Modbus addressing and function codes: why 40001 is register 0
A reference-style guide to Modbus data tables, 0-based versus 1-based addresses, the common function codes and exception responses, with the classic off-by-one trap explained.
· 3 minWhat Sign and SignAndEncrypt actually change, which security policies to avoid, how application certificates and trust lists work, and the connection errors you will meet first.
OPC UA security is easier to reason about once you separate its layers. Each answers a different question:
| Mode | What you get | Typical use |
|---|---|---|
| None | No signing, no encryption | Isolated lab tests only |
| Sign | Integrity and authenticity: messages cannot be altered undetected | Where confidentiality is not needed but tampering must be detected |
| SignAndEncrypt | Integrity, authenticity and confidentiality | Default choice for production networks |
Many servers ship with None enabled for convenience. On any network that carries real equipment, disable it.
The security policy fixes the cryptographic algorithms. Older policies based on SHA-1, namely Basic128Rsa15 and Basic256, are deprecated in current OPC UA specifications and should not be used for new work. Basic256Sha256 is widely supported and remains a common baseline, while newer policies such as Aes128_Sha256_RsaOaep and Aes256_Sha256_RsaPss are preferable when both ends support them. Match the strongest policy that every client and server in the system can handle, and write the choice down.
Each OPC UA client and server application has an X.509 application instance certificate. When a secure channel is opened, each side checks the other’s certificate against its trust list. The typical first-connection experience is therefore a refusal: the server places the unknown client certificate in a rejected store, and an administrator moves it to the trusted store after checking that it really belongs to the expected client. The client does the same for the server’s certificate.
The certificate has to match the application it represents:
When one of these fails, clients report status codes such as BadCertificateUntrusted, BadCertificateUriInvalid, BadCertificateHostNameInvalid or BadCertificateTimeInvalid. The names usually point straight at the cause. Prefer certificates issued by a certificate authority you control over trusting many individual self-signed ones, and plan renewal before expiry, because an expired certificate stops communication abruptly.
OPC UA supports four kinds of user identity token: anonymous, user name and password, X.509 user certificate and issued token. Practical guidance:
opc.tcp) to the clients that need it with firewall rules.For where OPC UA fits against other protocols, read OPC UA vs MQTT and the guide to companion specifications. For the wider security framework, see the practical introduction to IEC 62443.
Let’s look at your machine, your data flow or your production goal together. Describe your situation in a few sentences and the ASP Dijital team will reply by email.