = 60.0 * 60.0 * 1000.0; /* 1h */
  225. /* Limits for Subscriptions */
  226. conf->publishingIntervalLimits = UA_DURATIONRANGE(100.0, 3600.0 * 1000.0);
  227. conf->lifeTimeCountLimits = UA_UINT32RANGE(3, 15000);
  228. conf->keepAliveCountLimits = UA_UINT32RANGE(1, 100);
  229. conf->maxNotificationsPerPublish = 1000;
  230. conf->maxRetransmissionQueueSize = 0; /* unlimited */
  231. #ifdef UA_ENABLE_SUBSCRIPTIONS_EVENTS
  232. conf->maxEventsPerNode = 0; /* unlimited */
  233. #endif
  234. /* Limits for MonitoredItems */
  235. conf->samplingIntervalLimits = UA_DURATIONRANGE(50.0, 24.0 * 3600.0 * 1000.0);
  236. conf->queueSizeLimits = UA_UINT32RANGE(1, 100);
  237. #ifdef UA_ENABLE_DISCOVERY
  238. conf->discoveryCleanupTimeout = 60 * 60;
  239. #endif
  240. #ifdef UA_ENABLE_HISTORIZING
  241. /* conf->accessHistoryDataCapability = UA_FALSE; */
  242. /* conf->maxReturnDataValues = 0; */
  243. /* conf->accessHistoryEventsCapability = UA_FALSE; */
  244. /* conf->maxReturnEventValues = 0; */
  245. /* conf->insertDataCapability = UA_FALSE; */
  246. /* conf->insertEventCapability = UA_FALSE; */
  247. /* conf->insertAnnotationsCapability = UA_FALSE; */
  248. /* conf->replaceDataCapability = UA_FALSE; */
  249. /* conf->replaceEventCapability = UA_FALSE; */
  250. /* conf->updateDataCapability = UA_FALSE; */
  251. /* conf->updateEventCapability = UA_FALSE; */
  252. /* conf->deleteRawCapability = UA_FALSE; */
  253. /* conf->deleteEventCapability = UA_FALSE; */
  254. /* conf->deleteAtTimeDataCapability = UA_FALSE; */
  255. #endif
  256. /* --> Finish setting the default static config <-- */
  257. return conf;
  258. }
  259. static UA_StatusCode
  260. addDefaultNetworkLayers(UA_ServerConfig *conf, UA_UInt16 portNumber, UA_UInt32 sendBufferSize, UA_UInt32 recvBufferSize) {
  261. /* Add a network layer */
  262. conf->networkLayers = (UA_ServerNetworkLayer *)
  263. UA_malloc(sizeof(UA_ServerNetworkLayer));
  264. if(!conf->networkLayers)
  265. return UA_STATUSCODE_BADOUTOFMEMORY;
  266. UA_ConnectionConfig config = UA_ConnectionConfig_default;
  267. if (sendBufferSize > 0)
  268. config.sendBufferSize = sendBufferSize;
  269. if (recvBufferSize > 0)
  270. config.recvBufferSize = recvBufferSize;
  271. conf->networkLayers[0] =
  272. UA_ServerNetworkLayerTCP(config, portNumber, &conf->logger);
  273. if (!conf->networkLayers[0].handle)
  274. return UA_STATUSCODE_BADOUTOFMEMORY;
  275. conf->networkLayersSize = 1;
  276. return UA_STATUSCODE_GOOD;
  277. }
  278. UA_ServerConfig *
  279. UA_ServerConfig_new_customBuffer(UA_UInt16 portNumber,
  280. const UA_ByteString *certificate,
  281. UA_UInt32 sendBufferSize,
  282. UA_UInt32 recvBufferSize) {
  283. UA_ServerConfig *conf = createDefaultConfig();
  284. UA_StatusCode retval = UA_Nodestore_default_new(&conf->nodestore);
  285. if(retval != UA_STATUSCODE_GOOD) {
  286. UA_ServerConfig_delete(conf);
  287. return NULL;
  288. }
  289. if(addDefaultNetworkLayers(conf, portNumber, sendBufferSize, recvBufferSize) != UA_STATUSCODE_GOOD) {
  290. UA_ServerConfig_delete(conf);
  291. return NULL;
  292. }
  293. /* Allocate the endpoint */
  294. conf->endpoints = (UA_Endpoint *)UA_malloc(sizeof(UA_Endpoint));
  295. if(!conf->endpoints) {
  296. UA_ServerConfig_delete(conf);
  297. return NULL;
  298. }
  299. conf->endpointsSize = 1;
  300. /* Populate the endpoint */
  301. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  302. if(certificate)
  303. localCertificate = *certificate;
  304. retval =
  305. createSecurityPolicyNoneEndpoint(conf, &conf->endpoints[0], localCertificate);
  306. if(retval != UA_STATUSCODE_GOOD) {
  307. UA_ServerConfig_delete(conf);
  308. return NULL;
  309. }
  310. return conf;
  311. }
  312. #ifdef UA_ENABLE_ENCRYPTION
  313. UA_ServerConfig *
  314. UA_ServerConfig_new_basic128rsa15(UA_UInt16 portNumber,
  315. const UA_ByteString *certificate,
  316. const UA_ByteString *privateKey,
  317. const UA_ByteString *trustList,
  318. size_t trustListSize,
  319. const UA_ByteString *revocationList,
  320. size_t revocationListSize) {
  321. UA_ServerConfig *conf = createDefaultConfig();
  322. UA_StatusCode retval = UA_CertificateVerification_Trustlist(&conf->certificateVerification,
  323. trustList, trustListSize,
  324. revocationList, revocationListSize);
  325. if(retval != UA_STATUSCODE_GOOD) {
  326. UA_ServerConfig_delete(conf);
  327. return NULL;
  328. }
  329. retval = UA_Nodestore_default_new(&conf->nodestore);
  330. if(retval != UA_STATUSCODE_GOOD) {
  331. UA_ServerConfig_delete(conf);
  332. return NULL;
  333. }
  334. if(addDefaultNetworkLayers(conf, portNumber, 0, 0) != UA_STATUSCODE_GOOD) {
  335. UA_ServerConfig_delete(conf);
  336. return NULL;
  337. }
  338. if(trustListSize == 0)
  339. UA_LOG_WARNING(UA_Log_Stdout, UA_LOGCATEGORY_USERLAND,
  340. "No CA trust-list provided. Any remote certificate will be accepted.");
  341. /* Allocate the endpoints */
  342. conf->endpointsSize = 0;
  343. conf->endpoints = (UA_Endpoint *)UA_malloc(sizeof(UA_Endpoint) * 3);
  344. if(!conf->endpoints) {
  345. UA_ServerConfig_delete(conf);
  346. return NULL;
  347. }
  348. /* Populate the endpoints */
  349. ++conf->endpointsSize;
  350. retval = createSecurityPolicyNoneEndpoint(conf, &conf->endpoints[0], *certificate);
  351. if(retval != UA_STATUSCODE_GOOD) {
  352. UA_ServerConfig_delete(conf);
  353. return NULL;
  354. }
  355. ++conf->endpointsSize;
  356. retval = createSecurityPolicyBasic128Rsa15Endpoint(conf, &conf->endpoints[1],
  357. UA_MESSAGESECURITYMODE_SIGN, *certificate,
  358. *privateKey);
  359. if(retval != UA_STATUSCODE_GOOD) {
  360. UA_ServerConfig_delete(conf);
  361. return NULL;
  362. }
  363. ++conf->endpointsSize;
  364. retval = createSecurityPolicyBasic128Rsa15Endpoint(conf, &conf->endpoints[2],
  365. UA_MESSAGESECURITYMODE_SIGNANDENCRYPT, *certificate,
  366. *privateKey);
  367. if(retval != UA_STATUSCODE_GOOD) {
  368. UA_ServerConfig_delete(conf);
  369. return NULL;
  370. }
  371. return conf;
  372. }
  373. UA_ServerConfig *
  374. UA_ServerConfig_new_basic256sha256(UA_UInt16 portNumber,
  375. const UA_ByteString *certificate,
  376. const UA_ByteString *privateKey,
  377. const UA_ByteString *trustList,
  378. size_t trustListSize,
  379. const UA_ByteString *revocationList,
  380. size_t revocationListSize) {
  381. UA_ServerConfig *conf = createDefaultConfig();
  382. UA_StatusCode retval = UA_CertificateVerification_Trustlist(&conf->certificateVerification,
  383. trustList, trustListSize,
  384. revocationList, revocationListSize);
  385. if(retval != UA_STATUSCODE_GOOD) {
  386. UA_ServerConfig_delete(conf);
  387. return NULL;
  388. }
  389. retval = UA_Nodestore_default_new(&conf->nodestore);
  390. if(retval != UA_STATUSCODE_GOOD) {
  391. UA_ServerConfig_delete(conf);
  392. return NULL;
  393. }
  394. if(addDefaultNetworkLayers(conf, portNumber, 0, 0) != UA_STATUSCODE_GOOD) {
  395. UA_ServerConfig_delete(conf);
  396. return NULL;
  397. }
  398. if(trustListSize == 0)
  399. UA_LOG_WARNING(UA_Log_Stdout, UA_LOGCATEGORY_USERLAND,
  400. "No CA trust-list provided. Any remote certificate will be accepted.");
  401. /* Allocate the endpoints */
  402. conf->endpointsSize = 0;
  403. conf->endpoints = (UA_Endpoint *)UA_malloc(sizeof(UA_Endpoint) * 3);
  404. if(!conf->endpoints) {
  405. UA_ServerConfig_delete(conf);
  406. return NULL;
  407. }
  408. /* Populate the endpoints */
  409. ++conf->endpointsSize;
  410. retval = createSecurityPolicyNoneEndpoint(conf, &conf->endpoints[0], *certificate);
  411. if(retval != UA_STATUSCODE_GOOD) {
  412. UA_ServerConfig_delete(conf);
  413. return NULL;
  414. }
  415. ++conf->endpointsSize;
  416. retval = createSecurityPolicyBasic256Sha256Endpoint(conf, &conf->endpoints[1],
  417. UA_MESSAGESECURITYMODE_SIGN, *certificate,
  418. *privateKey);
  419. if(retval != UA_STATUSCODE_GOOD) {
  420. UA_ServerConfig_delete(conf);
  421. return NULL;
  422. }
  423. ++conf->endpointsSize;
  424. retval = createSecurityPolicyBasic256Sha256Endpoint(conf, &conf->endpoints[2],
  425. UA_MESSAGESECURITYMODE_SIGNANDENCRYPT, *certificate,
  426. *privateKey);
  427. if(retval != UA_STATUSCODE_GOOD) {
  428. UA_ServerConfig_delete(conf);
  429. return NULL;
  430. }
  431. return conf;
  432. }
  433. UA_ServerConfig *
  434. UA_ServerConfig_new_allSecurityPolicies(UA_UInt16 portNumber,
  435. const UA_ByteString *certificate,
  436. const UA_ByteString *privateKey,
  437. const UA_ByteString *trustList,
  438. size_t trustListSize,
  439. const UA_ByteString *revocationList,
  440. size_t revocationListSize) {
  441. UA_ServerConfig *conf = createDefaultConfig();
  442. UA_StatusCode retval = UA_CertificateVerification_Trustlist(&conf->certificateVerification,
  443. trustList, trustListSize,
  444. revocationList, revocationListSize);
  445. if(retval != UA_STATUSCODE_GOOD) {
  446. UA_ServerConfig_delete(conf);
  447. return NULL;
  448. }
  449. retval = UA_Nodestore_default_new(&conf->nodestore);
  450. if(retval != UA_STATUSCODE_GOOD) {
  451. UA_ServerConfig_delete(conf);
  452. return NULL;
  453. }
  454. if(addDefaultNetworkLayers(conf, portNumber, 0, 0) != UA_STATUSCODE_GOOD) {
  455. UA_ServerConfig_delete(conf);
  456. return NULL;
  457. }
  458. if(trustListSize == 0)
  459. UA_LOG_WARNING(UA_Log_Stdout, UA_LOGCATEGORY_USERLAND,
  460. "No CA trust-list provided. Any remote certificate will be accepted.");
  461. /* Allocate the endpoints */
  462. conf->endpointsSize = 0;
  463. conf->endpoints = (UA_Endpoint *)UA_malloc(sizeof(UA_Endpoint) * 5);
  464. if(!conf->endpoints) {
  465. UA_ServerConfig_delete(conf);
  466. return NULL;
  467. }
  468. /* Populate the endpoints */
  469. retval = createSecurityPolicyNoneEndpoint(conf, &conf->endpoints[conf->endpointsSize], *certificate);
  470. ++conf->endpointsSize;
  471. if(retval != UA_STATUSCODE_GOOD) {
  472. UA_ServerConfig_delete(conf);
  473. return NULL;
  474. }
  475. retval = createSecurityPolicyBasic128Rsa15Endpoint(conf, &conf->endpoints[conf->endpointsSize],
  476. UA_MESSAGESECURITYMODE_SIGN, *certificate,
  477. *privateKey);
  478. ++conf->endpointsSize;
  479. if(retval != UA_STATUSCODE_GOOD) {
  480. UA_ServerConfig_delete(conf);
  481. return NULL;
  482. }
  483. retval = createSecurityPolicyBasic128Rsa15Endpoint(conf, &conf->endpoints[conf->endpointsSize],
  484. UA_MESSAGESECURITYMODE_SIGNANDENCRYPT, *certificate,
  485. *privateKey);
  486. ++conf->endpointsSize;
  487. if(retval != UA_STATUSCODE_GOOD) {
  488. UA_ServerConfig_delete(conf);
  489. return NULL;
  490. }
  491. retval = createSecurityPolicyBasic256Sha256Endpoint(conf, &conf->endpoints[conf->endpointsSize],
  492. UA_MESSAGESECURITYMODE_SIGN, *certificate,
  493. *privateKey);
  494. ++conf->endpointsSize;
  495. if(retval != UA_STATUSCODE_GOOD) {
  496. UA_ServerConfig_delete(conf);
  497. return NULL;
  498. }
  499. retval = createSecurityPolicyBasic256Sha256Endpoint(conf, &conf->endpoints[conf->endpointsSize],
  500. UA_MESSAGESECURITYMODE_SIGNANDENCRYPT, *certificate,
  501. *privateKey);
  502. ++conf->endpointsSize;
  503. if(retval != UA_STATUSCODE_GOOD) {
  504. UA_ServerConfig_delete(conf);
  505. return NULL;
  506. }
  507. return conf;
  508. }
  509. #endif
  510. void
  511. UA_ServerConfig_delete(UA_ServerConfig *config) {
  512. if(!config)
  513. return;
  514. /* Server Description */
  515. UA_BuildInfo_deleteMembers(&config->buildInfo);
  516. UA_ApplicationDescription_deleteMembers(&config->applicationDescription);
  517. #ifdef UA_ENABLE_DISCOVERY
  518. UA_String_deleteMembers(&config->mdnsServerName);
  519. UA_Array_delete(config->serverCapabilities, config->serverCapabilitiesSize,
  520. &UA_TYPES[UA_TYPES_STRING]);
  521. config->serverCapabilities = NULL;
  522. config->serverCapabilitiesSize = 0;
  523. #endif
  524. /* Nodestore */
  525. if(config->nodestore.deleteNodestore)
  526. config->nodestore.deleteNodestore(config->nodestore.context);
  527. /* Custom DataTypes */
  528. /* nothing to do */
  529. /* Networking */
  530. for(size_t i = 0; i < config->networkLayersSize; ++i)
  531. config->networkLayers[i].deleteMembers(&config->networkLayers[i]);
  532. UA_free(config->networkLayers);
  533. config->networkLayers = NULL;
  534. config->networkLayersSize = 0;
  535. UA_String_deleteMembers(&config->customHostname);
  536. config->customHostname = UA_STRING_NULL;
  537. for(size_t i = 0; i < config->endpointsSize; ++i) {
  538. UA_SecurityPolicy *policy = &config->endpoints[i].securityPolicy;
  539. policy->deleteMembers(policy);
  540. UA_EndpointDescription_deleteMembers(&config->endpoints[i].endpointDescription);
  541. }
  542. UA_free(config->endpoints);
  543. config->endpoints = NULL;
  544. config->endpointsSize = 0;
  545. /* Certificate Validation */
  546. config->certificateVerification.deleteMembers(&config->certificateVerification);
  547. /* Access Control */
  548. config->accessControl.deleteMembers(&config->accessControl);
  549. /* Historical data */
  550. #ifdef UA_ENABLE_HISTORIZING
  551. if(config->historyDatabase.deleteMembers)
  552. config->historyDatabase.deleteMembers(&config->historyDatabase);
  553. #endif
  554. /* Logger */
  555. if(config->logger.clear)
  556. config->logger.clear(config->logger.context);
  557. UA_free(config);
  558. }
  559. #ifdef UA_ENABLE_PUBSUB /* conditional compilation */
  560. /**
  561. * Add a pubsubTransportLayer to the configuration.
  562. * Memory is reallocated on demand */
  563. UA_StatusCode
  564. UA_ServerConfig_addPubSubTransportLayer(UA_ServerConfig *config,
  565. UA_PubSubTransportLayer *pubsubTransportLayer) {
  566. if(config->pubsubTransportLayersSize == 0) {
  567. config->pubsubTransportLayers = (UA_PubSubTransportLayer *)
  568. UA_malloc(sizeof(UA_PubSubTransportLayer));
  569. } else {
  570. config->pubsubTransportLayers = (UA_PubSubTransportLayer*)
  571. UA_realloc(config->pubsubTransportLayers,
  572. sizeof(UA_PubSubTransportLayer) * (config->pubsubTransportLayersSize + 1));
  573. }
  574. if (config->pubsubTransportLayers == NULL) {
  575. return UA_STATUSCODE_BADOUTOFMEMORY;
  576. }
  577. memcpy(&config->pubsubTransportLayers[config->pubsubTransportLayersSize],
  578. pubsubTransportLayer, sizeof(UA_PubSubTransportLayer));
  579. config->pubsubTransportLayersSize++;
  580. return UA_STATUSCODE_GOOD;
  581. }
  582. #endif /* UA_ENABLE_PUBSUB */
  583. /***************************/
  584. /* Default Client Settings */
  585. /***************************/
  586. static UA_INLINE void UA_ClientConnectionTCP_poll_callback(UA_Client *client, void *data) {
  587. UA_ClientConnectionTCP_poll(client, data);
  588. }
  589. const UA_ClientConfig UA_ClientConfig_default = {
  590. 5000, /* .timeout, 5 seconds */
  591. 10 * 60 * 1000, /* .secureChannelLifeTime, 10 minutes */
  592. {UA_Log_Stdout_log, NULL, UA_Log_Stdout_clear}, /* .logger */
  593. { /* .localConnectionConfig */
  594. 0, /* .protocolVersion */
  595. 65535, /* .sendBufferSize, 64k per chunk */
  596. 65535, /* .recvBufferSize, 64k per chunk */
  597. 0, /* .maxMessageSize, 0 -> unlimited */
  598. 0 /* .maxChunkCount, 0 -> unlimited */
  599. },
  600. UA_ClientConnectionTCP, /* .connectionFunc (for sync connection) */
  601. UA_ClientConnectionTCP_init, /* .initConnectionFunc (for async client) */
  602. UA_ClientConnectionTCP_poll_callback, /* .pollConnectionFunc (for async connection) */
  603. NULL, /* .customDataTypes */
  604. NULL, /* .stateCallback */
  605. 0, /* .connectivityCheckInterval */
  606. 1200000, /* requestedSessionTimeout */
  607. NULL, /* .inactivityCallback */
  608. NULL, /* .clientContext */
  609. #ifdef UA_ENABLE_SUBSCRIPTIONS
  610. 10, /* .outStandingPublishRequests */
  611. NULL /* .subscriptionInactivityCallback */
  612. #endif
  613. };