Secure communication with SSL/TLS
Use SSL/TLS to encrypt communication between the client and broker.
SSL/TLS provides these options:
IMPORTANT:
Ensure that the certificate can be accessed by Windows Local Service.
- CA signed server certificateis used for one-way authentication. When the broker presents its digital certificate to the client, the client will establish a secure connection with the broker without the certificate validation.
- CA certificate onlyis used for one-way authentication. You need to validate the CA certificate from the broker.To use CA certificate only
- OnMQTT Client, enableSSL/TLS, and then selectCA certificate only.
- Select
, and then select a PEM certificate. If the certificate is in PFX format, enter its password if required to convert it to the PEM format.
- Self signed certificatesis used for a two-way authentication. You need to validate the CA certificate from the broker and provide the client certificate for broker authentication.To use self signed certificates
- OnMQTT Client, enableSSL/TLS, and then selectSelf signed certificates.
- Select
under Incoming Certificate from MQTT Broker, and then select a PEM certificate. If the certificate is not in PEM format, enter its password to convert it to the PEM format. - Select
under Outgoing Certificate to MQTT Broker, select a PFX certificate, and then enter its password.If the certificate is not in PFX format,- InChange Certificate, selectConvert From Other Format.
- InSelect Certificate, do one of the following:
- Use the outgoing certificate from the OPC UA interface.
- Add a public key and a private key, and then enter the password of the private key if it is required.
- SelectOK.
- (optional) SelectCreate CSRto obtain a new certificate from a CA as the Outgoing Certificate.
- SelectExtract Public Key, and then move the public key to the broker for validation.
To use the outgoing certificate from the OPC UA interface- OnMQTT Client, enableSSL/TLS, and then selectSelf signed certificates.
- UnderIncoming Certificate from MQTT Broker, select
, and then select a PEM certificate. If the certificate is not in PEM format, enter its password to convert it to the PEM format. - UnderOutgoing Certificate to MQTT Broker, select
. - InChange Certificate, selectConvert From Other Format.
- InSelect Certificate, select theUse the outgoing certificate from the OPC UA interfacecheckbox.
- SelectOK.
- (optional) SelectCreate CSRto obtain a new certificate from a CA as the Outgoing Certificate.
- SelectExtract Public Key, and then move the public key to the broker for validation.
Provide Feedback