NodeOPCUA API Documentation
    Preparing search index...

    Interface OPCUACertificateManagerOptions

    interface OPCUACertificateManagerOptions {
        automaticallyAcceptUnknownCertificate?: boolean;
        disableFileWatchers?: boolean;
        keyOperations?: IKeyOperations;
        keySize?: 2048 | 4096 | 3072;
        name?: string;
        privateKeyPassphrase?: PrivateKeyPassphrase;
        privateKeyProvider?: PrivateKeyProvider;
        rootFolder?: string | null;
    }
    Index
    automaticallyAcceptUnknownCertificate?: boolean
    disableFileWatchers?: boolean

    When true, file-system watchers (chokidar) on the PKI folders are disabled. The initial scan still populates the in-memory indexes but live change detection is off.

    Useful in test / CI pipelines where many servers start in parallel and the accumulated fs.watch handles exhaust the libuv thread-pool.

    false
    
    keyOperations?: IKeyOperations

    Use a private key this manager can never read: an opaque IKeyOperations provider (HSM, KMS, TPM, OS keystore). Unlike privateKeyProvider — which sources raw key material — the key never enters the process: getPrivateKey() throws PrivateKeyUnavailableError and every use goes through getKeyOperations(). Mutually exclusive with privateKeyProvider and privateKeyPassphrase. See node-opcua-pki's private-key-protection guide for the full contract.

    undefined
    
    keySize?: 2048 | 4096 | 3072
    name?: string

    A label for this store. It does not change where the store lives: the folder is rootFolder alone. Callers that want one store per name build the path themselves, as getDefaultCertificateManager does with rootFolder: path.join(config, name).

    privateKeyPassphrase?: PrivateKeyPassphrase

    Encrypt the private key at rest with this passphrase (opt-in, default off — a plaintext key is written, exactly as before). When set:

    • a freshly generated key is written already encrypted (PKCS#8);
    • an existing plaintext key is re-encrypted in place by OPCUACertificateManager.initialize, so turning the option on for an existing install never leaves the key in cleartext;
    • an existing encrypted key requires the same passphrase — a mismatch, or an encrypted key with no passphrase configured, fails initialize() closed with PrivateKeyPassphraseRequiredError.

    A function is called at most once per OPCUACertificateManager instance (the decrypted key is cached in memory for the instance's lifetime, see OPCUACertificateManager.getPrivateKey). Never logged.

    The in-process default managers returned by getDefaultCertificateManager (memoized by name, e.g. "PKI" / "UserPKI") are always passphrase-less — construct your own OPCUACertificateManager and pass it as serverCertificateManager / clientCertificateManager to use passphrase protection.

    undefined (plaintext key)
    
    privateKeyProvider?: PrivateKeyProvider

    Source the private key from somewhere other than own/private/private_key.pem (an HSM, a KMS, ...). When set, it overrides disk entirely for every operation that needs the private key — the on-disk file is not read, and privateKeyPassphrase is ignored.

    undefined
    
    rootFolder?: string | null

    The folder that is the PKI store: own/, trusted/, issuers/ and rejected/ are created directly under it. name is not appended.

    Two managers given the same rootFolder share one store and one private key, whatever their name. Give every application, and every side of an application (server side, client side), a folder of its own.

    the per-user config folder of node-opcua (%APPDATA%/node-opcua-default on Windows, ~/.config/node-opcua-default elsewhere)