Certificate Automation in Operational Technology (OT) combining PKI with OPC UA
Abstract
Operational Technology (OT) environments are undergoing a rapid transformation as industrial systems become increasingly connected to enterprise networks, cloud platforms, and Industrial IoT ecosystems. This increased connectivity enables new capabilities such as predictive maintenance, remote operation, and data driven optimization. At the same time, it significantly expands the cyberattack surface of industrial systems.
A fundamental requirement for securing connected industrial environments is the ability to establish trusted machine identities for devices, applications, and services. Public Key Infrastructure (PKI) provides the cryptographic foundation for these identities by issuing digital certificates that enable authentication, encrypted communication, and data integrity. Certificates allow industrial systems to verify the identity of communication partners before exchanging sensitive operational data.
However, implementing PKI in OT environments introduces unique operational challenges. Industrial deployments often include large and heterogeneous device fleets, long equipment lifecycles, limited connectivity, and strict availability requirements. Traditional manual certificate management processes cannot scale to such environments.
As a result, automated certificate lifecycle management has become a critical component of modern OT security architectures. Automation mechanisms enable organizations to provision, renew, and revoke certificates at scale while maintaining consistent security policies across distributed systems.
This whitepaper explores the role of certificate automation in OT environments. It examines the challenges of deploying PKI in industrial systems, discusses the security mechanisms provided by OPC UA, and explains how the Global Discovery Server (GDS) supports automated certificate lifecycle management. Finally, it outlines approaches for integrating OT PKI infrastructures with enterprise IT PKI while supporting regulatory and operational requirements.
Conclusion
While IT and OT have historically evolved with different priorities, with security in IT and operational continuity in OT, their growing convergence makes it necessary to reconcile these approaches rather than treat them as separate domains. The rise in cyber threats and stricter regulatory frameworks same as Zero-Trust strategy has made it clear that relying on network isolation alone is no longer sufficient for OT environments. At the same time, directly transferring IT security models, such as PKI, into OT without adaptation overlooks the unique constraints of industrial systems.
A balanced approach is therefore essential. By tailoring PKI principles to accommodate OT‑specific requirements, such as long asset lifecycles, limited connectivity, and strict operational controls, organizations can significantly enhance security without compromising reliability. In this context, technologies like OPC UA demonstrate how security by design principles, including authentication and authorization services as well as integrated certificate and trust management, can bridge the gap between IT and OT.
Integrating IT b ased PKI with OPC UA Global Discovery Server enables organizations to automate certificate provisioning, renewal, and trust management across large industrial device fleets. When combined with Certificate Lifecycle Management Tools even non OP C UA enabled devices integrate OT s pecific automation mechanisms with enterprise PKI infrastructures. With that organizations can achieve both strong security and operational efficiency while meeting emerging regulatory requirements for industrial cybersecurity. Ultimately, achieving a secure and resilient infrastructure depends on aligning IT security best practices with OT operational realities, creating a unified, zero t rust oriented framework that supports both protection and performance. The outcome is stronger and more consistent security, improved operational efficiency, reduced downtime, and increased system robustness, ultimately lowering operational costs while supporting agile security in industrial environments.
1. The Operational Technology (OT) Environment
Operational Technology (OT) refers to hardware and software systems that monitor and control industrial processes and physical infrastructure. These systems are widely used in sectors such as manufacturing, energy, transportation, utilities, and other forms of critical infrastructure.
Typical OT environments include:
• Industrial Control Systems (ICS)
• Supervisory Control and Data Acquisition (SCADA) systems
• Programmable Logic Controllers (PLCs)
• industrial sensors and actuators
• Human Machine Interfaces (HMIs)
• industrial gateways and edge computing systems
Historically, OT systems were designed to operate in isolated environments with limited external connectivity. Security was primarily achieved through physical separation and network segmentation. However, modern industrial environments increasingly integrate with enterprise IT systems and cloud platforms in order to support advanced analytics, centralized monitoring, and remote operations. Furthermore, strategies like Secure by Default and Zero-Trust concepts protect even isolated networks from threats from within.
This convergence between IT and OT environments introduces new cybersecurity risks. Industrial systems that were not originally designed for internet-connected environments must now protect against sophisticated cyber threats.
International cybersecurity frameworks such as IEC 62443 and NIST SP 800-82 (Guide to Industrial Control Systems Security) emphasize the need for secure communication, authentication mechanisms, and strong identity management for industrial systems. Establishing trustworthy identities for devices and applications has therefore become a central component of OT cybersecurity strategies.
1.1 Key Differences between IT and OT
Although IT and OT systems increasingly interact, they differ significantly in their operational requirements and technical characteristics.
Characteristic IT Environments OT Environments
Primary objective Data confidentiality System availability and integrity and safety
System lifetime 3 –5 years 10–30 years
Patch cycles Frequent Rare and carefully controlled
Connectivity Continuous network Segmented or intermittent access
Device Centralized and O ften manual or vendormanagement automated specific
Device Redundant/cluster Real hardware replacement replacement virtualized image
Availability and Safety
In enterprise IT environments, confidentiality and data integrity are often the primary security concerns. In contrast, OT systems prioritize availability and safety. Interruptions in industrial processes can lead to production losses, equipment damage, environmental incidents, or safety hazards.
Security mechanisms implemented in OT environments must therefore avoid introducing operational disruptions.
Long System Lifecycles
Industrial equipment typically remains in operation for extended periods of time. Device lifecycles of 10 to 30 years are common in manufacturing and critical infrastructure environments. During this time, cryptographic standards, certificate policies, and security requirements may evolve significantly.
Regulatory initiatives such as the Cyber Resilience Act (CRA) increasingly require manufacturers to ensure that connected products remain secure throughout their lifecycle, including the ability to manage cryptographic identities over long periods.
Controlled Patch Cycles
OT patch cycles are slow, risk‑managed, and tightly coordinated. They prioritize safety and operational continuity over speed. The cycle includes inventory, risk assessment, lab testing, scheduled deployment, and validation, often tied to maintenance windows or annual outages.
Restricted Connectivity
Many industrial networks are segmented or partially isolated from enterprise networks. Devices may operate in environments with limited connectivity or strict communication restrictions.
These constraints influence how certificate management and identity systems must be implemented.
Manual Device Management and Device Replacement
Fully automated device management is still uncommon in OT. While monitoring and inventory can often be automated, patching, configuration, and lifecycle activities typically remain manual due to safety, reliability, and vendor constraints.
Device replacement is a physical, on-site activity typically performed by maintenance personnel rather than security specialists. These replacements often occur under time pressure and outside normal hours, when centralized PKI or security teams are unavailable.
Heterogeneous Device Ecosystems
Industrial environments often contain devices from many different vendors and generations of technology. These devices may vary significantly in their processing capabilities, supported protocols, and security features.
Standards such as IEC 62443 encourage the use of interoperable security mechanisms to address this diversity.
2. PKI
Public Key Infrastructure (PKI) provides the framework for managing digital certificates and enabling secure communication through asymmetric cryptography.
At the heart of PKI are digital certificates, which bind a public crypto graphic key to an identity. These certificates are issued by trusted Certification Authorities (CAs) and can be verified by other systems during secure communication. In a PKI you need to manage the whole hierarchy with a root CA (preferably offline) and policy CAs and different issuing CAs. The separation with different CAs can be done for different reasons and use cases. There can be one branch in the hierarchy for OT equipment under one policy CA. Similarly, there can be one branch for Code signing. Another branch can be for service technicians. These are just examples and the hierarchy can be defined in other ways.
In both IT and OT environments, PKI supports several core security functions:
• authentication of systems and devices
• encryption of communications
• verification of data integrity
• es tablishment of trust between distributed systems
In industrial environments, certificates primarily represent machine identities rather than human users. Each device, application instance, or service endpoint may require its own cryptographic identity in order to participate securely in industrial communication.
Large industrial deployments can therefore involve thousands or even millions of machine identities, each requiring secure provisioning and lifecycle management.
However, managing certificates across thousands of devices becomes impractical if performed manually. Automated provisioning and lifecycle management mechanisms are therefore essential for maintaining security at scale.
Furthermore, certificates have limited validity periods and must be renewed periodically. They may also need to be revoked if devices are compromised or decommissioned.
Manual processes increase the risk of:
• expired certificates causing service outages
• inconsistent trust configurations
• unmanaged device identities
Automation of certificate lifecycle management is therefore a critical requirement for sustainable PKI deployments in OT systems.
Security frameworks for critical infrastructure, including requirements defined by NERC CIP for the North American electric grid, mandate strong authentication and cryptographic protections for systems that manage critical operations. PKI based authentication mechanisms are widely used to meet these requirements.
2.1
Certificate Lifecycle Management (CLM)
While PKI establishes the cryptographic trust infrastructure, Certificate Lifecycle Management (CLM) provides operational processes to manage certificates throughout their entire lifecycle. CLM systems automate critical certificate management functions such as:
• certificate enrollment and issuance
• certificate renewal and rotation
• certificate revocation
• trust list distribution
• monitoring and auditing of certificate usage
Automation reduces the operational burden associated with managing large numbers of certificates and helps prevent outages caused by expired or misconfigured certificates.
In OT environments, certificate lifecycle management must support multiple operational stages including:
• device manufacturing and provisioning
• secure onboarding during deployment
• long-term operational maintenance
• secure device decommissioning
2.2 PKI Challenges in OT environments (in comparison to IT)
While PKI is well established in enterprise IT environments, its deployment in industrial environments presents several unique challenges.
Guidance from organizations such as CISA (Cybersecurity and Infrastructure Security Agency) highlights the need for scalable identity management solutions capable of supporting large industrial device ecosystems.
2.2.1 Device fleet
IT environments typically consist of servers, workstations, laptops, mobile phones, printers, routers, and applications. The average lifetime of an IT device is relatively short, around two to four years. OT environments, however, rely on large and diverse device fleets, including PLCs, RTUs, actuators, and sensors distributed across multiple facilities and geographic locations. A significant portion of these devices are often many years old, run proprietary firmware, and are designed for lifecycles of 10 to 30 years. Ensuring that every endpoint can consume, store, and rotate X.509 certificates without vendor‑specific workarounds therefore becomes a major coordination effort.
2.2.2 Lifecycle management of Certificates
Certificate lifecycle management in IT environments is relatively mature, supported by standardized interfaces and robust tooling. Automation protocols such as SCEP, EST, and ACME, along with Windows auto‑ enrollment, Mobile Device Management (MDM) systems, and CLM platforms, provide consistent mechanisms for provisioning and renewing certificates across diverse devices and applications.
In contrast, OT environments have far fewer options for certificate automation. Many devices are older, run proprietary firmware, or lack support for standard enrollment protocols. Windows auto‑enrollment is generally irrelevant, and MDM services do not apply. As a result, certificate rollouts and expirations often require planned shutdowns, custom scripts, or manual intervention to maintain uptime and meet safety requirements. Real‑time CSR submission, certificate retrieval, and OCSP checks are not always feasible in constrained or intermittently connected environments.
Lifecycle operations must also be performed without disrupting production processes, which leads many OT teams to favor long‑lived certificates. Although this approach helps minimize downtime, it increases exposure if a private key is compromised. Short‑lived certificates reduce risk but require more frequent updates that rarely align with restrictive maintenance windows, which creates operational friction and scheduling challenges.
Additionally, most OT stacks lack native PKI integration points or support only basic CLI‑driven tooling. This forces administrators to rely on spreadsheets, ad hoc scripts, and periodic manual audits, which increases the likelihood of human error, missed expirations, and inconsistent security controls.
2.2.3 Network and Connectivity
Constraints
Many industrial networks operate under strict communication restrictions.
Devices may:
• operate in isolated network segments
• allow only limited inbound connections
• communicate through gateways
• have intermittent connectivity
Traditional enterprise certificate management solutions often assume continuous connectivity to centralized infrastructure. Industrial systems frequently require alternative models that accommodate these operational constraints.
3. OPC UA
OPC Unified Architecture (OPC UA) is a widely adopted communication standard for industrial automation systems. It provides a platform independent, service-oriented architecture designed to enable secure and reliable communication in smart manufacturing, industrial IoT (IIoT), and digital transformation initiatives. Developed and maintained by the OPC Foundation, OPC UA provides a standardized framework for information exchange between devices, control systems, and enterprise applications across diverse hardware and software platforms.
Security is a fundamental component of the OPC UA architecture. The communication framework includes built-in mechanisms for:
• application and user authentication
• encryption
• message integrity
• certificate based trust management
• application and user authorization
• audit capabilities
These capabilities align with the security principles defined in industrial cybersecurity standards such as IEC 62443
3.1 OPC UA Application Identification, Certificates and Trust Lists
OPC UA uses digital certificates to uniquely identify applications and establish trusted communication channels.
3.1.1 Application Description
Each OPC UA application exposes an Application Description containing metadata used for discovery and identification.
This information includes:
• Application URI
• product identifier
• application name
• application type
• discovery endpoints
The Application URI acts as a globally unique identifier and is included within the application instance certificate.
3.1.2
Application Instance Certificate
Every OPC UA application instance possesses an Application Instance Certificate. This certificate contains the public key used during secure communication and binds the key to the identity of the application. During the establishment of secure channels, OPC UA applications exchange certificates and verify that the communication partner is trusted before initiating encrypted communication.
The following figure shows the relationship between application description and application certificate.
3.1.3 Trust List and Certificate Store
Certificates of trusted OPC UA applications are stored in the trust list. These can be application instance certificates or CA certificates used to sign the application certificates. When a CA certificate is trusted, all application certificates signed by that CA are automatically trusted. Each CA certificate must have a Certificate Revocation List (CRL) of revoked certificates. This CRL is also stored in the trust list.
Certificates are stored in a certificate store, which contains separate locations for trusted and own certificates (ClientX.der + private key ClientX.pem).
The following figure shows the trust list and certificate store of an OPC UA application.
The trust list determines which applications are allowed to communicate securely with the system.
In large deployments, manually managing these trust lists across many devices becomes difficult, which highlights the importance of automated certificate management.
3.1.4 Certificate Content
OPC UA certificates follow the standard X.509 certificate format. They are exchanged in DER encoded format between client and server in OPC UA services for discovery and connection establishment. They are used for bidirectional application authentication based on client and server trust lists. Important certificate attributes include:
• subject name
• subject alternative names
• application URI
• public key information
• issuing certificate authority
• validity period
• key usage attributes
The inclusion of the Application URI ensures that certificates uniquely identify the corresponding application instance.
3.2 OPC UA User Authentication and Role Based Authorization
OPC UA supports multiple user authentication mechanisms to secure access to industrial systems. Clients can authenticate using anonymous access, username/password credentials, X.509 certificates, or JWT issued identity tokens that carry claims for federated identity scenarios. Certificate based authentication integrates seamlessly with enterprise PKI, allowing OPC UA servers to validate client identities via trusted certificate chains. After authentication, OPC UA implements role based user authorization, mapping users to roles such as operator, engineer, or administrator, each with specific permissions for reading, writing, or configuring nodes and methods. This layered approach ensures that sensitive OT resources are only accessible to authorized personnel, supporting compliance with industrial cybersecurity standards while maintaining operational flexibility.
4. GDS
The Global Discovery Server (GDS) is a component defined within the OPC UA specification that supports centralized discovery and certificate management for OPC UA applications.
In large industrial deployments, managing certificates and trust relationships manually is impractical. The GDS provides a standardized mechanism for automating these tasks and is therefore the standardized CLM solution for OPC UA.
Key capabilities of the GDS include:
• centralized application registration
• automated certificate issuance and renewal
• trust list management
• certificate revocation handling
• automated certificate distribution
By centralizing certificate management operations, the GDS simplifies the administration of large OPC UA environments and enables consistent security policies across distributed systems.
The GDS may operate as an independent certificate authority or integrate with an external enterprise PKI infrastructure.
The GDS can provide additional centralized OPC UA security services, such as single sign on mechanisms using JSON Web Tokens to authenticate users at OPC UA servers, or the distribution of secure communication keys for OPC UA publish/subscribe communication.
4.1 GDS Certificate Management Concepts
The GDS organizes certificate management using several logical structures that enable scalable administration.
4.1.1 Certificate Group
Certificate groups represent logical collections of certificates that share common policies or trust relationships.
Grouping certificates allows administrators to manage different certificate types independently while maintaining consistent automation mechanisms.
Different certificate groups may use:
• different issuing certificate authorities
• different cryptographic policies
• different validity periods
• different trust anchors
• different certificate usage
4.1.2 OPC UA Application Certificate Groups
Every OPC UA application has a default application certificate group with at least one OPC UA Application Instance Certificate and a trust list.
OPC UA applications may have more than one certificate group for the following use cases and certificate usage:
• OPC UA communication takes place within different security domains
• management of web server certificates
• management of user certificates
• management of TLS certificates e.g. for OPC UA publish/subscribe communication via MQTT
Separating certificate groups enables different trust models and security policies depending on the communication context.
4.1.3 GDS CA Certificate Group
The GDS may operate its own Certificate Authority for issuing OPC UA certificates. Alternatively, it may integrate with an external enterprise PKI.
In integrated environments, the GDS typically acts as a registration authority, forwarding certificate requests from devices to the enterprise CA while managing certificate distribution within the OT network.
In the GDS, a CA certificate group represents a combination of:
• shared trust list for all applications managed by the GDS
• the issuing certificate authority configuration used to sign certificates for the applications
• the certificate type(s) managed by the certificate group
4.1.4
Security domain
A Security Domain represents a group of devices and applications that share a common trust configuration.
All systems within the same security domain trust the same certificate authorities and follow the same certificate policies.
Security domains allow large industrial environments to be segmented into manageable trust zones.
4.2 Use of OPC UA to distribute certificates to OPC UA devices
OPC UA defines standardized services that allow applications to interact with the GDS for certificate lifecycle management. After registration, two primary distribution models are supported.
4.2.1 Application Registration
Before a device can participate in automated certificate management, it must register with the GDS.
During registration, the device provides information such as:
• Application URI
• product information
• supported certificate groups
• network endpoints
The GDS stores this information and associates the application with the appropriate security policies. The GDS configuration can discover devices and execute registration on their behalf.
4.2.2 PULL Certificate Management (OPC UA clients)
In the Pull model, applications periodically connect to the GDS to check for updates. During these interactions, devices may retrieve:
• newly issued certificates
• renewed certificates
• updated trust lists
• certificate revocation lists
The Pull model is particularly suitable for environments where devices are only allowed to initiate outbound connections or for OPC UA applications that have only client functionality.
4.2.3
PUSH Certificate Management (OPC UA servers)
In the Push model, the GDS acts as UA Client and actively distributes certificates and trust lists to registered devices (which is a UA Server).
This approach allows centralized administrators to deploy certificate updates across large device fleets in a coordinated manner.
Push management requires that the GDS can establish secure management connections to the devices.
4.3 GDS ‑Enabled Authorization and Identity Management Features
When combined with a GDS, OPC UA environments benefit from centralized user authorization management. The GDS acts as a trusted authority for issuing and revoking certificates, thereby simplifying the deployment of user certificates for certificate based authentication. The GDS can also manage role-based access assignments, enabling consistent authorization policies to be enforced across multiple devices. With support for JSON Web Tokens (JWT), the GDS can issue signed identity tokens for federated authentication, enabling secure cross-domain access to OPC UA services. By providing these centralized identity and authorization services, the GDS enhances the security, scalability and auditability of industrial networks, while reducing the operational complexity of certificate and user management.
5. Certificate management for other, non-OPC UA devices
Not all devices in industrial environments support OPC UA. Legacy equipment or devices using proprietary industrial protocols may require alternative certificate management approaches.
Possible solutions include:
• gateway based certificate management
• s tandard enrollment protocols
• use of traditional IT CLM solution
• manual certificate provisioning
5.1 Gateway‑based certificate management
Industrial gateways can often act as intermediaries, enabling secure communication between legacy protocols and OPC UA based systems. OPC UA defines a proxy functionality that enables certificates to be pushed through an OPC UA server to other non OPC UA applications on the same device, as well as to other devices connected to the server. One example is devices in a communication network managed by an industrial controller. The OPC UA server on the controller can push certificates to these devices.
5.2 Standard enrollment protocols
A competent PKI platform enables certificate automation also for such devices based on standard certificate enrollment protocols like ACME, CMP, EST, and SCEP, each of which exists to address different operational and technical constraints. ACME is optimized for highly automated, internet facing webserver. EST and SCEP are designed primarily for enrollment, focusing on issuing device certificates with minimal complexity. In contrast, CMP supports the full certificate management lifecycle, including enrollment, renewal, revocation, and status management, making it particularly suitable for environments that require comprehensive and automated certificate handling across the entire device lifecycle.
5.3 Use of traditional IT CLM solution
For legacy devices that do not support standard certificate management protocols, CLM solutions originally developed for IT environments can help extend certificate management coverage. By using OS specific agents, these OT devices can potentially be enabled for automated certificate management. In addition, advanced CLM platforms offer agentless push mechanisms for devices that cannot support an agent but provide a management API.
6. Combining OT PKI with IT PKI
Many organizations already operate enterprise PKI infrastructures to support identity management in IT environments.
Integrating OT PKI with enterprise PKI provides several advantages:
• centralized governance and certificate policies
• consistent identity management across IT and OT
• simplified compliance reporting
• improved visibility into machine identities
In many architectures, enterprise PKI systems provide the root trust infrastructure, while OT specific systems such as the OPC UA GDS provide the operational automation layer responsible for certificate provisioning and distribution.
6.1 Maximize OT device reach
The conclusion is that there may be a need to implement multiple certificate automation mechanisms to maximize coverage of OT devices. The need for each mechanism will vary from one OT environment to another, depending on device fleet and extent of OPC UA deployment.
Explanation to picture:
1. C ertificate automation for OPC UA devices is easily achieved through GDS integration, see section 4.2
2. Some non OPC UA devices can be covered through gateway based certificate management, see 5.1
3. O ther non OPC UA devices may support standard certificate automation protocols, e.g. EST or CMP, see 5.2
4. To reach other non OPC UA devices that do not support standard certificate automation protocols, installation of a CLM agent can enable certificate management through the CLM system, see 5.3
5. For non OPC UA devices not supporting standard certificate automation protocols and where a CLM agent c an not be installed, a CLM solution may still be able to deploy certificates based on agent l ess push mechanisms, e.g. script based API integration, see 5.3
6. Finally, an OT environment may consist of also devices where certificate automation is simply not possible as certificates must be deployed manually or, worst case, secure communication is not supported at all.
6.2 Chain of Trust
Different IT and OT issuing CAs with different certificate templates, key usage constraints, enrollment methods, revocation policies, adapted to respective domain and with physical network isolation can share the same Root CA to provide a simple governance.
This hybrid architecture allows organizations to maintain centralized control over certificate policies while supporting the operational constraints of industrial networks.
7. Regulatory and Standards Landscape for OT Cybersecurity
The importance of strong device identity and secure communication in industrial environments is reinforced by several international standards and regulatory frameworks.
IEC 62443 defines comprehensive cybersecurity requirements for industrial automation and control systems, including authentication, secure communication, and lifecycle security management.
NIST SP 800-82 provides guidance for securing industrial control systems and emphasizes the importance of encryption, authentication, and network security.
CISA provides operational cybersecurity guidance for critical infrastructure operators and promotes the adoption of strong device identity mechanisms.
NERC CIP standards mandate strict cybersecurity requirements for the North American electric grid, including authentication and encryption mechanisms for critical infrastructure systems.
The NIS2 Directive expands cybersecurity obligations for operators of essential services within the European Union, requiring organizations to implement robust technical and organizational security measures.
The Cyber Resilience Act (CRA) introduces cybersecurity requirements for connected products sold within the European market and emphasizes secure product design, vulnerability management, and lifecycle security.
Together, these frameworks highlight the growing importance of scalable identity management and automated certificate lifecycle management in modern industrial environments.
Solution: Unified Automation UaGDS - IN Groupe, Nexus CA integration
Combining enterprise grade Public Key Infrastructure (PKI) with automated certificate lifecycle management is a key requirement for secure and scalable OPC UA deployments in industrial environments. The integration of the Nexus Certificate Manager with the UaGDS from Unified Automation provides a ready-to-deploy solution that bridges enterprise security governance with automated operational technology (OT) certificate management.
In this architecture, the Nexus Certificate Manager acts as the central PKI and certificate authority (CA), providing trusted certificate issuance, policy enforcement, lifecycle management, and auditing capabilities.
It enables organizations to operate their OPC UA environments within a controlled PKI framework aligned with enterprise security and compliance requirements.
The UaGDS component implements the Global Discovery and Security Management functionality of OPC UA, enabling automated certificate provisioning and management for OPC UA applications across the network. Through the OPC UA GDS push and pull management models, UaGDS handles certificate distribution, trust list updates, and certificate renewal for connected OPC UA servers and clients.
UaGDS integrates with the PKI using the Certificate Management Protocol (CMP), a standardized protocol for automated certificate enrollment and management. When an OPC UA application requests a certificate via the GDS, the UaGDS generates a certificate request and forwards it to the Nexus Certificate Manager via the CMP. The PKI then validates the request according to defined policies, issues the certificate via the CA and returns it to UaGDS via the CMP workflow.
Once issued, UaGDS distributes the certificate to the requesting OPC UA application and manages the corresponding trust lists. This mechanism also supports automated certificate renewal and revocation handling, ensuring that certificates remain valid and trusted throughout their lifecycle.
This architecture delivers several key benefits for OT operators:
• automated certificate lifecycle management for OPC UA applications
• centralized trust and policy control through an enterprise grade PKI
• secure onboarding of OPC UA servers and clients
• simplified certificate renewal and revocation processes
• improved scalability and reduced operational effort
By combining the robust PKI capabilities of Nexus Certificate Manager with the standard OPC UA automation mechanisms offered by UaGDS, OT operators can establish a secure, scalable and standards-based infrastructure for managing certificates in industrial systems. This integrated solution minimizes the need for manual certificate handling, enhances trust management and supports the long term security requirements of modern industrial automation environments.
About IN Groupe and Nexus
IN Groupe is a global leader in secure identity and trust services, specializing in identity solutions, secure transactions and digital services.
With deep expertise across the entire identity value chain, IN Groupe delivers solutions ranging from citizen ID to professional identity services, all in support of its core mission: providing every individual – whether citizen, consumer, or professional – with a secure identity in both the physical and digital worlds.
Nexus, part of IN Groupe, enables organizations of all sizes and industries worldwide to issue, manage, and utilize PKI based trusted identities for their Workforce, Workplace devices, and Internet of Things (IoT) devices. Our comprehensive, EU hosted solutions and services help organizations achieve an identity first Zero Trust security approach based on open standards, that is future compatible, post quantum aligned, and compliant with European and global regulations.
IN Groupe employs 4,000 people across 40 countries, serving governments and businesses in approximately 130 countries. It operates a global network of 20 research and development centers, as well as 10 industrial sites, and generates annual consolidated revenue of nearly €1 billion (2025).
www.nexus.ingroupe.com
About Unified Automation
Unified Automation is a leading provider of software development kits (SDKs) and infrastructure components for OPC UA–based communication in industrial automation and the Industrial Internet of Things (IIoT). A comprehensive portfolio of OPC UA SDKs, development tools, and server products is provided to enable device manufacturers, software vendors, and system integrators to implement secure and interoperable OPC UA solutions across a wide range of platforms and operating systems.
Unified Automation’s technologies are widely used in industrial systems to implement standardized, secure, and scalable machine-to-machine communication. The company actively contributes to the OPC UA eco-system and supports industry initiatives aimed at advancing secure interoperability in industrial environments. Its solutions, including the UaGDS, help organizations simplify the deployment, discovery, and security management of OPC UA applications in large scale industrial networks.
www.unified automation.com
A global leader in secure identity and trust services