이 페이지에서

보안 기능을 지원하는 OPC UA 클라이언트 생성

OPC UA의 핵심 기능 중 하나는 보안 지원으로, 이를 통해 암호학적으로 암호화 및 서명된 프로토콜과 사용자 인증 및 권한 부여 기능을 이용할 수 있습니다.

이를 구현하려면 각 애플리케이션 인스턴스(프로그램 설치)마다 고유한 인증서( Application Instance Certificate )와 이에 대응하는 개인 키(private key)를 가져야 합니다.

애플리케이션은 자체적으로 자체 서명 인증서를 생성하거나( Qt OPC UA X509 지원 참조), OPC UA GDS를 사용하여 인증 기관(CA)으로부터 인증서를 발급받거나, 사용자가 수동으로 생성한 인증서로 간단히 구성할 수 있습니다.

UA 애플리케이션 구성

클라이언트가 보안 연결을 사용할 수 있도록 하려면 다음을 설정하는 것이 중요합니다.

  • 올바른 애플리케이션 ID
    m_identity = m_pkiConfig.applicationIdentity();
    를 구성해야 합니다.
  • SDK가 인증서, 개인 키, 신뢰 목록 등을 찾을 수 있도록 PKI 위치를 구성해야 합니다.

    예를 들어, Qt OPC UA 뷰어 예제의 코드를 참조하십시오:

    void MainWindow::setupPkiConfiguration()
    {
        const QDir pkidir =
                QDir(QStandardPaths::writableLocation(QStandardPaths::AppLocalDataLocation) + "/pki");
    
        if (!pkidir.exists()&& !copyDirRecursively(":/pki", pkidir.path()))
            qFatal("Could not set up directory %s!", qUtf8Printable(pkidir.path()));
    
        m_pkiConfig.setClientCertificateFile(pkidir.absoluteFilePath("own/certs/opcuaviewer.der"));
        m_pkiConfig.setPrivateKeyFile(pkidir.absoluteFilePath("own/private/opcuaviewer.pem"));
        m_pkiConfig.setTrustListDirectory(pkidir.absoluteFilePath("trusted/certs"));
        m_pkiConfig.setRevocationListDirectory(pkidir.absoluteFilePath("trusted/crl"));
        m_pkiConfig.setIssuerListDirectory(pkidir.absoluteFilePath("issuers/certs"));
        m_pkiConfig.setIssuerRevocationListDirectory(pkidir.absoluteFilePath("issuers/crl"));
    
        const QStringList toCreate = { m_pkiConfig.issuerListDirectory(),
                                       m_pkiConfig.issuerRevocationListDirectory() };
        for (const QString&dir: toCreate) {
            if (!QDir().mkpath(dir))
                qFatal("Could not create directory %s!", qUtf8Printable(dir));
        }
    }

    이 예제에서는 Qt 리소스 시스템에서 미리 구성된 자체 인증서 및 신뢰된 인증서를 파일 시스템의 쓰기 가능한 위치로 추출합니다. 발급자(해지) 목록을 위한 나머지 디렉터리는 수동으로 생성합니다.

첫 번째 연결

처음 연결할 때, 클라이언트는 서버 인증서를 신뢰해야 합니다.

클라이언트는 인증서 경고(인증서 세부 정보 포함)를 표시하고, 해당 인증서를 신뢰 목록에 저장할 수 있는 옵션을 제공해야 합니다. 예시는 Qt OPC UA Viewer Example을 참조하십시오.

클라이언트가 서버 인증서를 수락한 후에는 다시 연결을 시도할 수 있습니다. 이제 서버가 클라이언트 인증서를 거부할 수 있습니다. 이 경우 일반적인 오류 코드 BadSecurityChecksFailed 가 표시됩니다. 서버는 일반적으로 거부된 인증서를 rejected 폴더에 저장합니다. 관리자는 이러한 인증서를 신뢰 목록으로 이동하여 클라이언트를 신뢰할 수 있습니다. 이를 통해 클라이언트 인증서를 서버 컴퓨터로 수동으로 복사하는 과정을 생략할 수 있습니다.

서버가 클라이언트를 신뢰하게 되는 즉시, 보안이 적용된 상태로 연결할 수 있게 됩니다.

© 2026 The Qt Company Ltd. Documentation contributions included herein are the copyrights of their respective owners. The documentation provided herein is licensed under the terms of the GNU Free Documentation License version 1.3 as published by the Free Software Foundation. Qt and respective logos are trademarks of The Qt Company Ltd. in Finland and/or other countries worldwide. All other trademarks are property of their respective owners.