OptionalallowOptionalalternateOptionalautomaticallyTrust any unknown application certificate presented by a registrant.
Only used when serverCertificateManager is not provided.
When false (the default), a registrant whose certificate is not in the
trusted folder is refused at OpenSecureChannel and its certificate is
placed in the rejected folder; an administrator moves it to the trusted
folder to allow the registration. This matches the OPC Foundation
UA-LDS default and OPC UA Part 12 §5.3.5, which makes the
administrator-managed trust list the primary mechanism for establishing
trust between applications.
OptionalcertificateOptionalcertificateOptional pre-built certificate + private-key provider. When supplied,
OPCUASecureObject.getCertificate() / .getCertificateChain() /
.getPrivateKey() delegate to this object verbatim, and the disk-backed
path (fs.existsSync + readCertificateChain + readPrivateKey) is
not used.
Intended for browser builds (bundled via esbuild) and test fixtures that want to stage a cert+key pair without staging PKI folders on disk.
When present, certificateFile / privateKeyFile become optional and
may be omitted.
When absent, those two fields remain required strings and a
DiskCertificateKeyPairProvider is created automatically.
OptionalhostnameOptionalportOptionalprivateOptionalsecurityOptionalsecurityOptionalserverthe server Certificate Manager
Optionalserverthe information used in the end point description
Accept
RegisterServer/RegisterServer2over a SecureChannel withMessageSecurityMode.None, i.e. from a caller that presented no application certificate.OPC UA Part 4 §5.5.5 / §5.5.6 require these services to be invoked over a SecureChannel that authenticates the caller. Enable only for legacy registrants that cannot open a secured channel, on a network you control.
The
FindServers,FindServersOnNetworkandGetEndpointsservices are not affected: they stay available without message security, as Part 4 §5.5.1 requires.