Your OPC Classic server didn’t break.Windows stopped accepting the call.
Patch weekends are supposed to be boring. Somebody works down the list of computers, the updates go on, everything comes back up, and on Monday nobody mentions it.
Then one Monday the screens are flat. The software that collects your plant readings is running and configured exactly as it was on Friday, and no data is arriving. Nothing looks broken at either end, which is the worst kind of fault to be handed.
I have taken that call more than once, and the answer is nearly always the same. Your software did not change. The ground it stands on did, and I will be straight about what to do next, including an answer that has nothing to do with us.
Your OPC Classic server did not break, because Microsoft permanently raised the security floor under every Windows computer and older industrial software could no longer meet it.
You do not have to argue about whose fault it is, because your own computers keep a record of exactly what is being refused and why.
There are three honest answers to this, and what you are really choosing between them is whose calendar the machine moves on.
01 · What changed
Your server didn’t change. The floor under it moved.
If your plant data stopped arriving after a patch weekend, the software collecting it did not change. What changed is the ground it stands on, and that had nothing to do with you.
An OPC server is the software that gathers readings off plant equipment and hands them to everything else that needs them, and OPC Classic is the older version of that standard. When the server sits on one computer and the program that wants the readings sits on another, the two talk over something called DCOM, a Microsoft mechanism from about twenty-five years ago that lets a program on one Windows computer call a program on another. Microsoft found a security weakness in it, and the fix was to raise the minimum: every one of those calls now has to meet a stricter standard, and anything asking for less is refused. Your IT group knows that update as KB5004442.
Microsoft did that in stages, on purpose: available but switched off in June 2021, on by default in June 2022 with a setting to turn it back off, and since 14 March 2023 enforced on every supported version of Windows with nothing left to turn off. That last step is the one people remember, because it is when the workaround that had been buying them time stopped working.
None of this was aimed at industrial software. The weakness was in that Microsoft mechanism itself, and older industrial software just happens to be one of its loudest users, running on the computers that are hardest to change. When the two ends cannot both meet the stricter standard, the call is refused, and from a control room that looks exactly like the OPC server breaking. Your OPC server is doing exactly what it always did, and it is the platform underneath it that stopped accepting the call.
02 · The argument
Both sides of this are right, and the computers can settle it
The next thing that usually happens is an argument, and it is worth heading off, because both sides of it are right.
Your security people see a known weakness with a published fix, deliberately left off a computer that sits in the path of live plant data, and an auditor writes that up as a finding. Your operations people see something that has worked for years, and breaking it to satisfy a patch policy means losing data on a system somebody has to answer for. Neither of them set the deadline, because the date Microsoft stops supporting that version of Windows arrives on a schedule set somewhere else.
You can also take the heat out of it, because this is knowable rather than arguable. Windows writes a record at both ends every time one of these calls is refused. You do not have to argue about whose fault it is, because your own computers name the machine, the program, and whether the fix is yours or a vendor’s.
03 · The three answers
Three honest answers, and the trade-offs for each one
So what do you actually do? There is no version of this where you give nothing up, so the useful question is which trade you make on purpose. Here are the three options that are available, including one that needs nothing from us.
The first is to leave the computer alone and write down why. You keep it off the patch list, you put other protections around it, and you set a date to review the decision. That is scheduling rather than a fix and it gets harder to defend every year, but inside a defined window it is a legitimate answer. The trade is a written, dated exception you carry through every audit until the window closes.
The second is to update the software. The cleanest ending is replacing the old server with something modern, and many servers can meet you halfway by handing out the same readings both ways at once, in the old format and in a modern one, which can be OPC UA, so new programs use the modern connection and the old ones retire as they come up for replacement instead of moving in one weekend. However this might not be an option for older software that has not been updated and does not support the new updates. And when updating is the path you take, we can help move that data where it needs to go.
The third is to keep the old server and wrap it, and this is the one we build: we can both wrap it, and move it where it needs to go. You leave the server where it is and put a small piece of software on the same computer, which talks to the old server locally, in a conversation that never leaves the machine, and hands the readings onward in the modern format. Nothing is crossing between two computers any more, so there is nothing left for them to negotiate. The trade is one more thing to acquire, deploy and run, and it does not patch the Windows computer, make an unsupported version of Windows supported, or stop the support clock.
I am not arguing for ripping anything out. Most of these servers are doing their job accurately and have been for years. What I am arguing for is that you choose one of the three instead of arriving at one by default. You will make one of these three trades either way, so make the one that leaves the machine on your calendar instead of somebody else’s.
04 · How we help
How can we help?
The second and third answers are ones we support, so let me be precise rather than sell you the promise. What it buys you is narrow enough to name first: the data keeps arriving, and the Windows computer underneath it moves on your plan instead of on a support date.
RetroBridge is that wrapper. It runs on the computer that already hosts the old server, talks to it locally, and hands the readings onward in the modern format. The question of what two computers will agree to drops out, because nothing is crossing between them, not because anything about the old mechanism got fixed. Every reading keeps its own name, type and structure on the way through, along with the quality flag and the time stamp the equipment gave it. I insist on that because a wrapper that quietly improves the data it is wrapping is worse than useless in a plant.
I should state the limits just as plainly. This does not patch the Windows machine, it does not make an unsupported operating system supported, and it does not take the end-of-support date off anybody’s calendar. What it changes is what has to cross the network and what a modern client has to speak. It also separates moving the programs from moving the computer, so the two no longer have to happen on the same day. Whether the result satisfies a given audit is a question for your assessor to answer, and it is not something a product gets to declare for itself.
Other older protocols connect through the same runtime, Modbus, DNP3, HART and ROC+ among them, and everything comes out the other side in the modern format. The architecture underneath it is the subject of Cutting Through the Noise. Nothing in the field is replaced, re-pointed or restarted, so your equipment carries on doing its job and its data finally gets off the floor.
And if you take the second answer instead, we can still help move that data where it needs to go. Our Flowgate gateway carries readings onward over a connection your plant opens outward, buffered while a link is down, whether they came out of a wrapper or out of updated software.
05 · Sources
Sources
06 · Take with you
The three things to take with you
Your OPC server is doing exactly what it always did, and it is the platform underneath it that stopped accepting the call. You do not have to argue about whose fault it is, because your own computers name the machine, the program, and whether the fix is yours or a vendor’s. And you will make one of these three trades either way, so make the one that leaves the machine on your calendar instead of somebody else’s.
If you want one next step this week, make one list: the computers that still hand readings to a program on another computer, the date Windows support ends for each of them, and the programs that would have to move if one of them moved, named by owner. That list is your schedule.
If you would rather describe one of those links and hear what we would do with it, write to us at info@h2innovations.ca.