# MQTT SSL/TLS connection

**URL:** https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156
**Category:** General
**Created:** [1 October 2019 14:43 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156 "2019-10-01T14:43:15Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [1 October 2019 14:43 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/1 "2019-10-01T14:43:15Z")

</div>

Hi All  
I'm trying to configure an MQTT in to use SSL/TLS security.

I have created  
ca, client, and server crt files  
ca, client, and server key files.

We are using a Mosqitto MQTT broker, in which I have changed the conf file to use the above files, and restarted it (service mode)

In the Node Red MQTT in I have configured the tls-config to use  
client.crt, client.key, and ca.crt files, and given the passphrase that was provided when creating the files. Port is set to 8883

The node transitions from not connected (red circle) to connecting (yellow circle), but doesn't connect.

Without TLS, we connect instantly.

I've either configured something wrong, or I've missed something.  
I'm new to TLS...

Any ideas from the info provided?

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [1 October 2019 15:01 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/2 "2019-10-01T15:01:19Z")

</div>

Hello!

I am looking at this very setup in front of me, I have Node-RED talking to mosquitto and am currently bashing my head against the Paho Java Client!

I'd suggest we break the debugging into two stages:

1. Server (mosquitto)
2. Client (Node-RED)

Are you able to paste your mosquitto.conf here (removing any private data of course)?

If you're on a unix/linux environment, could you try issuing:  
`openssl s_client -connect <server>:8883 -prexit`  
and see what it comes out with, it should print the servers certificate and a negotiated TLS protocol, if that fails you definitely have a config problem in your server.

If you have client auth enabled in mosquitto, then you'll also need to specify the cert to openssl, but I'm going to assume you're using only server-auth for now.

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [1 October 2019 15:08 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/3 "2019-10-01T15:08:49Z")

</div>

Hi Andreas  
Conf file attached as a txt file, couldn't upload a \*.conf file  
[mosquitto.txt](https://discourse.nodered.org/uploads/short-url/kEqx9wittsmY9PaMFMVUWgNIEH8.txt) (38.2 KB)

I haven't edited that much.  
Port for Extra Listeners  
cafile, certfile and keyfile in  
Certificate based SSL/TLS support  
section below Extra Listeners.

I'm on a Win7 PC, but may need to duplicate on a Win 10 PC in the future.

Thanks for your time

Chris

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [1 October 2019 15:24 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/4 "2019-10-01T15:24:16Z")

</div>

Well the mosquitto.conf looks good, onwards!

How did you generate the certs and keys? Can you open the files and see a first line of  
`-----BEGIN RSA PRIVATE KEY-----`  
or  
`-----BEGIN CERTIFICATE-----`  
if not they're not in PEM format and need to be converted.

Did you specify a password for the broker key? I don't think mosquitto supports password enabled keys so you'd need to strip that out (easy if you have openssl: `openssl rsa -in server.key -out server-nopass.key` and then change the keyfile to be server-nopass.key in the conf.)

cheers,  
Andreas

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [1 October 2019 15:26 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/5 "2019-10-01T15:26:11Z")

</div>

I should probably ask for completeness:

- You _did_ check the Node-RED and mosquitto logs for errors didn't you‽

\*\*\*\*\* EDIT \*\*\*\*\* (since I'm a new discourse user I can't reply any more)  
Add

```auto
log_type all
log_dest file C:\mosquitto\mosquitto.log

```

to your mosquitto config to enable logging, then restart

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [1 October 2019 15:37 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/6 "2019-10-01T15:37:06Z")

</div>

Hi Andreas

certs and keys generated by following

> **[mosquitto-tls man page](https://mosquitto.org/man/mosquitto-tls-7.html)**
>
> Name
> mosquitto-tls — Configure SSL/TLS support for Mosquitto
> 
> 
> Description
> mosquitto provides SSL support for encrypted
> network connections and authentication. This manual describes how
> to creat

steps executed in Windows PowerShell, if that's relevant.

All files have a BEGIN \*\*\*\* line

As for checking logs, I'm afraid I haven't.  
I'll have a look.

The mosquitto/log directory is empty  
and .node-red doesn't have a log directory

I may need to configure them to produce log files?

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [1 October 2019 15:50 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/7 "2019-10-01T15:50:15Z")

</div>

ceejay has bumped my user level 🙂 I can reply again!

> [@andreas-ibm](#):
>
> Add
> 
> ```auto
> log_type all
> log_dest file C:\mosquitto\mosquitto.log
> 
> ```
> 
> to your mosquitto config to enable logging, then restart

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [2 October 2019 08:23 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/8 "2019-10-02T08:23:47Z")

</div>

Morning Andreas  
I've configured the logging for Mosquitto.  
An initial log file attached.  
[mosquittoI.txt](https://discourse.nodered.org/uploads/short-url/gqVdv3hDAJLCm5vJXYKFiFns2Nj.txt) (19.5 KB)

Looking at it, it looks like I may need to focus on my 'client' device, a BLE Gateway from Minew.

Thanks for your help so far, much appreciated

Chris

---

<div class="post-metadata">

### Author: ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)
#### Post date: [2 October 2019 09:08 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/9 "2019-10-02T09:08:51Z")

</div>

I have seen this (likely) exact issue on the forum about a month ago. Went through a lot of things but never managed to solve it. Let me link it.

> [@Scenario with MQTT nodes - No message received on debug node](https://discourse.nodered.org/t/scenario-with-mqtt-nodes-no-message-received-on-debug-node/15160):
>
> Hi all, I've build a NODE-RED flow with the following nodes: 1 node type INJECT 1 node type MQTT\_OUT connected to SCP Cloud Platform IoT with TLS v1.2 1 none type MQTT\_IN connected to SCP Cloud Platform IoT with TLS v1.2 1 node type DEBUG The node INJECT sends a message with body JSON to node MQTT\_OUT wich sends a MQTTS message to SCP Cloud Cloud Platform IoT. I see the message on IoT service cockpit. The node MQTT\_IN should be in listening on topic measures/# and send the message to nod…

While it says solved, the original poster never got the answer to their problem.

---

<div class="post-metadata">

### Author: ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)
#### Post date: [2 October 2019 09:14 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/10 "2019-10-02T09:14:21Z")

</div>

Since you are on windows, should you not use double-backslashes in the paths for certificates etc?

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [2 October 2019 09:15 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/11 "2019-10-02T09:15:34Z")

</div>

forward slashes work pretty much everywhere in Windows and have done for years.

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [2 October 2019 09:17 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/12 "2019-10-02T09:17:08Z")

</div>

Morning Chris,

The Gateway looks fine (using unsecured port 1883), but the logging is being particularly helpful in saying

```auto
1570002289: New connection from 127.0.0.1 on port 8883.
1570002289: Socket error on client <unknown>, disconnecting.

```

when N-R connects 😢

but since you used openssl to generate your certificates, you can use openssl to test mosquitto, can you issue:

```auto
openssl s_client -connect localhost:8883 -CAfile C:\mosquitto\certs\ca.crt -prexit

```

please?

It'll attempt to create a TLS connection to mosquitto (it'll fail to create an mqtt connection, but we don't mind that), then it'll print out what it achieved.  
e.g.:

```auto
CONNECTED(00000005)
depth=1 <CA Subject>
verify return:1
depth=0 <endpoint subject>
verify return:1
139641003102656:error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure:../ssl/record/rec_layer_s3.c:1528:SSL alert number 40
---
Certificate chain
 0 s:<endpoint subject>
   i:<CA subject>
 1 s:<CA subject>
   i:<CA subject>
---
Server certificate
-----BEGIN CERTIFICATE-----
<PEM Cert>
-----END CERTIFICATE-----
subject=<endpoint subject>

issuer=<CA subject>

---
No client certificate CA names sent
Client Certificate Types: RSA sign, DSA sign, ECDSA sign
Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:gost2012_512+md_gost12_512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:gost2012_256+md_gost12_256:gost2001+md_gost94:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
Shared Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
---
SSL handshake has read 2403 bytes and written 646 bytes
Verification: OK
---
New, TLSv1.2, Cipher is AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol : TLSv1.2
    Cipher : AES256-GCM-SHA384
    Session-ID:
    Session-ID-ctx:
    Master-Key: 1395B4B2EC84BEAF0EFEFE52F787C507F8625296C06D587A328B1A7A1BC1718C84A338A8082235DA0441E7E859114CC8
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1570007277
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
---

```

It'll print it twice since we passed "-prexit" (print status on exit), but without the -prexit it won't terminate the connection itself (avoiding the hardship of typing C-d)

The main thing to note is that it established an `SSL-Session` using a recognised protocol (in my case, `Protocol : TLSv1.2`). If openssl fails to do that then mosquitto is misconfigured. If it succeeds, the Node-RED is misconfigured and we'll move on!

cheers,  
Andreas

---

<div class="post-metadata">

### Author: ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)
#### Post date: [2 October 2019 09:17 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/13 "2019-10-02T09:17:19Z")

</div>

OK, I just saw that the config file attached had single backslashes in the paths and thought that could cause a problem, I might be wrong though

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [2 October 2019 09:19 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/14 "2019-10-02T09:19:14Z")

</div>

Single backslashes seem to be the norm in the other windows-examples I've seen online, but if the openssl test fails, it's probably worth a try...

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [2 October 2019 09:30 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/15 "2019-10-02T09:30:41Z")

</div>

Use forward slashes in commands, it saves a lot of hassle. If you do use backslashes on the command line, you **have** to double them up and put the whole thing in quotes. That is, of course, because a backslash is an escape character for all command line terminals.

There are a few older Windows applications that can't cope with forward slashes but all command-line apps should support them.

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [2 October 2019 09:47 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/16 "2019-10-02T09:47:28Z")

</div>

Andreas  
Here's the result from the openssl command requested

[connection.txt](https://discourse.nodered.org/uploads/short-url/nDXICOVQUMapLYn2IATsrdEyQnN.txt) (13.6 KB)

Chris

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [2 October 2019 10:07 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/17 "2019-10-02T10:07:52Z")

</div>

Lovely, your mosquitto connection is working just fine.

On to Node-RED!

Let's get some logs!

If you're using pm2 to run node-red, then simply do a `pm2 logs` command to retrieve the logs.  
Otherwise if you're following [https://nodered.org/docs/getting-started/windows](https://nodered.org/docs/getting-started/windows) to run on windows, you can see the suggestion:  
`If you want to access to the logs when running this way, you should amend the node-red.cmd file to redirect std and error outputs to a file (creating an alternative startup file would be better so that it isn’t overwritten on updates).`  
Thankfully windows has caught up with the rest of the sane world, so that redirect is simple. Add `> C:\node-red.log 2>&1` to the end of the two red.js lines in node-red.cmd and restart node-red. Or just kill the started task and run node-red manually in a terminal.

I'd suggest disabling the `Use legacy MQTT 3.1 support` in the MQTT config as it might be holding you back (i don't think it's getting that far, but best to be safe)

In your TLS configuration, are you:

1. Using `Use key and certificates from local files`? (I am)
2. Specifying a passphrase (I'm not)
3. Using `Verify server certificate` (I'm being lazy and am not)

If the answer to 1 is no, then try to enable it and specify the paths to the certificate files directly (since you're running on the server itself the certificates are already on there..)

If the answer to 2. is yes, double-check it's the right one:

```auto
openssl rsa -in C:\path\to\node-red.key -noout -text -passin <passphrase>

```

If you've enabled 3 then disable it for now to see if that's the bit that's failing.

fingers crossed we'll get there!  
cheers,  
Andreas

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [2 October 2019 10:47 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/18 "2019-10-02T10:47:47Z")

</div>

Hi Andreas  
Made the changes to node-red.cmd - still no log files though.  
Disabled legacy MQTT 3.1 support

TLS Config

1. Wasn't using local files, changed it so now we are
2. Specifying a passphrase - as provided one when generating certs
3. Disabled Verify server certs

Updated, and deployed.

All connected, instantly.

I do believe you have cracked it.

Thank You so much for all your time and efforts  
Chris

---

<div class="post-metadata">

### Author: ![andreas-ibm](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andreas-ibm/32/12733_2.png) [@andreas-ibm](https://discourse.nodered.org/u/andreas-ibm)
#### Post date: [2 October 2019 11:36 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/19 "2019-10-02T11:36:07Z")

</div>

Yay!

I'll have an experiment with those settings here, see if there's a bug somewhere!

cheers,  
Andreas

---

<div class="post-metadata">

### Author: ![ChrisO](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@ChrisO](https://discourse.nodered.org/u/ChrisO)
#### Post date: [2 October 2019 14:06 UTC](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156/20 "2019-10-02T14:06:53Z")

</div>

FYI

Just been through the process of adding an extra listener to the mosquitto.conf at port 8884, and we're back to connecting (yellow circle)

Remove the extra listener, and we connect ok again

Thanks

Chris

[Next page](https://discourse.nodered.org/t/mqtt-ssl-tls-connection/16156.md?page=2)
