<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Securest way to use TLS in MQT</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/72951/securest-way-to-use-tls-in-mqt</link><description>So in the MQTT example the following function is used to write the CA certificate to the modem so a TLS connection can be setup. 
 
 In our code/TLS setup we want to use Client certificates aswell that is why we are using the following setup. 
 
 The</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Mon, 22 Mar 2021 10:22:58 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/72951/securest-way-to-use-tls-in-mqt" /><item><title>RE: Securest way to use TLS in MQT</title><link>https://devzone.nordicsemi.com/thread/301156?ContentTypeID=1</link><pubDate>Mon, 22 Mar 2021 10:22:58 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:47b533ca-5166-49e6-8284-ce8070af2e25</guid><dc:creator>&amp;#216;yvind</dc:creator><description>&lt;p&gt;Hello, my apologies for the late reply.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The alternative is to flash the certificates using pynrfjprog or the certificate manager in the lte link monitor. The code that writes credentials to the modem at boot can then be removed. As long as the sec tag used in the TLS connection matches the sec tag used when flashing the certificates it should be all good.&lt;/em&gt;&lt;/p&gt;
&lt;div&gt;&lt;em&gt;When we produce DKs and Thingy91s, certificates are provisioned in the factory using AT commands. So they&amp;#39;re stored securely in the modem only, and no private keys or anything in app flash/RAM&lt;/em&gt;&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
[quote user=""]Thats why you have a very large warning in the AWS_FOTA example saying that this is not best practice.[/quote]
&lt;p&gt;Yes, we encourage customers to follow warnings and notes in our documentation.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;KInd regards,&lt;br /&gt;Øyvind&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Securest way to use TLS in MQT</title><link>https://devzone.nordicsemi.com/thread/301152?ContentTypeID=1</link><pubDate>Mon, 22 Mar 2021 10:13:08 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:451b8599-afc4-427b-80dc-6763ef7a5af0</guid><dc:creator>Jupyter1336</dc:creator><description>&lt;p&gt;Thnx&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Securest way to use TLS in MQT</title><link>https://devzone.nordicsemi.com/thread/300604?ContentTypeID=1</link><pubDate>Thu, 18 Mar 2021 08:59:30 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3afabe71-1f87-437b-b9fc-000e63dfe517</guid><dc:creator>&amp;#216;yvind</dc:creator><description>&lt;p&gt;Hello,&amp;nbsp;&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve forwarded you questions to our MQTT experts. And will reply today or tomorrow.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Kind regards,&lt;br /&gt;Øyvind&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>