Configure purge time/output path/REST channel authentication
- Last UpdatedSep 25, 2026
- 1 minute read
- PI System
- PI Connector for UFL 1.3.2.139
- Connectors
This section describes the global configuration settings available for PI Connector for UFL. You can use the GlobalConfig.ps1 PowerShell script to view or modify settings that control processed file retention, output file storage, REST authentication, and REST certificate validation
-
Purge time
By default, PI Connector for UFL deletes processed ZIP files that are more than 10 days old..
-
Output path
By default, PI Connector for UFL stores the processed data files in %PROGRAMDATA%\OSIsoft\PI Connectors\UFL.ConnectorHost\Output folder.
-
REST channel authentication
By default, the REST Server endpoint uses Basic authentication.
-
REST certificate validation
By default, PI Connector for UFL validates the REST Server certificate before establishing communication through the REST client channel.
You can change the above settings by running the GlobalConfig.ps1 PowerShell script located in %PIHOME64%\Connectors\UFL\PowerShellScripts folder.
Note: Run the GlobalConfig.ps1 in PowerShell to view the syntax for displaying and modifying the current settings
Using gMSAs with the REST Server
If the REST Server endpoint has Basic authentication enabled (default), any caller, including GlobalConfig.ps1, must supply a literal username and password. Group Managed Service Accounts (gMSAs) cannot be used for this credential, since their password is not retrievable.
To resolve:
-
Using a standard account with a known password, run the script once to disable Basic authentication: GlobalConfig.ps1 -ChangeConfig -RestBasicAuthentication 0 -UserName <account> -Password <password>
-
After you disable Basic authentication, the admin API uses Windows Integrated Authentication (NTLM or Kerberos). Processes running under a gMSA can then authenticate automatically through Kerberos. Use Invoke-RestMethod -UseDefaultCredentials to call the admin API because GlobalConfig.ps1 does not support passwordless authentication.