Back to blog

Commissioning OPC UA in KEPServerEX: A Field Checklist

A practical commissioning sequence for KEPServerEX OPC UA connections: define data ownership, test tags locally, configure endpoint and certificate trust, limit access, then verify failure recovery...

KEPServerEX, now described by PTC as Kepware Server, can expose industrial data through OPC UA. Commissioning that interface means more than finding an endpoint. Engineers must prove the right tags, trust relationships, access rules, and recovery behavior for the specific installation.

Start With the Data Path

Draw the actual path from controller to driver, server, and consuming application. Record the controller address, protocol, tag source, update expectations, and owner. OPC UA is the interface presented to the client; it does not make every underlying PLC connection identical.

Define which values are measurements, statuses, commands, or configuration settings. Apply extra scrutiny to writable tags. A dashboard that only needs observations should not gain write access merely because the server offers it.

Verify Controller Data Before OPC UA

Check communications between the controller and the relevant KEPServerEX driver first. Compare a small set of live values against an approved engineering reference. Include a changing measurement, a discrete status, and a known bad-quality condition where practical.

If the source value is wrong, publishing it via OPC UA only spreads the mistake. Document scaling, engineering units, tag naming, and whether a stale reading can be mistaken for a healthy process value. For wider network fault isolation, see our industrial network troubleshooting guide.

Commission the Endpoint and Trust

Identify the server endpoint URL and the security choices supported by the installed version. Match the client policy to the site's approved security baseline. Establish certificate trust deliberately on both sides, verify identities, and record certificate expiry and renewal ownership.

Do not disable security to make a production connection work. A temporary lab exception must not silently become the operating design. PTC provides an OPC UA client and server connection guide covering supported Kepware Server releases. Check the documentation matching the deployed build.

Keep Permissions Narrow

Use accounts and permissions appropriate to the client role. Where the installation supports it, separate monitoring from control access. Review every namespace and tag exposed to the consumer. A broad subscription can increase traffic and reveal data that the application does not need.

Place the server and its clients within an approved OT architecture. Firewall rules should specify the actual endpoints and direction of communication. The site’s communication and networking catalog illustrates the hardware categories used in such paths; catalog parts are not a substitute for a network design.

Prove the Fault and Restore Paths

Disconnect the controller or a test client under controlled conditions. Confirm the application reports bad quality or loss of communication clearly. Reconnect and verify that values recover without an unexplained configuration change. Confirm whether operators can distinguish old data from current data.

Record the endpoint, server version, driver version, certificate owners, allowed clients, tag list, and baseline test results. Repeat these checks after a driver upgrade, certificate replacement, controller change, or firewall edit. A connection that works today is only useful if the maintenance team can reproduce and diagnose it later.

Leave a comment

Please note, comments need to be approved before they are published.