Trust a client certificate
- Last UpdatedMar 30, 2026
- 1 minute read
- PI System
- PI OPC UA Server 1.0
- Developer
To trust an OPC UA client SSL certificate on the PI OPC UA Server, perform the following steps:
-
In Windows Explorer, navigate to the folder C:\ProgramData\AVEVA\PCS\OPC UA Rejected Client Certificates\certs. This is the location where the certificate from the client is initially placed by default when attempting to connect to the OPC UA Server.
Note: The Program Data folder is hidden by default. Enable the hidden items option in Windows Explorer in order to view it.
-
Locate the certificate for the client that has been initially rejected. If never rejected, locate and select the certificate.
-
Right-click the certificate and select Install Certificate.
-
In the Certificate Import Wizard, select Local Machine for the Store Location and then Next.
-
In the Certificate Store view, select the radio button Place all certificates in the following store.
-
Browse to the certificate store Trusted People and select OK. This is the only choice that will work with the OPC UA certificate.
-
If the certificate is chained, the root of the issuer chain must be in the Local Machine \ Trusted Root Certification Authorities store.
-
-
Select Next.
-
Select Finish to complete the certificate installation. The OPC UA Client is successfully configured to connect to the PI OPC UA Server.
-
Finally, delete the certificate from the OPC UA Rejected Client Certificates folder, since the certificate is now installed.