{"id":2023,"date":"2026-08-10T14:24:02","date_gmt":"2026-08-10T14:24:02","guid":{"rendered":"https:\/\/integrationobjects.com\/blog\/?p=2023"},"modified":"2026-08-13T09:37:32","modified_gmt":"2026-08-13T09:37:32","slug":"opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua","status":"publish","type":"post","link":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/","title":{"rendered":"OPC UA Global Discovery Server (GDS) Explained: Centralized Certificate Management for OPC UA"},"content":{"rendered":"  \r\n    \r\n<div id=\"wpj-jtoc\" class=\"wpj-jtoc wpj-jtoc--main --jtoc-the-content --jtoc-theme-original-v3 --jtoc-title-align-left --jtoc-toggle-icon --jtoc-toggle-position-right --jtoc-toggle-1 --jtoc-has-numeration --jtoc-header-as-toggle --jtoc-headings-full-row-clickable --jtoc-text-hover-soft --jtoc-has-custom-styles --jtoc-is-unfolded --jtoc-animate --jtoc-align-left\" >\r\n  <!-- TOC -->\r\n        <div class=\"wpj-jtoc--toc wpj-jtoc--toc-inline \" >\r\n              <div class=\"wpj-jtoc--header\">\r\n        <div class=\"wpj-jtoc--header-main\">\r\n                    <div class=\"wpj-jtoc--title\">\r\n                        <span class=\"wpj-jtoc--title-label\">Table of contents<\/span>\r\n          <\/div>\r\n                                <div class=\"wpj-jtoc--toggle-wrap\">\r\n                                                          <div class=\"wpj-jtoc--toggle-box\">\r\n                  <div class=\"wpj-jtoc--toggle\"><\/div>\r\n                <\/div>\r\n                          <\/div>\r\n                  <\/div>\r\n      <\/div>\r\n            <div class=\"wpj-jtoc--body\">\r\n            <nav class=\"wpj-jtoc--nav\">\r\n        <ol class=\"wpj-jtoc--items\"><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--1--><\/span>        <a href=\"#why-certificate-management-matters\"  rel=\"nofollow\"  title=\"Why Certificate Management Matters\" data-numeration=\"1\">Why Certificate Management Matters<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--2--><\/span>        <a href=\"#what-is-an-opc-ua-global-discovery-server\"  rel=\"nofollow\"  title=\"What Is an OPC UA Global Discovery Server?\" data-numeration=\"2\">What Is an OPC UA Global Discovery Server?<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--3--><\/span>        <a href=\"#the-two-primary-responsibilities-of-a-gds\"  rel=\"nofollow\"  title=\"The Two Primary Responsibilities of a GDS\" data-numeration=\"3\">The Two Primary Responsibilities of a GDS<\/a>\r\n                    <\/div><ol class=\"wpj-jtoc--items\"><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--3.1--><\/span>        <a href=\"#1-enterprise-application-discovery\"  rel=\"nofollow\"  title=\"1. Enterprise Application Discovery\" data-numeration=\"3.1\">1. Enterprise Application Discovery<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--3.2--><\/span>        <a href=\"#2-certificate-lifecycle-management\"  rel=\"nofollow\"  title=\"2. Certificate Lifecycle Management\" data-numeration=\"3.2\">2. Certificate Lifecycle Management<\/a>\r\n                    <\/div><\/li><\/ol><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--4--><\/span>        <a href=\"#understanding-the-certificate-lifecycle\"  rel=\"nofollow\"  title=\"Understanding the Certificate Lifecycle\" data-numeration=\"4\">Understanding the Certificate Lifecycle<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--5--><\/span>        <a href=\"#certificate-enrollment\"  rel=\"nofollow\"  title=\"Certificate Enrollment\" data-numeration=\"5\">Certificate Enrollment<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--6--><\/span>        <a href=\"#trust-lists\"  rel=\"nofollow\"  title=\"Trust Lists\" data-numeration=\"6\">Trust Lists<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--7--><\/span>        <a href=\"#automatic-certificate-renewal\"  rel=\"nofollow\"  title=\"Automatic Certificate Renewal\" data-numeration=\"7\">Automatic Certificate Renewal<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--8--><\/span>        <a href=\"#push-and-pull-certificate-management\"  rel=\"nofollow\"  title=\"Push and Pull Certificate Management\" data-numeration=\"8\">Push and Pull Certificate Management<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--9--><\/span>        <a href=\"#certificate-revocation\"  rel=\"nofollow\"  title=\"Certificate Revocation\" data-numeration=\"9\">Certificate Revocation<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--10--><\/span>        <a href=\"#acting-as-a-certificate-authority\"  rel=\"nofollow\"  title=\"Acting as a Certificate Authority\" data-numeration=\"10\">Acting as a Certificate Authority<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--11--><\/span>        <a href=\"#integrating-with-enterprise-pki\"  rel=\"nofollow\"  title=\"Integrating with Enterprise PKI\" data-numeration=\"11\">Integrating with Enterprise PKI<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--12--><\/span>        <a href=\"#benefits-of-using-a-gds\"  rel=\"nofollow\"  title=\"Benefits of Using a GDS\" data-numeration=\"12\">Benefits of Using a GDS<\/a>\r\n                    <\/div><ol class=\"wpj-jtoc--items\"><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--12.1--><\/span>        <a href=\"#improved-security\"  rel=\"nofollow\"  title=\"Improved Security\" data-numeration=\"12.1\">Improved Security<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--12.2--><\/span>        <a href=\"#reduced-administrative-maintenance-overhead\"  rel=\"nofollow\"  title=\"Reduced Administrative\/Maintenance Overhead\" data-numeration=\"12.2\">Reduced Administrative\/Maintenance Overhead<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--12.3--><\/span>        <a href=\"#simplified-deployment\"  rel=\"nofollow\"  title=\"Simplified Deployment\" data-numeration=\"12.3\">Simplified Deployment<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--12.4--><\/span>        <a href=\"#consistent-security-policies\"  rel=\"nofollow\"  title=\"Consistent Security Policies\" data-numeration=\"12.4\">Consistent Security Policies<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h3\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h3\" data-depth=\"3\">\r\n                                        <span class=\"jtoc--num\"><!--12.5--><\/span>        <a href=\"#better-scalability\"  rel=\"nofollow\"  title=\"Better Scalability\" data-numeration=\"12.5\">Better Scalability<\/a>\r\n                    <\/div><\/li><\/ol><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--13--><\/span>        <a href=\"#when-should-you-deploy-a-gds\"  rel=\"nofollow\"  title=\"When Should You Deploy a GDS?\" data-numeration=\"13\">When Should You Deploy a GDS?<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--14--><\/span>        <a href=\"#gds-in-practice\"  rel=\"nofollow\"  title=\"GDS in Practice\" data-numeration=\"14\">GDS in Practice<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--15--><\/span>        <a href=\"#implementation-best-practices-for-gds-deployments\"  rel=\"nofollow\"  title=\"Implementation Best Practices for GDS Deployments\" data-numeration=\"15\">Implementation Best Practices for GDS Deployments<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--16--><\/span>        <a href=\"#frequently-asked-questions\"  rel=\"nofollow\"  title=\"Frequently Asked Questions\" data-numeration=\"16\">Frequently Asked Questions<\/a>\r\n                    <\/div><\/li><\/ol>      <\/nav>\r\n          <\/div>\r\n      <\/div>\r\n    <\/div>\r\n\n<p>In the previous article, &#8220;<a href=\"https:\/\/integrationobjects.com\/blog\/opc-ua-discovery-explained-understanding-lds-and-gds\/\">OPC UA Discovery Explained: Understanding LDS and GDS<\/a>,&#8221; we introduced the role of discovery services in OPC UA and compared the Local Discovery Server (LDS) with the Global Discovery Server (GDS).<\/p>\n<p>While the LDS mainly focuses on discovering OPC UA servers running on a single machine, GDS provides centralized management of OPC UA applications across an enterprise while automating certificate lifecycle management, which is one of the most challenging aspects of industrial cybersecurity.<\/p>\n<p>For organizations operating dozens or even hundreds of <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-unified-architecture\/opc-ua-client\">OPC UA clients<\/a> and servers, manually managing certificates quickly becomes impractical. GDS was introduced by the OPC Foundation to solve this problem by providing a scalable, standardized approach to application discovery and trust management.<\/p>\n<p>In this article, we explore how GDS works, why it matters, and how it simplifies secure OPC UA deployments.<\/p>\n<h2>Why Certificate Management Matters<\/h2>\n<p>Unlike OPC Classic, <a href=\"https:\/\/integrationobjects.com\/blog\/what-is-opc-ua\/\">OPC UA<\/a> was designed with security built into the protocol itself.<\/p>\n<p>Every OPC UA application, whether a client or a server, uses an Application Instance Certificate to establish its identity.<\/p>\n<p>When two OPC UA applications communicate, they must verify each other&#8217;s certificates before creating a secure channel.<\/p>\n<p>For a small system with only a few devices, exchanging certificates manually may be manageable. Now imagine an enterprise with:<\/p>\n<ul>\n<li>100 PLCs exposing OPC UA servers<\/li>\n<\/ul>\n<ul>\n<li>10 SCADA servers<\/li>\n<\/ul>\n<ul>\n<li>Multiple historians<\/li>\n<\/ul>\n<ul>\n<li>MES applications<\/li>\n<\/ul>\n<ul>\n<li>Cloud gateways<\/li>\n<\/ul>\n<ul>\n<li>Edge computing platforms<\/li>\n<\/ul>\n<ul>\n<li>Engineering workstations<\/li>\n<\/ul>\n<ul>\n<li>Third-party OPC UA clients<\/li>\n<\/ul>\n<p>Without centralized management:<\/p>\n<ul>\n<li>Every client must trust every server.<\/li>\n<\/ul>\n<ul>\n<li>Every server must trust every client.<\/li>\n<\/ul>\n<ul>\n<li>New applications require manual certificate distribution.<\/li>\n<\/ul>\n<ul>\n<li>Expired certificates interrupt communications.<\/li>\n<\/ul>\n<ul>\n<li>Revoking compromised certificates becomes a manual process.<\/li>\n<\/ul>\n<p>As deployments grow, certificate management becomes one of the largest maintenance burdens.<\/p>\n<h2>What Is an OPC UA Global Discovery Server?<\/h2>\n<p>The Global Discovery Server (GDS) is a centralized OPC UA server service, defined by the OPC Foundation n in Part 12, that manages both application discovery and certificate lifecycle management across an OPC UA environment. Think of it as the administrative control center for your OPC UA ecosystem. GDS enables organizations to:<\/p>\n<ul>\n<li>Register OPC UA applications<\/li>\n<\/ul>\n<ul>\n<li>Discover applications across the enterprise<\/li>\n<\/ul>\n<ul>\n<li>Issue application certificates<\/li>\n<\/ul>\n<ul>\n<li>Renew certificates<\/li>\n<\/ul>\n<ul>\n<li>Revoke certificates<\/li>\n<\/ul>\n<ul>\n<li>Manage trust lists<\/li>\n<\/ul>\n<ul>\n<li>Distribute trusted certificates<\/li>\n<li>Automate certificate enrollment<\/li>\n<\/ul>\n<p>Rather than manually configuring trust relationships between every client and server, applications interact with the GDS to obtain the information they need.<\/p>\n<h2>The Two Primary Responsibilities of a GDS<\/h2>\n<p>Although the GDS performs several functions, the 2 major categories are:<\/p>\n<h3>1. Enterprise Application Discovery<\/h3>\n<p>The GDS maintains a centralized registry of OPC UA applications. Applications can register information such as application name, application URI, product URI, discovery URL, endpoint URLs, supported security policies and transport profiles.<\/p>\n<p>This allows OPC UA client applications to locate available OPC UA servers throughout an organization without maintaining manual endpoint lists.<\/p>\n<p>For a deeper look at how this discovery mechanism works alongside the Local Discovery Server, see our related article:<\/p>\n<p style=\"text-align: center;\"><a id=\"download\" class=\"btn_product_download\" href=\"https:\/\/integrationobjects.com\/blog\/opc-ua-discovery-explained-understanding-lds-and-gds\/\"><strong>OPC UA Discovery Explained: Understanding LDS and GDS<\/strong><\/a><\/p>\n<h3>2. Certificate Lifecycle Management<\/h3>\n<p>The second role of the GDS is managing the complete lifecycle of OPC UA application certificates. This includes certificate enrollment, certificate issuance, certificate renewal, trust list distribution, certificate revocation and certificate replacement. For large deployments, this dramatically reduces engineering and maintenance efforts while improving security.<\/p>\n<h2>Understanding the Certificate Lifecycle<\/h2>\n<p>Every OPC UA application follows a lifecycle similar to the one below.<\/p>\n<figure id=\"attachment_2024\" aria-describedby=\"caption-attachment-2024\" style=\"width: 277px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-2024\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-certificate-lifecycle-diagram.png\" alt=\"Diagram of the OPC UA application certificate lifecycle from enrollment to renewal and revocation \" width=\"277\" height=\"418\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-certificate-lifecycle-diagram.png 320w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-certificate-lifecycle-diagram-199x300.png 199w\" sizes=\"auto, (max-width: 277px) 100vw, 277px\" \/><figcaption id=\"caption-attachment-2024\" class=\"wp-caption-text\">Figure 1: Certificate Lifecycle<\/figcaption><\/figure>\n<p>Without a GDS, most of these steps require manual intervention. With a GDS, they can be automated.<\/p>\n<h2>Certificate Enrollment<\/h2>\n<p>When a new OPC UA application is installed, it first needs an application certificate.<\/p>\n<p>Instead of generating and distributing certificates manually, the application can submit a certificate signing request (CSR) to the GDS. The GDS verifies the request according to the organization&#8217;s policies and issues a signed certificate.<\/p>\n<p>This process ensures:<\/p>\n<ul>\n<li>Consistent certificate policies<\/li>\n<\/ul>\n<ul>\n<li>Trusted certificate issuance<\/li>\n<\/ul>\n<ul>\n<li>Reduced manual configuration<\/li>\n<\/ul>\n<ul>\n<li>Faster deployment of new applications<\/li>\n<\/ul>\n<h2>Trust Lists<\/h2>\n<p>One of the most time-consuming aspects of <a href=\"https:\/\/integrationobjects.com\/blog\/blog-opc-ua-security\/\">OPC UA security<\/a> is maintaining trust relationships. Each OPC UA application maintains a trust list, which contains certificates it considers trustworthy. Without centralized management, administrators must manually copy certificates between every client and server. As systems grow, this quickly becomes unmanageable. GDS solves this by maintaining centralized trust lists that can include:<\/p>\n<ul>\n<li>Trusted Certificate Authorities (CAs)<\/li>\n<\/ul>\n<ul>\n<li>Trusted application certificates<\/li>\n<\/ul>\n<ul>\n<li>Issuer certificates<\/li>\n<\/ul>\n<ul>\n<li>Certificate Revocation Lists (CRLs)<\/li>\n<\/ul>\n<p>Applications periodically synchronize their trust stores with GDS, ensuring they always have the latest trusted certificates and revocation information.<\/p>\n<h2>Automatic Certificate Renewal<\/h2>\n<p>Certificates have finite validity periods. If a certificate expires, secure communication may fail until a replacement certificate is installed.<\/p>\n<p>Manual renewal introduces several risks such as unexpected communication failures, production downtime, forgotten renewal dates and human error during replacement.<\/p>\n<p>GDS can automate this process by:<\/p>\n<ol>\n<li>Monitoring certificate expiration dates.<\/li>\n<li>Generating replacement certificates before expiration.<\/li>\n<li>Delivering the new certificates to applications.<\/li>\n<li>Updating trust lists automatically.<\/li>\n<\/ol>\n<p>Automation helps maintain continuous operation while reducing administrative overhead.<\/p>\n<h2>Push and Pull Certificate Management<\/h2>\n<p>The OPC UA specification, Part 12, defines two models for how a GDS delivers certificates and trust list updates to applications:<\/p>\n<ul>\n<li><strong>Push Management<\/strong> &#8211; the GDS pushes new certificates and updated trust lists directly to a running server or client. This requires the connecting client to hold the SecurityAdmin role over an encrypted channel, and the GDS will only deliver an update over a channel at least as strong as the certificate being installed. It will not push a 4096-bit certificate down a connection secured with a weaker policy.<\/li>\n<\/ul>\n<ul>\n<li><strong>Pull Management<\/strong> &#8211; the application periodically connects to the GDS and requests (pulls) certificate and trust list updates on its own schedule.<\/li>\n<\/ul>\n<p>In practice, server applications more commonly use Push, since they can expose the methods needed to receive updates, while client applications more commonly use Pull.<\/p>\n<h2>Certificate Revocation<\/h2>\n<p>Sometimes certificates must be invalidated before they expire. Common reasons include:<\/p>\n<ul>\n<li>A device has been decommissioned.<\/li>\n<\/ul>\n<ul>\n<li>A private key has been compromised.<\/li>\n<\/ul>\n<ul>\n<li>An application has been replaced.<\/li>\n<\/ul>\n<ul>\n<li>Unauthorized software has been detected.<\/li>\n<\/ul>\n<p>Rather than waiting for the certificate to expire naturally, administrators can revoke it.<\/p>\n<p>GDS updates its Certificate Revocation List (CRL), and applications receive the updated revocation information during trust list synchronization.<\/p>\n<p>This helps prevent compromised applications from participating in secure communications.<\/p>\n<h2>Acting as a Certificate Authority<\/h2>\n<p>A GDS implementation can operate as a Certificate Authority (CA<strong>)<\/strong> or integrate with an existing CA. As a CA, GDS can:<\/p>\n<ul>\n<li>Issue certificates<\/li>\n<\/ul>\n<ul>\n<li>Sign certificate requests<\/li>\n<\/ul>\n<ul>\n<li>Renew certificates<\/li>\n<\/ul>\n<ul>\n<li>Revoke certificates<\/li>\n<\/ul>\n<ul>\n<li>Publish CRLs<\/li>\n<\/ul>\n<p>It is worth noting that dedicated, production-ready GDS products are still relatively limited compared to the broader PKI market. Many organizations today rely on reference implementations, vendor-specific GDS features built into PLC or SCADA platforms, or integration with an external CA rather than a standalone, full-featured GDS product. Organizations should verify the capabilities of their chosen GDS implementation, as features can vary significantly between vendors.<\/p>\n<h2>Integrating with Enterprise PKI<\/h2>\n<p>Many organizations already operate a Public Key Infrastructure (PKI), often based on solutions such as Microsoft Active Directory Certificate Services (AD CS). Rather than replacing the existing PKI, a GDS can often integrate with it.<\/p>\n<p>A common architecture looks like this:<\/p>\n<figure id=\"attachment_2025\" aria-describedby=\"caption-attachment-2025\" style=\"width: 460px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2025\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-gds-enterprise-pki-integration-architecture.png\" alt=\"Architecture diagram showing OPC UA GDS integrated with enterprise PKI\" width=\"460\" height=\"498\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-gds-enterprise-pki-integration-architecture.png 460w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-ua-gds-enterprise-pki-integration-architecture-277x300.png 277w\" sizes=\"auto, (max-width: 460px) 100vw, 460px\" \/><figcaption id=\"caption-attachment-2025\" class=\"wp-caption-text\">Figure 2: Integrating OPC UA GDS with Enterprise PKI<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>In this model:<\/p>\n<ul>\n<li>The enterprise PKI remains the root of trust.<\/li>\n<\/ul>\n<ul>\n<li>GDS manages OPC UA application certificates.<\/li>\n<\/ul>\n<ul>\n<li>Corporate certificate policies continue to apply.<\/li>\n<\/ul>\n<ul>\n<li>Certificate enrollment becomes automated.<\/li>\n<\/ul>\n<p>This approach aligns industrial security with enterprise IT governance.<\/p>\n<h2>Benefits of Using a GDS<\/h2>\n<p>Implementing a GDS provides several important advantages.<\/p>\n<h3>Improved Security<\/h3>\n<p>Centralized certificate management reduces inconsistent trust configurations and helps ensure that only authorized applications participate in OPC UA communications.<\/p>\n<h3>Reduced Administrative\/Maintenance Overhead<\/h3>\n<p>Administrators manage certificates from a central location rather than configuring trust individually on every client and server.<\/p>\n<h3>Simplified Deployment<\/h3>\n<p>New OPC UA applications can automatically:<\/p>\n<ul>\n<li>Register with GDS<\/li>\n<\/ul>\n<ul>\n<li>Request certificates<\/li>\n<\/ul>\n<ul>\n<li>Receive trust lists<\/li>\n<\/ul>\n<ul>\n<li>Join the existing security infrastructure<\/li>\n<\/ul>\n<p>This significantly accelerates commissioning.<\/p>\n<h3>Consistent Security Policies<\/h3>\n<p>Organizations can enforce standardized certificate lifetimes, signing algorithms, and trust policies across all OPC UA applications.<\/p>\n<h3>Better Scalability<\/h3>\n<p>The larger the deployment, the greater the benefits of centralized certificate lifecycle management.<\/p>\n<h2>When Should You Deploy a GDS?<\/h2>\n<p>GDS is especially valuable when:<\/p>\n<ul>\n<li>Managing dozens or hundreds of OPC UA applications<\/li>\n<\/ul>\n<ul>\n<li>Operating multiple production sites<\/li>\n<\/ul>\n<ul>\n<li>Integrating OT with enterprise IT<\/li>\n<\/ul>\n<ul>\n<li>Implementing Industrial IoT architectures<\/li>\n<\/ul>\n<ul>\n<li>Connecting cloud platforms<\/li>\n<\/ul>\n<ul>\n<li>Supporting multiple engineering teams<\/li>\n<\/ul>\n<ul>\n<li>Enforcing centralized cybersecurity policies<\/li>\n<\/ul>\n<p>Small standalone systems may not require a GDS, but enterprise deployments typically benefit significantly from its capabilities.<\/p>\n<h2>GDS in Practice<\/h2>\n<p>GDS support is picking up and appearing as a built-in capability in industrial software platforms rather than requiring a separate standalone product. For example, recent PLC platforms have added native &#8220;GDS Push&#8221; toggles that let an external GDS manage a server&#8217;s certificate and trust list automatically once enabled. This is turning what used to be a manual, per-application configuration step into a centrally managed one. This trend reflects the direction GDS adoption is heading: less a bolt-on tool, and more a standard feature of the platforms already running on the plant floor.<\/p>\n<h2>Implementation Best Practices for GDS Deployments<\/h2>\n<ul>\n<li>Integrate with your enterprise PKI whenever practical.<\/li>\n<li>Protect the GDS using strong authentication and role-based access control. The GDS holds privileged access to your entire certificate infrastructure, so it should be treated as a Tier-0 security asset, not a general-purpose server.<\/li>\n<li>Monitor certificate expiration proactively.<\/li>\n<li>Maintain a local rejected-certificate log on each\u00a0OPC UA\u00a0application even when using a GDS. Centralized trust management should\u00a0not remove your ability to see and investigate what tried to connect at the individual application level. This local visibility is what lets you identify a misconfigured or unauthorized device quickly.<\/li>\n<li>Audit certificate issuance and revocation events, and forward those logs to your SIEM or central logging platform rather than leaving them only on the GDS.<\/li>\n<li>Test certificate renewal procedures before production deployment.<\/li>\n<li>Consider redundant GDS instances for high-availability .<\/li>\n<li>Keep GDS software updated to address security vulnerabilities and maintain compatibility with evolving OPC UA specifications.<\/li>\n<li>Plan for crypto agility by choosing a GDS and PKI architecture that can move beyond current algorithms (e.g., RSA-based suites) toward newer, stronger options as OPC UA security policy recommendations evolve, rather than hard-coding today&#8217;s algorithms into your infrastructure.<\/li>\n<\/ul>\n<h2>Frequently Asked Questions<\/h2>\n<style>#sp-ea-2026 .spcollapsing { height: 0; overflow: hidden; transition-property: height;transition-duration: 300ms;}#sp-ea-2026.sp-easy-accordion>.sp-ea-single {margin-bottom: 10px; border: 1px solid #e2e2e2; }#sp-ea-2026.sp-easy-accordion>.sp-ea-single>.ea-header a {color: #444;}#sp-ea-2026.sp-easy-accordion>.sp-ea-single>.sp-collapse>.ea-body {background: #fff; color: #444;}#sp-ea-2026.sp-easy-accordion>.sp-ea-single {background: #eee;}#sp-ea-2026.sp-easy-accordion>.sp-ea-single>.ea-header a .ea-expand-icon { float: left; color: #444;font-size: 16px;}.sp-easy-accordion .sp-ea-single .ea-header a{\r\n  display: block;\r\n    text-decoration: none;\r\n    cursor: pointer;\r\n    font-weight: 600;\r\n    color: #444;\r\n    font-size: 16px;\r\n    line-height: 1;\r\n  box-shadow: none;}<\/style><div id=\"sp_easy_accordion-1786371377\"><div id=\"sp-ea-2026\" class=\"sp-ea-one sp-easy-accordion\" data-ea-active=\"ea-click\" data-ea-mode=\"vertical\" data-preloader=\"\" data-scroll-active-item=\"\" data-offset-to-scroll=\"0\"><div class=\"ea-card ea-expand sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20260\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20260\" aria-controls=\"collapse20260\" href=\"#\" aria-expanded=\"true\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-minus\"><\/i> Does every OPC UA deployment need a GDS? <\/a><\/h3><div class=\"sp-collapse spcollapse collapsed show\" id=\"collapse20260\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20260\"> <div class=\"ea-body\"><p>No. Small systems with only a few OPC UA applications can often manage certificates manually. As the number of applications grows, a GDS greatly simplifies administration and improves security.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20261\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20261\" aria-controls=\"collapse20261\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Does GDS replace a Certificate Authority? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20261\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20261\"> <div class=\"ea-body\"><p>Not necessarily. As covered above, some GDS implementations include CA functionality, while others integrate with an organization's existing PKI. Many enterprises tend to prefer integration so that OPC UA certificates follow the same governance model as other corporate certificates.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20262\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20262\" aria-controls=\"collapse20262\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Does GDS manage user authentication certificates? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20262\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20262\"> <div class=\"ea-body\"><p>GDS-based centralization primarily applies to application instance certificates. User authentication certificates are handled through a separate trust store and, per the OPC UA specification, can be centrally managed through a GDS's optional KeyCredentialService. Although, this is far less commonly implemented than application certificate management.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20263\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20263\" aria-controls=\"collapse20263\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Can the GDS automatically renew certificates? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20263\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20263\"> <div class=\"ea-body\"><p>Yes. One of the major advantages of a GDS is its ability to automate certificate renewal, reducing downtime caused by expired certificates and minimizing manual administrative tasks.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20264\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20264\" aria-controls=\"collapse20264\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Why would users deploy a GDS? What are the benefits? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20264\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20264\"> <div class=\"ea-body\"><p>By automating tasks such as certificate enrollment, renewal, and revocation, the GDS reduces operational complexity while strengthening the overall security posture of industrial systems. When integrated with an enterprise PKI, it also aligns operational technology with established IT security practices, providing a unified approach to identity and trust management. For organizations building scalable, secure OPC UA infrastructures, the GDS is more than a convenience. It is a foundational component of modern certificate management.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20265\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20265\" aria-controls=\"collapse20265\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Are GDS and certificate management the only security controls in OPC UA? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20265\" data-parent=\"#sp-ea-2026\" role=\"region\" aria-labelledby=\"ea-header-20265\"> <div class=\"ea-body\"><p>No. It is worth remembering that GDS solves certificate lifecycle management specifically. It does not replace the other controls that make an OPC UA deployment secure. A complete security posture still depends on enforcing Sign or SignAndEncrypt with modern security policies, applying role-based access control on top of certificate-based application authentication, and keeping deprecated policies like Basic128Rsa15 disabled. GDS reduces the operational burden of the certificate piece. It is one component of a defensible architecture, not the whole of it.<\/p><\/div><\/div><\/div><script type=\"application\/ld+json\">{ \"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"@id\": \"sp-ea-schema-2026-6aae7c8816c37\", \"mainEntity\": [{ \"@type\": \"Question\", \"name\": \"Does every OPC UA deployment need a GDS? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"No. Small systems with only a few OPC UA applications can often manage certificates manually. As the number of applications grows, a GDS greatly simplifies administration and improves security.\" } },{ \"@type\": \"Question\", \"name\": \"Does GDS replace a Certificate Authority? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Not necessarily. As covered above, some GDS implementations include CA functionality, while others integrate with an organization's existing PKI. Many enterprises tend to prefer integration so that OPC UA certificates follow the same governance model as other corporate certificates.\" } },{ \"@type\": \"Question\", \"name\": \"Does GDS manage user authentication certificates? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"GDS-based centralization primarily applies to application instance certificates. User authentication certificates are handled through a separate trust store and, per the OPC UA specification, can be centrally managed through a GDS's optional KeyCredentialService. Although, this is far less commonly implemented than application certificate management.\" } },{ \"@type\": \"Question\", \"name\": \"Can the GDS automatically renew certificates? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Yes. One of the major advantages of a GDS is its ability to automate certificate renewal, reducing downtime caused by expired certificates and minimizing manual administrative tasks.\" } },{ \"@type\": \"Question\", \"name\": \"Why would users deploy a GDS? What are the benefits? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"By automating tasks such as certificate enrollment, renewal, and revocation, the GDS reduces operational complexity while strengthening the overall security posture of industrial systems. When integrated with an enterprise PKI, it also aligns operational technology with established IT security practices, providing a unified approach to identity and trust management. For organizations building scalable, secure OPC UA infrastructures, the GDS is more than a convenience. It is a foundational component of modern certificate management.\" } },{ \"@type\": \"Question\", \"name\": \"Are GDS and certificate management the only security controls in OPC UA? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"No. It is worth remembering that GDS solves certificate lifecycle management specifically. It does not replace the other controls that make an OPC UA deployment secure. A complete security posture still depends on enforcing Sign or SignAndEncrypt with modern security policies, applying role-based access control on top of certificate-based application authentication, and keeping deprecated policies like Basic128Rsa15 disabled. GDS reduces the operational burden of the certificate piece. It is one component of a defensible architecture, not the whole of it.\" } }] }<\/script><\/div><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the previous article, &#8220;OPC UA Discovery Explained: Understanding LDS and GDS,&#8221; we introduced the role of discovery services in OPC UA and compared the<\/p>\n","protected":false},"author":1,"featured_media":2027,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[183],"tags":[196,194],"class_list":["post-2023","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opc-ua","tag-opc-ua-discovery","tag-opc-ua-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>OPC UA GDS Explained: Centralized Certificate Management<\/title>\n<meta name=\"description\" content=\"Learn how the OPC UA Global Discovery Server (GDS) simplifies certificate management, trust lists, and secure application deployment across enterprise OPC UA systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OPC UA GDS Explained: Centralized Certificate Management\" \/>\n<meta property=\"og:description\" content=\"Learn how the OPC UA Global Discovery Server (GDS) simplifies certificate management, trust lists, and secure application deployment across enterprise OPC UA systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/\" \/>\n<meta property=\"og:site_name\" content=\"OPC Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Integration.Objects.OPC\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T14:24:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-13T09:37:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/OPC-UA-Global-Discovery-Server-GDS-Explained.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1248\" \/>\n\t<meta property=\"og:image:height\" content=\"832\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"OPCBlogAdmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:site\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"OPCBlogAdmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OPC UA GDS Explained: Centralized Certificate Management","description":"Learn how the OPC UA Global Discovery Server (GDS) simplifies certificate management, trust lists, and secure application deployment across enterprise OPC UA systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/","og_locale":"en_US","og_type":"article","og_title":"OPC UA GDS Explained: Centralized Certificate Management","og_description":"Learn how the OPC UA Global Discovery Server (GDS) simplifies certificate management, trust lists, and secure application deployment across enterprise OPC UA systems.","og_url":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/","og_site_name":"OPC Blog","article_publisher":"https:\/\/www.facebook.com\/Integration.Objects.OPC\/","article_published_time":"2026-08-10T14:24:02+00:00","article_modified_time":"2026-08-13T09:37:32+00:00","og_image":[{"width":1248,"height":832,"url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/OPC-UA-Global-Discovery-Server-GDS-Explained.png","type":"image\/png"}],"author":"OPCBlogAdmin","twitter_card":"summary_large_image","twitter_creator":"@IntegObjects","twitter_site":"@IntegObjects","twitter_misc":{"Written by":"OPCBlogAdmin","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/","url":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/","name":"OPC UA GDS Explained: Centralized Certificate Management","isPartOf":{"@id":"https:\/\/integrationobjects.com\/blog-\/#website"},"primaryImageOfPage":{"@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/#primaryimage"},"image":{"@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/#primaryimage"},"thumbnailUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/OPC-UA-Global-Discovery-Server-GDS-Explained.png","datePublished":"2026-08-10T14:24:02+00:00","dateModified":"2026-08-13T09:37:32+00:00","author":{"@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b"},"description":"Learn how the OPC UA Global Discovery Server (GDS) simplifies certificate management, trust lists, and secure application deployment across enterprise OPC UA systems.","breadcrumb":{"@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/#primaryimage","url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/OPC-UA-Global-Discovery-Server-GDS-Explained.png","contentUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/OPC-UA-Global-Discovery-Server-GDS-Explained.png","width":1248,"height":832,"caption":"OPC UA GDS certificate management"},{"@type":"BreadcrumbList","@id":"https:\/\/integrationobjects.com\/blog\/opc-ua-global-discovery-server-gds-explained-centralized-certificate-management-for-opc-ua\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/integrationobjects.com\/blog-\/"},{"@type":"ListItem","position":2,"name":"OPC UA Global Discovery Server (GDS) Explained: Centralized Certificate Management for OPC UA"}]},{"@type":"WebSite","@id":"https:\/\/integrationobjects.com\/blog-\/#website","url":"https:\/\/integrationobjects.com\/blog-\/","name":"OPC Blog","description":"OPC and related technologies news from Integration Objects","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/integrationobjects.com\/blog-\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b","name":"OPCBlogAdmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","caption":"OPCBlogAdmin"}}]}},"_links":{"self":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/comments?post=2023"}],"version-history":[{"count":5,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2023\/revisions"}],"predecessor-version":[{"id":2055,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2023\/revisions\/2055"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media\/2027"}],"wp:attachment":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media?parent=2023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/categories?post=2023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/tags?post=2023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}