<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/94936/how-to-set-aws-iot-certificates-in-runtime</link><description>Hi team, 
 
 I am building AWS IoT client based on NRF52833 + Ethernet Controller. 
 I have done connecting and subscribing/publishing to AWS IoT broker successfully, and now I am trying to find a way for provisioning each device properly. 
 In AWS IoT</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Tue, 20 Dec 2022 11:03:55 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/94936/how-to-set-aws-iot-certificates-in-runtime" /><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401483?ContentTypeID=1</link><pubDate>Tue, 20 Dec 2022 11:03:55 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:475d1a84-d681-4de9-9aad-383e9777a6d4</guid><dc:creator>choehyunho</dc:creator><description>&lt;p&gt;Oh, thanks.&lt;/p&gt;
&lt;p&gt;I added the following line in my prj.conf&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;CONFIG_AWS_IOT_CERTIFICATES_FILE=&amp;quot;aws-certs.h&amp;quot;
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;checked the following line in my CMakeLists.txt&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;zephyr_include_directories_ifdef(CONFIG_AWS_IOT_PROVISION_CERTIFICATES certs)
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;and put my own aws-certs.h in cert folder.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;It is because my firmware will include claim certificates by default for initial connection, and load/save from NVS if needed.&lt;/p&gt;
&lt;p&gt;Basically the combined approach you suggested.&lt;/p&gt;
&lt;p&gt;Now I can use all my features without nasty modification. Thank you!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401409?ContentTypeID=1</link><pubDate>Tue, 20 Dec 2022 06:28:17 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:623ca8e0-bec4-4fcc-a18f-043aea7fdbfc</guid><dc:creator>Susheel Nuguru</dc:creator><description>&lt;p&gt;My Colleague who have some experience in this thinks it can be done. Suggestion from him is below .&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Okay, so the library can actually handle the loading of the credentials for you. As you have already found out, it does that by writing the contents of some buffers it assumes exists in aws-certs.h (you can change the name of the file with a Kconfig option). So the user can define those buffers in a way that makes the application capable of changing their contents. The content of the buffers are loaded each time the application calls aws_iot_connect()&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;The other option is what I thought you had to do, which is to load the credentials yourself (in the application), before you call aws_iot_connect(). This approach gives more flexibility, but you will have to do all the credential handling yourself&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401336?ContentTypeID=1</link><pubDate>Mon, 19 Dec 2022 16:38:19 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:7ca298ab-9c99-4a4a-8a4c-4b15c17f7780</guid><dc:creator>choehyunho</dc:creator><description>&lt;p&gt;It may be more practical, not just for sample, if runtime certificate loading is possible.&lt;/p&gt;
&lt;p&gt;Hope some knit &amp;amp; clean way provided in the future NCS release.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401170?ContentTypeID=1</link><pubDate>Mon, 19 Dec 2022 06:31:11 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:0547957a-5213-42de-a178-1c09247fbdd5</guid><dc:creator>Susheel Nuguru</dc:creator><description>[quote user="choehyunho"]Is there any better way? Or can you suggest how I can access these variable without modifying NCS codes?[/quote]
&lt;p&gt;Not that I know of, but I can ask my colleague just to be sure.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401135?ContentTypeID=1</link><pubDate>Sat, 17 Dec 2022 11:51:35 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:9a88b17c-3d68-4e66-abee-ec99db1eaf7e</guid><dc:creator>choehyunho</dc:creator><description>&lt;p&gt;For the certificate change, I made some quick dirty workaround on aws-certs.h&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="c_cpp"&gt;//static const unsigned char ca_certificate[] = {
unsigned char ca_certificate[2048] = {
...
//static const unsigned char private_key[] = {
unsigned char private_key[2048] = {
...
//static const unsigned char device_certificate[] = {
unsigned char device_certificate[2048] = {
...&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;With this workaround, I can access these variables in my application code.&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="c_cpp"&gt;extern unsigned char ca_certificate[2048];
extern unsigned char private_key[2048];
extern unsigned char device_certificate[2048];
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;Is there any better way? Or can you suggest how I can access these variable without modifying NCS codes?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to set AWS IoT certificates in runtime</title><link>https://devzone.nordicsemi.com/thread/401028?ContentTypeID=1</link><pubDate>Fri, 16 Dec 2022 11:13:33 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4094f155-ab4c-46a3-b746-7bdd9ee6d36a</guid><dc:creator>Susheel Nuguru</dc:creator><description>[quote user=""]And, Is there any plan for supporting AWS IoT Fleet Provisioning (Online Provisioning) in future nRFConnect SDK?[/quote]
&lt;p&gt;WE do not talk about roadmaps and timelines here in devzone. Please ask your RSM about this. I have requested an RSM from your place to reach you out soon regarding this.&lt;/p&gt;
[quote user=""]How can I change device certificates for AWS IoT client in runtime?[/quote]
&lt;p&gt;It does not look like we support this. For now it looks like static certificates only. I will let you know if the developers have anymore insight than this.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>