<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TLS not working without certificate provisioning</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/79055/tls-not-working-without-certificate-provisioning</link><description>Hi, On our new type of 9160 based boards, we failed to create a connection with TLS socket. After creating a TLS socket Without peer verification, and trying to connect with that socket, we always got error 95 (operation not supported). Trying to locate</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Tue, 31 Aug 2021 09:00:46 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/79055/tls-not-working-without-certificate-provisioning" /><item><title>RE: TLS not working without certificate provisioning</title><link>https://devzone.nordicsemi.com/thread/327362?ContentTypeID=1</link><pubDate>Tue, 31 Aug 2021 09:00:46 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:f8bc7998-8ab6-4934-9789-5091977838bd</guid><dc:creator>Albrecht Markus Schellenberger</dc:creator><description>&lt;p&gt;Hello again,&lt;/p&gt;
&lt;p&gt;nRF91 does not support TLS without a certificate. At minimum, a PSK or Root CA is needed for opening the TLS connection.&lt;/p&gt;
&lt;p&gt;Peer verification is an optional method, where client and server certificates are verified. Even when a TLS connection is opened without peer verification there is a need to have either correct PSK or Root CA in the device.&lt;/p&gt;
&lt;p&gt;Probably one of the sample applications has stored a Root CA to the device and after that TLS connections have successfully opened.&lt;/p&gt;
&lt;p&gt;In summary: There must be a certificate installed in the device before opening a TLS connection with or without of peer verification.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Markus&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: TLS not working without certificate provisioning</title><link>https://devzone.nordicsemi.com/thread/327234?ContentTypeID=1</link><pubDate>Mon, 30 Aug 2021 13:20:42 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:31e4a537-f693-40e5-b85d-2659445186b5</guid><dc:creator>Albrecht Markus Schellenberger</dc:creator><description>&lt;p lang="en-GB"&gt;Hello,&lt;/p&gt;
&lt;p lang="en-GB"&gt;thanks a lot for the detailed explanation of the problem you are facing. I have to check this with our modem team. I will come back to you as soon as possible.&lt;/p&gt;
&lt;p lang="en-GB"&gt;Regards,&lt;/p&gt;
&lt;p lang="en-GB"&gt;Markus&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: TLS not working without certificate provisioning</title><link>https://devzone.nordicsemi.com/thread/327053?ContentTypeID=1</link><pubDate>Sat, 28 Aug 2021 02:35:18 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:d138e6d7-4592-44f7-b060-5a4c8a4d9b76</guid><dc:creator>royalbee</dc:creator><description>&lt;p&gt;One more thing:&lt;br /&gt;&lt;br /&gt;After fixing the TLS connection problem&amp;nbsp;by running https_client,&amp;nbsp;we could not reproduce the problem on the same device (that was fixed), even after erasing the flash, and re-flushing the modem&amp;#39;s fw, TLS sockets worked fine without peer verification.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>