|
| 1 | +#pragma once |
| 2 | + |
| 3 | +// The mqqt host and port |
| 4 | +const char* mqtt_host = "<mqtt_host>"; |
| 5 | +const uint16_t mqtt_port = <mqtt_port>; |
| 6 | + |
| 7 | +//The finger print to validate the mqtt server certificate. This is less secure and less convenient |
| 8 | +// than using certificate authorities |
| 9 | +// Command (3 lines...) to obtain the certificate finger print: |
| 10 | +// $>openssl s_client -connect <hostname>:<host port> < /dev/null 2>/dev/null | \ |
| 11 | +// openssl x509 -fingerprint -noout -in /dev/stdin \ |
| 12 | +// awk -F= '{print $2}' |
| 13 | +const char mqtt_fingerprint [] PROGMEM = "CA:EE:2B:ED:D3:23:A7:F1:8C:73:9E:9B:B7:D5:75:41:10:61:E4:05"; |
| 14 | + |
| 15 | +//Certificate Authorities. The best method to validate server certificates |
| 16 | +// Advised to retrieve root Certificate Authorities as they expire less often |
| 17 | +// than server certificates. Here after letsencrypt Certificate Authorities are listed. |
| 18 | +// They are available at https://letsencrypt.org/certificates/ |
| 19 | + |
| 20 | +// Root Certificate Authorities ISRG Root X1 |
| 21 | +// https://letsencrypt.org/certs/isrgrootx1.pem |
| 22 | +// Not Before: Jun 4 11:04:38 2015 GMT |
| 23 | +// Not After : Jun 4 11:04:38 2035 GMT |
| 24 | +const char cert_isrgrootx1_Authority [] PROGMEM = R"CERT( |
| 25 | +-----BEGIN CERTIFICATE----- |
| 26 | +MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw |
| 27 | +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh |
| 28 | +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4 |
| 29 | +WhcNMzUwNjA0MTEwNDM4WjBPMQswCQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJu |
| 30 | +ZXQgU2VjdXJpdHkgUmVzZWFyY2ggR3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBY |
| 31 | +MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK3oJHP0FDfzm54rVygc |
| 32 | +h77ct984kIxuPOZXoHj3dcKi/vVqbvYATyjb3miGbESTtrFj/RQSa78f0uoxmyF+ |
| 33 | +0TM8ukj13Xnfs7j/EvEhmkvBioZxaUpmZmyPfjxwv60pIgbz5MDmgK7iS4+3mX6U |
| 34 | +A5/TR5d8mUgjU+g4rk8Kb4Mu0UlXjIB0ttov0DiNewNwIRt18jA8+o+u3dpjq+sW |
| 35 | +T8KOEUt+zwvo/7V3LvSye0rgTBIlDHCNAymg4VMk7BPZ7hm/ELNKjD+Jo2FR3qyH |
| 36 | +B5T0Y3HsLuJvW5iB4YlcNHlsdu87kGJ55tukmi8mxdAQ4Q7e2RCOFvu396j3x+UC |
| 37 | +B5iPNgiV5+I3lg02dZ77DnKxHZu8A/lJBdiB3QW0KtZB6awBdpUKD9jf1b0SHzUv |
| 38 | +KBds0pjBqAlkd25HN7rOrFleaJ1/ctaJxQZBKT5ZPt0m9STJEadao0xAH0ahmbWn |
| 39 | +OlFuhjuefXKnEgV4We0+UXgVCwOPjdAvBbI+e0ocS3MFEvzG6uBQE3xDk3SzynTn |
| 40 | +jh8BCNAw1FtxNrQHusEwMFxIt4I7mKZ9YIqioymCzLq9gwQbooMDQaHWBfEbwrbw |
| 41 | +qHyGO0aoSCqI3Haadr8faqU9GY/rOPNk3sgrDQoo//fb4hVC1CLQJ13hef4Y53CI |
| 42 | +rU7m2Ys6xt0nUW7/vGT1M0NPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNV |
| 43 | +HRMBAf8EBTADAQH/MB0GA1UdDgQWBBR5tFnme7bl5AFzgAiIyBpY9umbbjANBgkq |
| 44 | +hkiG9w0BAQsFAAOCAgEAVR9YqbyyqFDQDLHYGmkgJykIrGF1XIpu+ILlaS/V9lZL |
| 45 | +ubhzEFnTIZd+50xx+7LSYK05qAvqFyFWhfFQDlnrzuBZ6brJFe+GnY+EgPbk6ZGQ |
| 46 | +3BebYhtF8GaV0nxvwuo77x/Py9auJ/GpsMiu/X1+mvoiBOv/2X/qkSsisRcOj/KK |
| 47 | +NFtY2PwByVS5uCbMiogziUwthDyC3+6WVwW6LLv3xLfHTjuCvjHIInNzktHCgKQ5 |
| 48 | +ORAzI4JMPJ+GslWYHb4phowim57iaztXOoJwTdwJx4nLCgdNbOhdjsnvzqvHu7Ur |
| 49 | +TkXWStAmzOVyyghqpZXjFaH3pO3JLF+l+/+sKAIuvtd7u+Nxe5AW0wdeRlN8NwdC |
| 50 | +jNPElpzVmbUq4JUagEiuTDkHzsxHpFKVK7q4+63SM1N95R1NbdWhscdCb+ZAJzVc |
| 51 | +oyi3B43njTOQ5yOf+1CceWxG1bQVs5ZufpsMljq4Ui0/1lvh+wjChP4kqKOJ2qxq |
| 52 | +4RgqsahDYVvTH9w7jXbyLeiNdd8XM2w9U/t7y0Ff/9yi0GE44Za4rF2LN9d11TPA |
| 53 | +mRGunUHBcnWEvgJBQl9nJEiU0Zsnvgc/ubhPgXRR4Xq37Z0j4r7g1SgEEzwxA57d |
| 54 | +emyPxgcYxn/eR44/KJ4EBs+lVDR3veyJm+kXQ99b21/+jh5Xos1AnX5iItreGCc= |
| 55 | +-----END CERTIFICATE----- |
| 56 | +)CERT"; |
| 57 | +
|
| 58 | +// Root Certificate Authorities ISRG Root X2 |
| 59 | +// https://letsencrypt.org/certs/isrg-root-x2.pem |
| 60 | +// Not Before: Sep 4 00:00:00 2020 GMT |
| 61 | +// Not After : Sep 17 16:00:00 2040 GMT |
| 62 | +const char cert_isrgrootx2_Authority [] PROGMEM = R"CERT( |
| 63 | +-----BEGIN CERTIFICATE----- |
| 64 | +MIICGzCCAaGgAwIBAgIQQdKd0XLq7qeAwSxs6S+HUjAKBggqhkjOPQQDAzBPMQsw |
| 65 | +CQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJuZXQgU2VjdXJpdHkgUmVzZWFyY2gg |
| 66 | +R3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBYMjAeFw0yMDA5MDQwMDAwMDBaFw00 |
| 67 | +MDA5MTcxNjAwMDBaME8xCzAJBgNVBAYTAlVTMSkwJwYDVQQKEyBJbnRlcm5ldCBT |
| 68 | +ZWN1cml0eSBSZXNlYXJjaCBHcm91cDEVMBMGA1UEAxMMSVNSRyBSb290IFgyMHYw |
| 69 | +EAYHKoZIzj0CAQYFK4EEACIDYgAEzZvVn4CDCuwJSvMWSj5cz3es3mcFDR0HttwW |
| 70 | ++1qLFNvicWDEukWVEYmO6gbf9yoWHKS5xcUy4APgHoIYOIvXRdgKam7mAHf7AlF9 |
| 71 | +ItgKbppbd9/w+kHsOdx1ymgHDB/qo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0T |
| 72 | +AQH/BAUwAwEB/zAdBgNVHQ4EFgQUfEKWrt5LSDv6kviejM9ti6lyN5UwCgYIKoZI |
| 73 | +zj0EAwMDaAAwZQIwe3lORlCEwkSHRhtFcP9Ymd70/aTSVaYgLXTWNLxBo1BfASdW |
| 74 | +tL4ndQavEi51mI38AjEAi/V3bNTIZargCyzuFJ0nN6T5U6VR5CmD1/iQMVtCnwr1 |
| 75 | +/q4AaOeMSQ+2b1tbFfLn |
| 76 | +-----END CERTIFICATE----- |
| 77 | +)CERT"; |
| 78 | +
|
| 79 | +// This one shouldn't be needed.... |
| 80 | +// Root Certificate Authorities Let’s Encrypt R3 |
| 81 | +// https://letsencrypt.org/certs/lets-encrypt-r3.pem |
| 82 | +// Not Before: Sep 4 00:00:00 2020 GMT |
| 83 | +// Not After : Sep 15 16:00:00 2025 GMT |
| 84 | +const char cert_letsEncryptR3_Authority [] PROGMEM = R"CERT( |
| 85 | +-----BEGIN CERTIFICATE----- |
| 86 | +MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw |
| 87 | +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh |
| 88 | +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw |
| 89 | +WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg |
| 90 | +RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| 91 | +AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP |
| 92 | +R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx |
| 93 | +sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm |
| 94 | +NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg |
| 95 | +Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG |
| 96 | +/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC |
| 97 | +AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB |
| 98 | +Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA |
| 99 | +FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw |
| 100 | +AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw |
| 101 | +Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB |
| 102 | +gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W |
| 103 | +PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl |
| 104 | +ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz |
| 105 | +CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm |
| 106 | +lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 |
| 107 | +avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 |
| 108 | +yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O |
| 109 | +yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids |
| 110 | +hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ |
| 111 | +HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv |
| 112 | +MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX |
| 113 | +nLRbwHOoq7hHwg== |
| 114 | +-----END CERTIFICATE----- |
| 115 | +)CERT"; |
| 116 | +
|
| 117 | +//The mqtt server may require client certificate for authentication. |
| 118 | +// The following are genereted and signed thanks to openssl. |
| 119 | +// The signing certificate is holded by the mqtt server. |
| 120 | +// Please see Client section in https://mosquitto.org/man/mosquitto-tls-7.html |
| 121 | +const char cert_client [] PROGMEM = R"CERT( |
| 122 | +-----BEGIN CERTIFICATE----- |
| 123 | +... ... ... ... ... |
| 124 | +-----END CERTIFICATE----- |
| 125 | +)CERT"; |
| 126 | + |
| 127 | +const char key_client [] PROGMEM = R"CERT( |
| 128 | +-----BEGIN RSA PRIVATE KEY----- |
| 129 | +... ... ... ... ... |
| 130 | +-----END RSA PRIVATE KEY----- |
| 131 | +)CERT"; |
| 132 | +// end of certificate chain |
| 133 | +//////////////////////////////////////////////////////////// |
0 commit comments