[Bug]: OPC UA UserNameIdentityToken sends length+password+nonce instead of the plain password when token security policy is None
Maintainers usually reply within 1 day
@splatch is already working on this.
Since Oct 2, 2026.
Assessment
This issue has not been assessed yet.
Description
What happened?
With PLC4J 1.0.0, the OPC UA driver cannot log in with username/password when the selected user token policy resolves to security policy None (and allow-insecure-credentials=true is set). The server answers ActivateSession with BadUserAccessDenied (0x801f0000). The same server and credentials work with 0.13.1.
The cause is in SecureChannel.getIdentityToken(...) (plc4j/drivers/opcua/src/main/java/org/apache/plc4x/java/opcua/context/SecureChannel.java, tag v1.0.0, unchanged on develop). For userTokenTypeUserName the method builds the RSA plaintext block length(4, little endian) + password + serverNonce (encodeablePassword). In the SecurityPolicy.NONE branch that block is sent as the token password instead of the password itself:
if (tokenSecurityPolicy == SecurityPolicy.NONE) {
// No encryption: the password is sent as-is and no algorithm is declared.
tokenPassword = encodeablePassword; // should be passwordBytes
encryptionAlgorithm = "";
}
OPC UA Part 4, 7.41.3 (UserNameIdentityToken): when encryptionAlgorithm is empty the password field carries the UTF-8 password itself; the length/nonce wrapping only applies to the encrypted form. A spec-conforming server therefore compares <4 length bytes> + password + nonce with the stored password and rejects the login. The code comment says "the password is sent as-is", so this looks like the wrong local variable.
Steps to reproduce
- OPC UA server that exposes a
Noneendpoint with aUserNameuser token policy without its ownsecurityPolicyUriand requires authentication (we used pythonasyncua1.1.5 with a user manager that compares username/password in plain text). - Connect with
opcua:tcp://host:port?discovery=false&security-policy=NONE&allow-insecure-credentials=true&username=u&password=pand read any node. - Connection fails with
PlcProtocolException: Server returned error BadUserAccessDenied (0x801f0000). On the server side the received password is 4 + len(password) + 32 bytes long.
Expected
The token password is the plain UTF-8 password when no encryption algorithm is declared, as in 0.13.1, and the login succeeds.
Suggested fix
In the SecurityPolicy.NONE branch use tokenPassword = passwordBytes; (and only build encodeablePassword for the encrypted branch).
Version
1.0.0 (Java, plc4j-driver-opcua), JDK 21.
- Dominant language
- Java
- Stars
- 1.8k
- Forks
- 505
- Avg merge
- 9h 45m
- Merged PRs (30d)
- 48
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/plc4x
-
Ethernet/IP java
Difficulty 1/5 Under an hour Newbie friendliness 90/100
apache/plc4x#2733 · 4 comments ·
Maintainers usually reply within 1 day
-
ADS java
Difficulty 3/5 1-2 days Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
java OPC-UA
Difficulty 4/5 3-5 days Newbie friendliness 42/100
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
apache/plc4x#2744 · 3 comments ·
Maintainers usually reply within 1 day
-
S7: reading a BOOL array fails with NullPointerException in PlcBOOL.of, tag returns INTERNAL_ERROROpenS7
Difficulty 4/5 3-5 days Newbie friendliness 58/100
apache/plc4x#2742 · 2 comments ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display languagePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
apache/rocketmq-dashboard#5561 ·
Maintainers usually reply within 3 days
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
HMCL-dev/HMCL#6934 · 1 comment ·
Maintainers usually reply within 1 day
-
test(setup): GitHub configuration tests fail when the temp path is long enough for YAML foldingOpenbug good first issue help wanted priority medium size S
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
martin-francois/symphony-trello#776 · 1 comment ·
Maintainers usually reply within 1 day
-
Console.printHexOpengood first issue kernel
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
JackFurton/who-would-build-a-kernel-in-java#33 · 2 comments ·
Maintainers usually reply within 1 day