0
votes

I want to suscribe/publish over MQTT using Google Cloud's IOT Core using a SIM modem. I have succesfully tried suscribing and publishing to a private broker with a set of functions of this SIM modem. Now I want to use Google Cloud as my broker.

Since communication must be done using SSL protocol, I have some questions:

1. Google provides the following information

enter image description here

What is the diference between the primary and backup certificate?


2. Modem needs the following parameters to set SSL before starting connection:

enter image description here

Is "ca.crt" file the primary/backup certificate provided by Google?

What is "myclient.crt"? Is it any key/file created from "ca.crt"?


3. Google Cloud's IOT Core has a list of CA where I can upload the certificates, but I am not sure which one should I upload in case it is necessary:

enter image description here

Need help since I am confused with these doubts.

1

1 Answers

0
votes

Hokay, so... I BELIEVE for 1, the minimal root cert contains a primary and backup certificate of trust. This is just like any other root certificate, where there are multiple certificates in the one file so that the certificate can be rotated without breaking deployments. In the standard Google root cert, for example there are dozens of certificates in the roots.pem file, and those certificates get rotated every few months. The minimal root cert is guaranteed for a much longer deployment (I forget how long at the moment, but it's quite long) because IoT devices aren't updated as often, and having to redeploy to the field is a pain. So the backup certificate is there in case the primary has issues, again, so that the root cert file doesn't break deployments.

2 - Where is that information from? Is that from Google? I haven't seen it (I've been off working on IoT Core for almost a year now though, so it's possible I just haven't seen it). I would ASSUME that the ca.cert is the Google root certificate, yes, but it may not be depending on where that information is from.

3 - In IoT Core, the place where you can upload CA files is specifically for device registration. It's an added authentication piece that requires that any devices registered with IoT Core must use SSL certificates signed by the specified CA. You'll note, that's per registry where that is specified. So you can have protected registries that only allow devices to be registered with that extra layer of authentication. It's not required by any means, it's just an addition if your system wants it.