ua_config_default.c 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711
  1. /* This work is licensed under a Creative Commons CCZero 1.0 Universal License.
  2. * See http://creativecommons.org/publicdomain/zero/1.0/ for more information.
  3. *
  4. * Copyright 2017 (c) Fraunhofer IOSB (Author: Julius Pfrommer)
  5. * Copyright 2017 (c) Julian Grothoff
  6. * Copyright 2017-2018 (c) Mark Giraud, Fraunhofer IOSB
  7. * Copyright 2017 (c) Stefan Profanter, fortiss GmbH
  8. * Copyright 2017 (c) Thomas Stalder, Blue Time Concept SA
  9. * Copyright 2018 (c) Daniel Feist, Precitec GmbH & Co. KG
  10. * Copyright 2018 (c) Fabian Arndt, Root-Core
  11. * Copyright 2019 (c) Kalycito Infotech Private Limited
  12. */
  13. #include <open62541/client_config_default.h>
  14. #include <open62541/network_tcp.h>
  15. #include <open62541/plugin/accesscontrol_default.h>
  16. #include <open62541/plugin/log_stdout.h>
  17. #include <open62541/plugin/pki_default.h>
  18. #include <open62541/plugin/securitypolicy_default.h>
  19. #include <open62541/server_config_default.h>
  20. /* Struct initialization works across ANSI C/C99/C++ if it is done when the
  21. * variable is first declared. Assigning values to existing structs is
  22. * heterogeneous across the three. */
  23. static UA_INLINE UA_UInt32Range
  24. UA_UINT32RANGE(UA_UInt32 min, UA_UInt32 max) {
  25. UA_UInt32Range range = {min, max};
  26. return range;
  27. }
  28. static UA_INLINE UA_DurationRange
  29. UA_DURATIONRANGE(UA_Duration min, UA_Duration max) {
  30. UA_DurationRange range = {min, max};
  31. return range;
  32. }
  33. /*******************************/
  34. /* Default Connection Settings */
  35. /*******************************/
  36. const UA_ConnectionConfig UA_ConnectionConfig_default = {
  37. 0, /* .protocolVersion */
  38. 65535, /* .sendBufferSize, 64k per chunk */
  39. 65535, /* .recvBufferSize, 64k per chunk */
  40. 0, /* .maxMessageSize, 0 -> unlimited */
  41. 0 /* .maxChunkCount, 0 -> unlimited */
  42. };
  43. /***************************/
  44. /* Default Server Settings */
  45. /***************************/
  46. #define MANUFACTURER_NAME "open62541"
  47. #define PRODUCT_NAME "open62541 OPC UA Server"
  48. #define PRODUCT_URI "http://open62541.org"
  49. #define APPLICATION_NAME "open62541-based OPC UA Application"
  50. #define APPLICATION_URI "urn:unconfigured:application"
  51. #define STRINGIFY(arg) #arg
  52. #define VERSION(MAJOR, MINOR, PATCH, LABEL) \
  53. STRINGIFY(MAJOR) "." STRINGIFY(MINOR) "." STRINGIFY(PATCH) LABEL
  54. static UA_StatusCode
  55. createEndpoint(UA_ServerConfig *conf, UA_EndpointDescription *endpoint,
  56. const UA_SecurityPolicy *securityPolicy,
  57. UA_MessageSecurityMode securityMode) {
  58. UA_EndpointDescription_init(endpoint);
  59. endpoint->securityMode = securityMode;
  60. UA_String_copy(&securityPolicy->policyUri, &endpoint->securityPolicyUri);
  61. endpoint->transportProfileUri =
  62. UA_STRING_ALLOC("http://opcfoundation.org/UA-Profile/Transport/uatcp-uasc-uabinary");
  63. /* Add security level value for the corresponding message security mode */
  64. endpoint->securityLevel = (UA_Byte) securityMode;
  65. /* Enable all login mechanisms from the access control plugin */
  66. UA_StatusCode retval = UA_Array_copy(conf->accessControl.userTokenPolicies,
  67. conf->accessControl.userTokenPoliciesSize,
  68. (void **)&endpoint->userIdentityTokens,
  69. &UA_TYPES[UA_TYPES_USERTOKENPOLICY]);
  70. if(retval != UA_STATUSCODE_GOOD)
  71. return retval;
  72. endpoint->userIdentityTokensSize = conf->accessControl.userTokenPoliciesSize;
  73. UA_String_copy(&securityPolicy->localCertificate, &endpoint->serverCertificate);
  74. UA_ApplicationDescription_copy(&conf->applicationDescription, &endpoint->server);
  75. return UA_STATUSCODE_GOOD;
  76. }
  77. static const size_t usernamePasswordsSize = 2;
  78. static UA_UsernamePasswordLogin usernamePasswords[2] = {
  79. {UA_STRING_STATIC("user1"), UA_STRING_STATIC("password")},
  80. {UA_STRING_STATIC("user2"), UA_STRING_STATIC("password1")}};
  81. static UA_StatusCode
  82. setDefaultConfig(UA_ServerConfig *conf) {
  83. if (!conf)
  84. return UA_STATUSCODE_BADINVALIDARGUMENT;
  85. /* Zero out.. All members have a valid initial value */
  86. UA_ServerConfig_clean(conf);
  87. memset(conf, 0, sizeof(UA_ServerConfig));
  88. /* --> Start setting the default static config <-- */
  89. conf->nThreads = 1;
  90. conf->logger = UA_Log_Stdout_;
  91. /* Server Description */
  92. conf->buildInfo.productUri = UA_STRING_ALLOC(PRODUCT_URI);
  93. conf->buildInfo.manufacturerName = UA_STRING_ALLOC(MANUFACTURER_NAME);
  94. conf->buildInfo.productName = UA_STRING_ALLOC(PRODUCT_NAME);
  95. conf->buildInfo.softwareVersion =
  96. UA_STRING_ALLOC(VERSION(UA_OPEN62541_VER_MAJOR, UA_OPEN62541_VER_MINOR,
  97. UA_OPEN62541_VER_PATCH, UA_OPEN62541_VER_LABEL));
  98. #ifdef UA_PACK_DEBIAN
  99. conf->buildInfo.buildNumber = UA_STRING_ALLOC("deb");
  100. #else
  101. conf->buildInfo.buildNumber = UA_STRING_ALLOC(__DATE__ " " __TIME__);
  102. #endif
  103. conf->buildInfo.buildDate = 0;
  104. conf->applicationDescription.applicationUri = UA_STRING_ALLOC(APPLICATION_URI);
  105. conf->applicationDescription.productUri = UA_STRING_ALLOC(PRODUCT_URI);
  106. conf->applicationDescription.applicationName =
  107. UA_LOCALIZEDTEXT_ALLOC("en", APPLICATION_NAME);
  108. conf->applicationDescription.applicationType = UA_APPLICATIONTYPE_SERVER;
  109. /* conf->applicationDescription.gatewayServerUri = UA_STRING_NULL; */
  110. /* conf->applicationDescription.discoveryProfileUri = UA_STRING_NULL; */
  111. /* conf->applicationDescription.discoveryUrlsSize = 0; */
  112. /* conf->applicationDescription.discoveryUrls = NULL; */
  113. #ifdef UA_ENABLE_DISCOVERY_MULTICAST
  114. UA_MdnsDiscoveryConfiguration_init(&conf->discovery.mdns);
  115. conf->discovery.mdnsInterfaceIP = UA_STRING_NULL;
  116. #endif
  117. /* Custom DataTypes */
  118. /* conf->customDataTypesSize = 0; */
  119. /* conf->customDataTypes = NULL; */
  120. /* Networking */
  121. /* conf->networkLayersSize = 0; */
  122. /* conf->networkLayers = NULL; */
  123. /* conf->customHostname = UA_STRING_NULL; */
  124. /* Endpoints */
  125. /* conf->endpoints = {0, NULL}; */
  126. /* Certificate Verification that accepts every certificate. Can be
  127. * overwritten when the policy is specialized. */
  128. UA_CertificateVerification_AcceptAll(&conf->certificateVerification);
  129. /* Global Node Lifecycle */
  130. conf->nodeLifecycle.constructor = NULL;
  131. conf->nodeLifecycle.destructor = NULL;
  132. /* Relax constraints for the InformationModel */
  133. conf->relaxEmptyValueConstraint = true; /* Allow empty values */
  134. /* Limits for SecureChannels */
  135. conf->maxSecureChannels = 40;
  136. conf->maxSecurityTokenLifetime = 10 * 60 * 1000; /* 10 minutes */
  137. /* Limits for Sessions */
  138. conf->maxSessions = 100;
  139. conf->maxSessionTimeout = 60.0 * 60.0 * 1000.0; /* 1h */
  140. /* Limits for Subscriptions */
  141. conf->publishingIntervalLimits = UA_DURATIONRANGE(100.0, 3600.0 * 1000.0);
  142. conf->lifeTimeCountLimits = UA_UINT32RANGE(3, 15000);
  143. conf->keepAliveCountLimits = UA_UINT32RANGE(1, 100);
  144. conf->maxNotificationsPerPublish = 1000;
  145. conf->enableRetransmissionQueue = true;
  146. conf->maxRetransmissionQueueSize = 0; /* unlimited */
  147. #ifdef UA_ENABLE_SUBSCRIPTIONS_EVENTS
  148. conf->maxEventsPerNode = 0; /* unlimited */
  149. #endif
  150. /* Limits for MonitoredItems */
  151. conf->samplingIntervalLimits = UA_DURATIONRANGE(50.0, 24.0 * 3600.0 * 1000.0);
  152. conf->queueSizeLimits = UA_UINT32RANGE(1, 100);
  153. #ifdef UA_ENABLE_DISCOVERY
  154. conf->discovery.cleanupTimeout = 60 * 60;
  155. #endif
  156. #ifdef UA_ENABLE_HISTORIZING
  157. /* conf->accessHistoryDataCapability = UA_FALSE; */
  158. /* conf->maxReturnDataValues = 0; */
  159. /* conf->accessHistoryEventsCapability = UA_FALSE; */
  160. /* conf->maxReturnEventValues = 0; */
  161. /* conf->insertDataCapability = UA_FALSE; */
  162. /* conf->insertEventCapability = UA_FALSE; */
  163. /* conf->insertAnnotationsCapability = UA_FALSE; */
  164. /* conf->replaceDataCapability = UA_FALSE; */
  165. /* conf->replaceEventCapability = UA_FALSE; */
  166. /* conf->updateDataCapability = UA_FALSE; */
  167. /* conf->updateEventCapability = UA_FALSE; */
  168. /* conf->deleteRawCapability = UA_FALSE; */
  169. /* conf->deleteEventCapability = UA_FALSE; */
  170. /* conf->deleteAtTimeDataCapability = UA_FALSE; */
  171. #endif
  172. /* --> Finish setting the default static config <-- */
  173. return UA_STATUSCODE_GOOD;
  174. }
  175. UA_EXPORT UA_StatusCode
  176. UA_ServerConfig_setBasics(UA_ServerConfig* conf) {
  177. return setDefaultConfig(conf);
  178. }
  179. static UA_StatusCode
  180. addDefaultNetworkLayers(UA_ServerConfig *conf, UA_UInt16 portNumber,
  181. UA_UInt32 sendBufferSize, UA_UInt32 recvBufferSize) {
  182. return UA_ServerConfig_addNetworkLayerTCP(conf, portNumber, sendBufferSize, recvBufferSize);
  183. }
  184. UA_EXPORT UA_StatusCode
  185. UA_ServerConfig_addNetworkLayerTCP(UA_ServerConfig *conf, UA_UInt16 portNumber,
  186. UA_UInt32 sendBufferSize, UA_UInt32 recvBufferSize) {
  187. /* Add a network layer */
  188. UA_ServerNetworkLayer *tmp = (UA_ServerNetworkLayer *)
  189. UA_realloc(conf->networkLayers, sizeof(UA_ServerNetworkLayer) * (1 + conf->networkLayersSize));
  190. if(!tmp)
  191. return UA_STATUSCODE_BADOUTOFMEMORY;
  192. conf->networkLayers = tmp;
  193. UA_ConnectionConfig config = UA_ConnectionConfig_default;
  194. if (sendBufferSize > 0)
  195. config.sendBufferSize = sendBufferSize;
  196. if (recvBufferSize > 0)
  197. config.recvBufferSize = recvBufferSize;
  198. conf->networkLayers[conf->networkLayersSize] =
  199. UA_ServerNetworkLayerTCP(config, portNumber, &conf->logger);
  200. if (!conf->networkLayers[conf->networkLayersSize].handle)
  201. return UA_STATUSCODE_BADOUTOFMEMORY;
  202. conf->networkLayersSize++;
  203. return UA_STATUSCODE_GOOD;
  204. }
  205. UA_EXPORT UA_StatusCode
  206. UA_ServerConfig_addSecurityPolicyNone(UA_ServerConfig *config,
  207. const UA_ByteString *certificate) {
  208. UA_StatusCode retval;
  209. /* Allocate the SecurityPolicies */
  210. UA_SecurityPolicy *tmp = (UA_SecurityPolicy *)
  211. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * (1 + config->securityPoliciesSize));
  212. if(!tmp)
  213. return UA_STATUSCODE_BADOUTOFMEMORY;
  214. config->securityPolicies = tmp;
  215. /* Populate the SecurityPolicies */
  216. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  217. if(certificate)
  218. localCertificate = *certificate;
  219. retval = UA_SecurityPolicy_None(&config->securityPolicies[config->securityPoliciesSize], NULL,
  220. localCertificate, &config->logger);
  221. if(retval != UA_STATUSCODE_GOOD)
  222. return retval;
  223. config->securityPoliciesSize++;
  224. return UA_STATUSCODE_GOOD;
  225. }
  226. UA_EXPORT UA_StatusCode
  227. UA_ServerConfig_addEndpoint(UA_ServerConfig *config, const UA_String securityPolicyUri,
  228. UA_MessageSecurityMode securityMode)
  229. {
  230. UA_StatusCode retval;
  231. /* Allocate the endpoint */
  232. UA_EndpointDescription * tmp = (UA_EndpointDescription *)
  233. UA_realloc(config->endpoints, sizeof(UA_EndpointDescription) * (1 + config->endpointsSize));
  234. if(!tmp) {
  235. return UA_STATUSCODE_BADOUTOFMEMORY;
  236. }
  237. config->endpoints = tmp;
  238. /* Lookup the security policy */
  239. const UA_SecurityPolicy *policy = NULL;
  240. for (size_t i = 0; i < config->securityPoliciesSize; ++i) {
  241. if (UA_String_equal(&securityPolicyUri, &config->securityPolicies[i].policyUri)) {
  242. policy = &config->securityPolicies[i];
  243. break;
  244. }
  245. }
  246. if (!policy)
  247. return UA_STATUSCODE_BADINVALIDARGUMENT;
  248. /* Populate the endpoint */
  249. retval = createEndpoint(config, &config->endpoints[config->endpointsSize],
  250. policy, securityMode);
  251. if(retval != UA_STATUSCODE_GOOD)
  252. return retval;
  253. config->endpointsSize++;
  254. return UA_STATUSCODE_GOOD;
  255. }
  256. UA_EXPORT UA_StatusCode
  257. UA_ServerConfig_addAllEndpoints(UA_ServerConfig *config) {
  258. UA_StatusCode retval;
  259. /* Allocate the endpoints */
  260. UA_EndpointDescription * tmp = (UA_EndpointDescription *)
  261. UA_realloc(config->endpoints, sizeof(UA_EndpointDescription) * (2 * config->securityPoliciesSize + config->endpointsSize));
  262. if(!tmp) {
  263. return UA_STATUSCODE_BADOUTOFMEMORY;
  264. }
  265. config->endpoints = tmp;
  266. /* Populate the endpoints */
  267. for (size_t i = 0; i < config->securityPoliciesSize; ++i) {
  268. if (UA_String_equal(&UA_SECURITY_POLICY_NONE_URI, &config->securityPolicies[i].policyUri)) {
  269. retval = createEndpoint(config, &config->endpoints[config->endpointsSize],
  270. &config->securityPolicies[i], UA_MESSAGESECURITYMODE_NONE);
  271. if(retval != UA_STATUSCODE_GOOD)
  272. return retval;
  273. config->endpointsSize++;
  274. } else {
  275. retval = createEndpoint(config, &config->endpoints[config->endpointsSize],
  276. &config->securityPolicies[i], UA_MESSAGESECURITYMODE_SIGN);
  277. if(retval != UA_STATUSCODE_GOOD)
  278. return retval;
  279. config->endpointsSize++;
  280. retval = createEndpoint(config, &config->endpoints[config->endpointsSize],
  281. &config->securityPolicies[i], UA_MESSAGESECURITYMODE_SIGNANDENCRYPT);
  282. if(retval != UA_STATUSCODE_GOOD)
  283. return retval;
  284. config->endpointsSize++;
  285. }
  286. }
  287. return UA_STATUSCODE_GOOD;
  288. }
  289. UA_EXPORT UA_StatusCode
  290. UA_ServerConfig_setMinimalCustomBuffer(UA_ServerConfig *config, UA_UInt16 portNumber,
  291. const UA_ByteString *certificate,
  292. UA_UInt32 sendBufferSize,
  293. UA_UInt32 recvBufferSize) {
  294. if (!config)
  295. return UA_STATUSCODE_BADINVALIDARGUMENT;
  296. UA_StatusCode retval = setDefaultConfig(config);
  297. if(retval != UA_STATUSCODE_GOOD) {
  298. UA_ServerConfig_clean(config);
  299. return retval;
  300. }
  301. retval = addDefaultNetworkLayers(config, portNumber, sendBufferSize, recvBufferSize);
  302. if(retval != UA_STATUSCODE_GOOD) {
  303. UA_ServerConfig_clean(config);
  304. return retval;
  305. }
  306. /* Allocate the SecurityPolicies */
  307. retval = UA_ServerConfig_addSecurityPolicyNone(config, certificate);
  308. if(retval != UA_STATUSCODE_GOOD) {
  309. UA_ServerConfig_clean(config);
  310. return retval;
  311. }
  312. /* Initialize the Access Control plugin */
  313. retval = UA_AccessControl_default(config, true,
  314. &config->securityPolicies[config->securityPoliciesSize-1].policyUri,
  315. usernamePasswordsSize, usernamePasswords);
  316. if(retval != UA_STATUSCODE_GOOD) {
  317. UA_ServerConfig_clean(config);
  318. return retval;
  319. }
  320. /* Allocate the endpoint */
  321. retval = UA_ServerConfig_addEndpoint(config, UA_SECURITY_POLICY_NONE_URI, UA_MESSAGESECURITYMODE_NONE);
  322. if(retval != UA_STATUSCODE_GOOD) {
  323. UA_ServerConfig_clean(config);
  324. return retval;
  325. }
  326. return UA_STATUSCODE_GOOD;
  327. }
  328. #ifdef UA_ENABLE_ENCRYPTION
  329. UA_EXPORT UA_StatusCode
  330. UA_ServerConfig_addSecurityPolicyBasic128Rsa15(UA_ServerConfig *config,
  331. const UA_ByteString *certificate,
  332. const UA_ByteString *privateKey) {
  333. UA_StatusCode retval;
  334. /* Allocate the SecurityPolicies */
  335. UA_SecurityPolicy *tmp = (UA_SecurityPolicy *)
  336. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * (1 + config->securityPoliciesSize));
  337. if(!tmp)
  338. return UA_STATUSCODE_BADOUTOFMEMORY;
  339. config->securityPolicies = tmp;
  340. /* Populate the SecurityPolicies */
  341. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  342. UA_ByteString localPrivateKey = UA_BYTESTRING_NULL;
  343. if(certificate)
  344. localCertificate = *certificate;
  345. if(privateKey)
  346. localPrivateKey = *privateKey;
  347. retval = UA_SecurityPolicy_Basic128Rsa15(&config->securityPolicies[config->securityPoliciesSize],
  348. &config->certificateVerification,
  349. localCertificate, localPrivateKey, &config->logger);
  350. if(retval != UA_STATUSCODE_GOOD)
  351. return retval;
  352. config->securityPoliciesSize++;
  353. return UA_STATUSCODE_GOOD;
  354. }
  355. UA_EXPORT UA_StatusCode
  356. UA_ServerConfig_addSecurityPolicyBasic256(UA_ServerConfig *config,
  357. const UA_ByteString *certificate,
  358. const UA_ByteString *privateKey) {
  359. UA_StatusCode retval;
  360. /* Allocate the SecurityPolicies */
  361. UA_SecurityPolicy *tmp = (UA_SecurityPolicy *)
  362. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * (1 + config->securityPoliciesSize));
  363. if(!tmp)
  364. return UA_STATUSCODE_BADOUTOFMEMORY;
  365. config->securityPolicies = tmp;
  366. /* Populate the SecurityPolicies */
  367. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  368. UA_ByteString localPrivateKey = UA_BYTESTRING_NULL;
  369. if(certificate)
  370. localCertificate = *certificate;
  371. if(privateKey)
  372. localPrivateKey = *privateKey;
  373. retval = UA_SecurityPolicy_Basic256(&config->securityPolicies[config->securityPoliciesSize],
  374. &config->certificateVerification,
  375. localCertificate, localPrivateKey, &config->logger);
  376. if(retval != UA_STATUSCODE_GOOD)
  377. return retval;
  378. config->securityPoliciesSize++;
  379. return UA_STATUSCODE_GOOD;
  380. }
  381. UA_EXPORT UA_StatusCode
  382. UA_ServerConfig_addSecurityPolicyBasic256Sha256(UA_ServerConfig *config,
  383. const UA_ByteString *certificate,
  384. const UA_ByteString *privateKey) {
  385. UA_StatusCode retval;
  386. /* Allocate the SecurityPolicies */
  387. UA_SecurityPolicy *tmp = (UA_SecurityPolicy *)
  388. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * (1 + config->securityPoliciesSize));
  389. if(!tmp)
  390. return UA_STATUSCODE_BADOUTOFMEMORY;
  391. config->securityPolicies = tmp;
  392. /* Populate the SecurityPolicies */
  393. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  394. UA_ByteString localPrivateKey = UA_BYTESTRING_NULL;
  395. if(certificate)
  396. localCertificate = *certificate;
  397. if(privateKey)
  398. localPrivateKey = *privateKey;
  399. retval = UA_SecurityPolicy_Basic256Sha256(&config->securityPolicies[config->securityPoliciesSize],
  400. &config->certificateVerification,
  401. localCertificate, localPrivateKey, &config->logger);
  402. if(retval != UA_STATUSCODE_GOOD)
  403. return retval;
  404. config->securityPoliciesSize++;
  405. return UA_STATUSCODE_GOOD;
  406. }
  407. UA_EXPORT UA_StatusCode
  408. UA_ServerConfig_addAllSecurityPolicies(UA_ServerConfig *config,
  409. const UA_ByteString *certificate,
  410. const UA_ByteString *privateKey) {
  411. UA_StatusCode retval;
  412. /* Allocate the SecurityPolicies */
  413. UA_SecurityPolicy *tmp = (UA_SecurityPolicy *)
  414. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * (4 + config->securityPoliciesSize));
  415. if(!tmp)
  416. return UA_STATUSCODE_BADOUTOFMEMORY;
  417. config->securityPolicies = tmp;
  418. /* Populate the SecurityPolicies */
  419. UA_ByteString localCertificate = UA_BYTESTRING_NULL;
  420. UA_ByteString localPrivateKey = UA_BYTESTRING_NULL;
  421. if(certificate)
  422. localCertificate = *certificate;
  423. if(privateKey)
  424. localPrivateKey = *privateKey;
  425. retval = UA_SecurityPolicy_None(&config->securityPolicies[config->securityPoliciesSize], NULL,
  426. localCertificate, &config->logger);
  427. if(retval != UA_STATUSCODE_GOOD)
  428. return retval;
  429. config->securityPoliciesSize++;
  430. retval = UA_SecurityPolicy_Basic128Rsa15(&config->securityPolicies[config->securityPoliciesSize],
  431. &config->certificateVerification,
  432. localCertificate, localPrivateKey, &config->logger);
  433. if(retval != UA_STATUSCODE_GOOD)
  434. return retval;
  435. config->securityPoliciesSize++;
  436. retval = UA_SecurityPolicy_Basic256(&config->securityPolicies[config->securityPoliciesSize],
  437. &config->certificateVerification,
  438. localCertificate, localPrivateKey, &config->logger);
  439. if(retval != UA_STATUSCODE_GOOD)
  440. return retval;
  441. config->securityPoliciesSize++;
  442. retval = UA_SecurityPolicy_Basic256Sha256(&config->securityPolicies[config->securityPoliciesSize],
  443. &config->certificateVerification,
  444. localCertificate, localPrivateKey, &config->logger);
  445. if(retval != UA_STATUSCODE_GOOD)
  446. return retval;
  447. config->securityPoliciesSize++;
  448. return retval;
  449. }
  450. UA_EXPORT UA_StatusCode
  451. UA_ServerConfig_setDefaultWithSecurityPolicies(UA_ServerConfig *conf,
  452. UA_UInt16 portNumber,
  453. const UA_ByteString *certificate,
  454. const UA_ByteString *privateKey,
  455. const UA_ByteString *trustList,
  456. size_t trustListSize,
  457. const UA_ByteString *revocationList,
  458. size_t revocationListSize) {
  459. UA_StatusCode retval = setDefaultConfig(conf);
  460. if(retval != UA_STATUSCODE_GOOD) {
  461. UA_ServerConfig_clean(conf);
  462. return retval;
  463. }
  464. retval = UA_CertificateVerification_Trustlist(&conf->certificateVerification,
  465. trustList, trustListSize,
  466. revocationList, revocationListSize);
  467. if (retval != UA_STATUSCODE_GOOD)
  468. return retval;
  469. if(trustListSize == 0)
  470. UA_LOG_WARNING(&conf->logger, UA_LOGCATEGORY_USERLAND,
  471. "No CA trust-list provided. "
  472. "Any remote certificate will be accepted.");
  473. retval = addDefaultNetworkLayers(conf, portNumber, 0, 0);
  474. if(retval != UA_STATUSCODE_GOOD) {
  475. UA_ServerConfig_clean(conf);
  476. return retval;
  477. }
  478. retval = UA_ServerConfig_addAllSecurityPolicies(conf, certificate, privateKey);
  479. if(retval != UA_STATUSCODE_GOOD) {
  480. UA_ServerConfig_clean(conf);
  481. return retval;
  482. }
  483. retval = UA_AccessControl_default(conf, true,
  484. &conf->securityPolicies[conf->securityPoliciesSize-1].policyUri,
  485. usernamePasswordsSize, usernamePasswords);
  486. if(retval != UA_STATUSCODE_GOOD) {
  487. UA_ServerConfig_clean(conf);
  488. return retval;
  489. }
  490. retval = UA_ServerConfig_addAllEndpoints(conf);
  491. if(retval != UA_STATUSCODE_GOOD) {
  492. UA_ServerConfig_clean(conf);
  493. return retval;
  494. }
  495. return UA_STATUSCODE_GOOD;
  496. }
  497. #endif
  498. /***************************/
  499. /* Default Client Settings */
  500. /***************************/
  501. static UA_INLINE void
  502. UA_ClientConnectionTCP_poll_callback(UA_Client *client, void *data) {
  503. UA_ClientConnectionTCP_poll(client, data);
  504. }
  505. UA_StatusCode
  506. UA_ClientConfig_setDefault(UA_ClientConfig *config) {
  507. config->timeout = 5000;
  508. config->secureChannelLifeTime = 10 * 60 * 1000; /* 10 minutes */
  509. config->logger.log = UA_Log_Stdout_log;
  510. config->logger.context = NULL;
  511. config->logger.clear = UA_Log_Stdout_clear;
  512. config->localConnectionConfig = UA_ConnectionConfig_default;
  513. /* Certificate Verification that accepts every certificate. Can be
  514. * overwritten when the policy is specialized. */
  515. UA_CertificateVerification_AcceptAll(&config->certificateVerification);
  516. /* With encryption enabled, the applicationUri needs to match the URI from
  517. * the certificate */
  518. config->clientDescription.applicationUri = UA_STRING_ALLOC(APPLICATION_URI);
  519. config->clientDescription.applicationType = UA_APPLICATIONTYPE_CLIENT;
  520. if(config->securityPoliciesSize > 0) {
  521. UA_LOG_ERROR(&config->logger, UA_LOGCATEGORY_NETWORK,
  522. "Could not initialize a config that already has SecurityPolicies");
  523. return UA_STATUSCODE_BADINTERNALERROR;
  524. }
  525. config->securityPolicies = (UA_SecurityPolicy*)UA_malloc(sizeof(UA_SecurityPolicy));
  526. if(!config->securityPolicies)
  527. return UA_STATUSCODE_BADOUTOFMEMORY;
  528. UA_StatusCode retval = UA_SecurityPolicy_None(config->securityPolicies, NULL,
  529. UA_BYTESTRING_NULL, &config->logger);
  530. if(retval != UA_STATUSCODE_GOOD) {
  531. UA_free(config->securityPolicies);
  532. config->securityPolicies = NULL;
  533. return retval;
  534. }
  535. config->securityPoliciesSize = 1;
  536. config->connectionFunc = UA_ClientConnectionTCP;
  537. config->initConnectionFunc = UA_ClientConnectionTCP_init; /* for async client */
  538. config->pollConnectionFunc = UA_ClientConnectionTCP_poll_callback; /* for async connection */
  539. config->customDataTypes = NULL;
  540. config->stateCallback = NULL;
  541. config->connectivityCheckInterval = 0;
  542. config->requestedSessionTimeout = 1200000; /* requestedSessionTimeout */
  543. config->inactivityCallback = NULL;
  544. config->clientContext = NULL;
  545. #ifdef UA_ENABLE_SUBSCRIPTIONS
  546. config->outStandingPublishRequests = 10;
  547. config->subscriptionInactivityCallback = NULL;
  548. #endif
  549. return UA_STATUSCODE_GOOD;
  550. }
  551. #ifdef UA_ENABLE_ENCRYPTION
  552. UA_StatusCode
  553. UA_ClientConfig_setDefaultEncryption(UA_ClientConfig *config,
  554. UA_ByteString localCertificate, UA_ByteString privateKey,
  555. const UA_ByteString *trustList, size_t trustListSize,
  556. const UA_ByteString *revocationList, size_t revocationListSize) {
  557. UA_StatusCode retval = UA_ClientConfig_setDefault(config);
  558. if(retval != UA_STATUSCODE_GOOD)
  559. return retval;
  560. retval = UA_CertificateVerification_Trustlist(&config->certificateVerification,
  561. trustList, trustListSize,
  562. revocationList, revocationListSize);
  563. if(retval != UA_STATUSCODE_GOOD)
  564. return retval;
  565. /* Populate SecurityPolicies */
  566. UA_SecurityPolicy *sp = (UA_SecurityPolicy*)
  567. UA_realloc(config->securityPolicies, sizeof(UA_SecurityPolicy) * 4);
  568. if(!sp)
  569. return UA_STATUSCODE_BADOUTOFMEMORY;
  570. config->securityPolicies = sp;
  571. retval = UA_SecurityPolicy_Basic128Rsa15(&config->securityPolicies[1],
  572. &config->certificateVerification,
  573. localCertificate, privateKey, &config->logger);
  574. if(retval != UA_STATUSCODE_GOOD)
  575. return retval;
  576. ++config->securityPoliciesSize;
  577. retval = UA_SecurityPolicy_Basic256(&config->securityPolicies[2],
  578. &config->certificateVerification,
  579. localCertificate, privateKey, &config->logger);
  580. if(retval != UA_STATUSCODE_GOOD)
  581. return retval;
  582. ++config->securityPoliciesSize;
  583. retval = UA_SecurityPolicy_Basic256Sha256(&config->securityPolicies[3],
  584. &config->certificateVerification,
  585. localCertificate, privateKey, &config->logger);
  586. if(retval != UA_STATUSCODE_GOOD)
  587. return retval;
  588. ++config->securityPoliciesSize;
  589. return UA_STATUSCODE_GOOD;
  590. }
  591. #endif