Overview
After migrating a Siemens WinCC project from V7.3 to V8.0, many engineers encounter a missing OPC UA entry under the Server Type selector of the legacy OPC channel. The dropdown only lists DA (OPC Data Access), and the OPC UA connection that existed in the V7.3 export no longer appears in the WinCC Explorer.
This is not a defect. Siemens restructured OPC UA access in WinCC V7.4 and made it mandatory in V8.0: OPC UA is no longer a server type on the legacy OPC channel, it is now a dedicated communication driver called OPC UA WinCC Channel. To restore the connection, install the WinCCOPUAClient component, add the OPC UA WinCC Channel to the project, and remap the tag addresses to the UA namespace format.
Why OPC UA Disappeared From the Legacy OPC Channel
In WinCC V7.3 the OPC channel (channel name OPC) exposed three server types: DA, A&E (Alarms & Events), and UA (Unified Architecture). The UA server type was an embedded wrapper around the DA mapping defined in OPCUAServerWrapper.ini and opcua_config.xml on the V7.3 station.
Beginning with WinCC V7.4 and consolidated in V8.0, Siemens removed the UA server type from the legacy OPC channel and delivered OPC UA as a stand-alone channel. The reasoning documented by Siemens is that:
- OPC UA uses session-based, encrypted transport (TCP port 4840 by default) that is incompatible with the COM/DCOM plumbing of the legacy OPC channel.
- The UA address space (browse paths, NodeIds, namespaces) cannot be represented by the legacy DA item syntax
\server\itempath. - Certificate management, security policies (None, Basic128Rsa15, Basic256, Basic256Sha256) and authentication modes are now controlled by the OPC UA WinCC Channel rather than by WinCC's OPC settings dialog.
For an existing V7.3 project migrated with the WinCC Migrator, the migrated configuration keeps the legacy OPC channel intact but leaves the OPC UA sub-connection invalid. The channel is silently skipped at runtime, which is why the connection disappears from the explorer without an error message.
Prerequisites
| Component | Version / Detail |
|---|---|
| WinCC Runtime / Configuration | V8.0 or V8.1 (Update 1+ recommended) |
| Operating system | Windows Server 2016 Standard/Datacenter (64-bit) or Windows Server 2019 |
| OPC UA WinCC Channel setup |
WinCC_OPC_UA_Channel.exe located on the WinCC V8.0 installation media under \Install\WinCC_OPC_UA_Channel
|
| OPC UA client runtime |
WinCCOPUAClient (installed together with the channel) |
| OPC UA server endpoint URL |
opc.tcp://<server>:4840 (default) — confirm with the server vendor |
| User rights | Local Administrator on the WinCC station and on the OPC UA server |
| Backup | Full export of the V7.3 project (Project > Export) plus a copy of the project folder |
Step-by-Step: Restoring the OPC UA Connection in WinCC V8.0
Step 1 — Install the OPC UA WinCC Channel
- Insert the WinCC V8.0 installation DVD or mount the ISO.
- Navigate to
\Install\WinCC_OPC_UA_Channeland launchSetup.exeas Administrator. - Accept the license agreement and select Install WinCC OPC UA Channel.
- The installer registers the COM service
WinCCOPCUAService, the channel DLLWCCOpcUaChn.dll, and the client proxyWinCCOPUAClient.exe. - Reboot the station when prompted — the OPC UA stack requires a clean Windows certificate store.
Step 2 — Add the OPC UA WinCC Channel to the Project
- Open the migrated project in WinCC Explorer V8.0.
- Right-click Tag Management and select Add New Driver.
- Choose OPC UA WinCC Channel from the driver list (display name: OPC UA WinCC Channel).
- A new channel node OPC UA WinCC Channel appears under Tag Management.
- Open the channel, right-click Connection Parameters and select New Connection.
Step 3 — Configure the Connection to the OPC UA Server
The connection dialog contains the parameters shown below. Values shown are the defaults shipped by Siemens; adjust to match your UA server.
| Parameter | Default / Example | Description |
|---|---|---|
| Connection name | OPCUA_PlantFloor |
Unique symbolic name within the project |
| Server URL | opc.tcp://192.168.10.50:4840 |
Discovery URL of the OPC UA server |
| Endpoint URL | Auto (first compatible endpoint) | Select a specific endpoint if the server exposes multiple |
| Security Policy | Basic256Sha256 |
None, Basic128Rsa15, Basic256, Basic256Sha256 |
| Message Security Mode | SignAndEncrypt |
None / Sign / SignAndEncrypt |
| Authentication Mode |
Anonymous or UserName
|
Match the server's UserTokenPolicy |
| User name / password | — | Required when Authentication Mode = UserName |
| Session timeout (s) | 60000 | Range 1000–600000 |
| Subscription publishing interval (ms) | 500 | Range 100–60000 |
| Sampling interval (ms) | 250 | Range 50–60000 |
| Queue size | 10 | KeepLast / KeepBoth behaviour |
Click Test Connection. A successful test opens a session, reads the server's namespaces, and populates the channel's browse tree.
Step 4 — Remap V7.3 OPC UA Tag Addresses
V7.3 OPC UA tags used the DA-style item path \<ServerName>\<ItemPath>. The new OPC UA WinCC Channel requires a structured address of the form:
NS=<NamespaceIndex>;S=<StringNodeId>
// Example
NS=4;S=Channel1.Device1.Temperature.Value
or, for numeric NodeIds:
NS=2;I=10234
The recommended workflow to migrate hundreds of tags is:
- In the V7.3 project, export the tag list to CSV (Tag Management > Export Tags).
- Open the CSV in Microsoft Excel and create a column NewAddress.
- Use
FIND,SUBSTITUTE, andCONCATENATEto rewrite the legacy address into the UA form. Example formula:
=CONCATENATE("NS=4;S=", SUBSTITUTE(SUBSTITUTE(B2,"\\","")," ","_"))
- Save the file as Unicode Text (.txt) with tab separators — WinCC's import expects this exact format.
- In WinCC V8.0, open the OPC UA WinCC Channel connection and choose Import Tags.
- Map the NewAddress column to the Address field and complete the import wizard.
2 (default OPC UA namespace) or the index assigned by the server. Always browse the server with the OPC UA Tag Browser in WinCC Explorer to capture the exact NodeId syntax before scripting the Excel transformation.Step 5 — Update Internal Tags and Cross-References
Tag names in WinCC are project-wide and remain unchanged, so any image, script, alarm, or archive configuration that references the tag by name continues to work. However, all references to the tag address field in faceplate internals, C scripts, or VB scripts must be updated. Run a global search across the project for the string OPC_ (the default V7.3 OPC channel prefix) and confirm no script still addresses the old channel.
Step 6 — Configure Runtime Behavior and Certificate Trust
- Open the WinCC Explorer and navigate to Computer > Properties > Startup.
- Add OPC UA WinCC Channel to the startup list. The service
WinCCOPCUAServiceis registered as a Windows service and starts automatically, but the runtime add-in must be enabled. - The first time WinCC connects to the UA server, Windows displays the Certificate Trust dialog. Click Trust to move the server certificate from Untrusted Certificates to Trusted Certificates in the local certificate store
Cert:\LocalMachine\UA Applications. - If the UA server uses a self-signed certificate, copy the server's
.derfile to the WinCC station and import it viaWinCC Certificate Manager(Start > Siemens Automation > WinCC Certificate Manager).
Verifying the Migration
- Activate the WinCC runtime project.
- Open WinCC Channel Diagnosis (
C:\Program Files (x86)\Siemens\Automation\WinCC\bin\CCChannelDiag.exe). - Confirm the OPC UA WinCC Channel shows Connected with a green status indicator.
- Open an internal tag reference (e.g. an I/O field) bound to a migrated tag and verify the value updates in real time.
- Run SIMATIC WinCC Connectivity Station test page and browse the OPC UA server — values returned must match the WinCC internal tag values.
OPC UA Server Configuration in WinCC Professional (TIA Portal) RT
When WinCC is used inside a TIA Portal project with an HMI panel (Comfort, Unified, or RT Professional) acting as the OPC UA server, the server is enabled and parameterised under the runtime settings of the HMI device, not from WinCC Explorer. The relevant configuration file is OPCUASERVERWINCCPRO.XML located in the runtime directory. Key parameters in this XML include:
| Element | Default | Meaning |
|---|---|---|
| <ServerUrl> | opc.tcp://<host>:4840 |
Endpoint URL exposed by the RT runtime |
| <SecurityPolicy> | None |
None, Basic128Rsa15, Basic256, Basic256Sha256 |
| <Authentication> | Anonymous |
Anonymous / Username / Certificate |
| <MaxSessions> | 100 | Maximum concurrent UA client sessions |
| <MaxSubscriptionsPerSession> | 50 | Subscription count per session |
The official Siemens documentation portal describes the procedure for editing this file, generating self-signed server certificates, and adding trusted client certificates. The runtime settings UI in TIA Portal mirrors the same options for non-Expert users.
Tag Lifecycle Notes
Per the Siemens knowledge base ID 109818894, an active OPC UA connection is not required to delete imported WinCC OPC UA tags. To remove a tag:
- Open Tag Management > OPC UA WinCC Channel > Connection > Tags.
- Select the tag(s) and press Del.
- If the tag is referenced in a screen, an alarm, or an archive, the references must be cleared first — the dialog will list them.
Bulk deletion is supported through the same Import/Export wizard used for migration: export a tag list, remove the rows in Excel, and re-import as a delta.
Troubleshooting Matrix
| Symptom | Likely Root Cause | Resolution |
|---|---|---|
| Server Type dropdown shows only DA | Legacy OPC channel only — UA was moved out in V7.4+ | Install WinCC_OPC_UA_Channel and add the new channel |
| Channel installed but driver missing in Add New Driver list | Setup run without administrator privileges | Re-run setup as Administrator and reboot |
| Test Connection returns BadCertificateUntrusted | Server certificate not in trusted store | Open WinCC Certificate Manager and trust the server certificate |
| Test Connection returns BadSecurityPolicy | Endpoint security policy mismatch | Match the Security Policy in the channel with an endpoint the server actually exposes |
| Tags show Quality = Bad after activation | Wrong NamespaceIndex or NodeId syntax | Use the OPC UA Tag Browser in WinCC Explorer to capture the exact NodeId |
| Subscription values update slowly | Publishing / sampling intervals too high | Lower Publishing interval to 200 ms and Sampling interval to 100 ms |
| Migration error "Unknown server type OPCUA" | Old V7.3 OPC channel still in migrated project | Delete the legacy OPC channel; the new UA channel carries the migrated configuration |
| High CPU on WinCC station after activation | KeepBoth queue size set excessively high | Set Queue size to 10 and Queue behaviour to KeepLast |
Field-Proven Caveats
- The legacy OPC channel and the new OPC UA WinCC Channel can coexist in the same project. Run a parallel test before deleting the DA connection.
- OPC UA subscriptions consume one item per tag; for projects with more than 5 000 tags, raise MaxSubscriptionsPerSession on the server side to avoid Bad_TooManySubscriptions.
- On Windows Server 2019, the Windows firewall blocks inbound TCP 4840 by default. Add an inbound rule for
WinCCOPCUAService.exebefore commissioning. - Domain-joined stations: store UA client certificates in
Cert:\LocalMachine\UA Applicationsfor service accounts and inCert:\CurrentUser\UA Applicationsfor interactive users. Mixing the two stores causes intermittent trust failures. - For time-critical control loops (cycle < 100 ms), prefer DA over UA — UA's session and subscription overhead adds 30–80 ms latency even on a LAN.
FAQ
Why does my migrated WinCC v8.0 OPC channel only show the DA server type?
Because OPC UA was removed from the legacy OPC channel in WinCC V7.4 and consolidated into the dedicated OPC UA WinCC Channel. Install the WinCC_OPC_UA_Channel setup and add the new channel to your project — the legacy OPC channel will only show DA, A&E, and HDA server types.
Do I need the WinCCOPUAClient installed for the UA connection to appear?
Yes. WinCCOPUAClient is the runtime proxy that connects the new OPC UA WinCC Channel to a remote UA server. Without it, the channel is visible in the configuration but cannot open a session at runtime.
Can I keep my V7.3 OPC tag addresses unchanged?
No. V7.3 OPC UA tags used the legacy \server\itempath DA syntax. In V8.0 the OPC UA WinCC Channel requires the NS=<index>;S=<NodeId> or NS=<index>;I=<numeric> format. Export the tag list to CSV, transform the address column in Excel, and re-import.
How do I trust a self-signed OPC UA server certificate in WinCC V8.0?
Open the WinCC Certificate Manager from the Siemens Automation program group, switch to Trusted Certificates, and import the server's .der certificate. Alternatively, accept the trust prompt that appears the first time the channel attempts a connection.
Where do I configure the WinCC OPC UA server when using TIA Portal RT Professional?
Server parameters are edited in the runtime settings of the HMI device and persisted in OPCUASERVERWINCCPRO.XML. The configuration covers endpoint URL, security policy, authentication mode, and maximum session / subscription counts.