NodeOPCUA API Documentation
    Preparing search index...

    Interface OPCUADiscoveryServerOptions

    interface OPCUADiscoveryServerOptions {
        allowUnsecuredRegistration?: boolean;
        alternateHostname?: string[];
        automaticallyAcceptUnknownCertificate?: boolean;
        certificateFile?: string;
        certificateKeyPairProvider?: ICertificateKeyPairProvider;
        hostname?: string;
        port?: number;
        privateKeyFile?: string;
        securityModes?: MessageSecurityMode[];
        securityPolicies?: SecurityPolicy[];
        serverCertificateManager?: ICertificateStore | OPCUACertificateManager;
        serverInfo?: ApplicationDescriptionOptions;
    }

    Hierarchy (View Summary)

    Index
    allowUnsecuredRegistration?: boolean

    Accept RegisterServer / RegisterServer2 over a SecureChannel with MessageSecurityMode.None, i.e. from a caller that presented no application certificate.

    OPC UA Part 4 §5.5.5 / §5.5.6 require these services to be invoked over a SecureChannel that authenticates the caller. Enable only for legacy registrants that cannot open a secured channel, on a network you control.

    The FindServers, FindServersOnNetwork and GetEndpoints services are not affected: they stay available without message security, as Part 4 §5.5.1 requires.

    false
    
    alternateHostname?: string[]
    automaticallyAcceptUnknownCertificate?: boolean

    Trust any unknown application certificate presented by a registrant. Only used when serverCertificateManager is not provided.

    When false (the default), a registrant whose certificate is not in the trusted folder is refused at OpenSecureChannel and its certificate is placed in the rejected folder; an administrator moves it to the trusted folder to allow the registration. This matches the OPC Foundation UA-LDS default and OPC UA Part 12 §5.3.5, which makes the administrator-managed trust list the primary mechanism for establishing trust between applications.

    false
    
    certificateFile?: string
    certificateKeyPairProvider?: ICertificateKeyPairProvider

    Optional pre-built certificate + private-key provider. When supplied, OPCUASecureObject.getCertificate() / .getCertificateChain() / .getPrivateKey() delegate to this object verbatim, and the disk-backed path (fs.existsSync + readCertificateChain + readPrivateKey) is not used.

    Intended for browser builds (bundled via esbuild) and test fixtures that want to stage a cert+key pair without staging PKI folders on disk.

    When present, certificateFile / privateKeyFile become optional and may be omitted. When absent, those two fields remain required strings and a DiskCertificateKeyPairProvider is created automatically.

    hostname?: string
    port?: number
    privateKeyFile?: string
    securityModes?: MessageSecurityMode[]
    securityPolicies?: SecurityPolicy[]
    serverCertificateManager?: ICertificateStore | OPCUACertificateManager

    the server Certificate Manager

    the information used in the end point description