Version 52.3 by Mengting Qiu on 2025/07/29 15:22

Hide last authors
Xiaoling 23.7 1 **Table of Contents: **
2
Xiaoling 1.1 3 {{toc/}}
4
5
Xiaoling 23.7 6
7
8
9
10
11
12
13
Xiaoling 23.6 14 = 1. Log in to the platform and find IoT core =
Xiaoling 1.1 15
Xiaoling 23.2 16
Xiaoling 23.6 17 = 2. Create your own test policy =
Xiaoling 1.1 18
Xiaoling 23.6 19 == 2.1 First click the policy on the left, enter the page and click Create policy ==
Xiaoling 1.1 20
Xiaoling 23.7 21
Xiaoling 23.3 22 [[image:image-20240528172927-2.png||height="377" width="931"]]
Xiaoling 1.1 23
24
Xiaoling 23.6 25 == 2.2 After filling in a policy name for testing, the policy will be displayed on the page ==
Xiaoling 23.2 26
27
Xiaoling 1.2 28 a. Fill in any name
Xiaoling 1.1 29
30
Bei Jinggeng 35.1 31 b. Fill in * to Policy action and Policy resource (* stands for all)
Xiaoling 1.1 32
Bei Jinggeng 35.1 33 [[image:image-20250103152135-2.png||height="777" width="1544"]]
Bei Jinggeng 22.1 34
Bei Jinggeng 35.1 35
Xiaoling 1.2 36 c. After clicking to enter the policy configuration page, follow the clicking sequence below to go to the json configuration interface, and then fill in the following fields in the "statement" keyword:
Xiaoling 1.1 37
38
Bei Jinggeng 35.1 39 **{
40 "Version": "2012-10-17",
41 "Statement": [
42 {
43 "Effect": "Allow",
44 "Action": "iot:*",
45 "Resource": "*"
46 }
47 ]
48 }**
Xiaoling 24.6 49
Xiaoling 1.1 50
51
Bei Jinggeng 35.1 52 [[image:image-20250103151957-1.png||height="529" width="935"]]
Xiaoling 1.2 53
54 d. Create this policy
55
56
Bei Jinggeng 22.1 57 = 3. Create a Things =
Xiaoling 1.2 58
Bei Jinggeng 22.1 59 == 3.1 Create a single Things ==
Xiaoling 1.2 60
Xiaoling 23.2 61
Xiaoling 23.7 62 (% style="color:blue" %)**1. Select Create Things**
Xiaoling 1.2 63
Bei Jinggeng 22.1 64 [[image:image-20240528173244-5.png||height="329" width="932"]]
Xiaoling 1.2 65
Bei Jinggeng 22.1 66 [[image:image-20240528173500-6.png||height="484" width="928"]]
Xiaoling 1.2 67
68
Xiaoling 23.7 69 (% style="color:blue" %)**2. Fill in the name of the control item you want to create in the thing name column**
Xiaoling 1.2 70
71 Use the default for other parameters
72
73 Then click Next.
74
Bei Jinggeng 22.1 75 [[image:image-20240528173754-7.png||height="712" width="781"]]
Xiaoling 1.2 76
77
Xiaoling 23.7 78 (% style="color:blue" %)**3. Choose to automatically generate a new certificate**
Bei Jinggeng 22.1 79
Xiaoling 1.2 80 Then click Next
81
Bei Jinggeng 22.1 82 [[image:image-20240528173829-8.png||height="547" width="782"]]
Xiaoling 1.2 83
84
Xiaoling 23.7 85 (% style="color:blue" %)**4. The next step is to choose a strategy**
Bei Jinggeng 22.1 86
Xiaoling 1.2 87 Here you can choose a policy we created in the first step
88
Bei Jinggeng 22.1 89 [[image:image-20240528173851-9.png||height="580" width="785"]]
Xiaoling 1.2 90
91
Xiaoling 23.7 92 (% style="color:blue" %)**5. When you click to create things, the certificate download page will pop up**
Bei Jinggeng 22.1 93
Xiaoling 1.2 94
Xiaoling 24.7 95 **This certificate is very important.** After creating the device, you must download the certificate of the device so that our NB device can connect normally.
Xiaoling 24.6 96
Xiaoling 1.2 97 Please download all the following certificates and put them in a folder.
98
Bei Jinggeng 22.1 99 [[image:image-20240528173926-10.png]]
Xiaoling 1.2 100
101
Xiaoling 23.7 102 (% style="color:blue" %)**6. You can see the things you just created in the things**
Xiaoling 1.2 103
Bei Jinggeng 22.1 104 [[image:image-20240528173951-11.png||height="381" width="1089"]]
Xiaoling 1.2 105
106
Xiaoling 23.7 107 = 4. Connect to AWS using Dragino-NB device =
Xiaoling 1.2 108
kai 28.1 109
Xiaoling 29.1 110 (% id="cke_bm_37736S" style="color:red; display:none" %)** **(% style="color:red" %)**Note: **(%%)In order to avoid problems with certificate writing, you need to set the serial port assistant to automatically add a newline character when sending commands, if there is no such newline character, the certificate written will be invalid.(Using the serial port assistant as an example)
kai 28.1 111
Mengting Qiu 31.1 112 [[image:image-20240822090554-1.png||height="501" width="656"]]
kai 28.1 113
Xiaoling 29.1 114
Xiaoling 24.6 115 == 4.1 For -NB /-NS model ==
Xiaoling 1.2 116
Mengting Qiu 36.1 117 === 4.1.1 Upgrade the firmware to configure TLS firmware to set the certificate ===
Xiaoling 23.2 118
Bei Jinggeng 24.2 119
Bei Jinggeng 23.1 120 User can change device firmware to::
Xiaoling 1.2 121
Bei Jinggeng 23.1 122 * Update with new features.
Bei Jinggeng 22.1 123
Bei Jinggeng 23.1 124 * Fix bugs.
Bei Jinggeng 22.1 125
Bei Jinggeng 24.2 126 Firmware and changelog can be downloaded from : **[[Set up TLS certificate - Dropbox>>https://www.dropbox.com/scl/fo/1ykfsesmr3702tj3kp663/AOOyH1GiVEOGR41gASuiDk0?rlkey=1q7a1b5yvjgt87d16w8tt0cum&st=vdy765ut&dl=0||data-sider-select-id="830d1b64-cb24-48b3-91e4-49da5c3f0783"]]**
Bei Jinggeng 23.1 127
128 Methods to Update Firmware:
129
130 * (Recommended way) OTA firmware update via BLE: [[**Instruction**>>url:http://wiki.dragino.com/xwiki/bin/view/Main/BLE_Firmware_Update_NB_Sensors_BC660K-GL/]].
131
132 * Update through UART TTL interface : **[[Instruction>>url:http://wiki.dragino.com/xwiki/bin/view/Main/UART_Access_for_NB_ST_BC660K-GL/#H4.2UpdateFirmware28Assumethedevicealreadyhaveabootloader29]]**.
133
Xiaoling 24.6 134 === 4.1.2 Configure certificate ===
Xiaoling 23.2 135
Bei Jinggeng 22.1 136
Xiaoling 1.2 137 After upgrade the firmware, the serial port displays as follows:
138
Mengting Qiu 38.1 139 [[image:image-20250306113602-1.png||height="401" width="856"]]
Xiaoling 1.2 140
Xiaoling 23.2 141
Xiaoling 24.6 142 ==== 4.1.2.1  Configure CA certificate ====
Xiaoling 1.2 143
Xiaoling 23.2 144
Xiaoling 1.2 145 Please input the certificate in PEM format for the user.
146
147 Use the AT command AT+CACERT as follows:
148
149 AT+CACERT=~-~-~-~--BEGIN CERTIFICATE~-~-~-~--
150
151 MIIDQTCCAimgAwIBAgITBmyfz5m/jAo54vB4ikPmljZbyjANBgkqhkiG9w0BAQsF
152
153 ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
154
155 b24gUm9vdCBDQSAxMB4XDTE1MDUyNjAwMDAwMFoXDTM4MDExNzAwMDAwMFowOTEL
156
157 MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEZMBcGA1UEAxMQQW1hem9uIFJv
158
159 b3QgQ0EgMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALJ4gHHKeNXj
160
161 ca9HgFB0fW7Y14h29Jlo91ghYPl0hAEvrAIthtOgQ3pOsqTQNroBvo3bSMgHFzZM
162
163 9O6II8c+6zf1tRn4SWiw3te5djgdYZ6k/oI2peVKVuRF4fn9tBb6dNqcmzU5L/qw
164
165 IFAGbHrQgLKm+a/sRxmPUDgH3KKHOVj4utWp+UhnMJbulHheb4mjUcAwhmahRWa6
166
167 VOujw5H5SNz/0egwLX0tdHA114gk957EWW67c4cX8jJGKLhD+rcdqsq08p8kDi1L
168
169 93FcXmn/6pUCyziKrlA4b9v7LWIbxcceVOF34GfID5yHI9Y/QCB/IIDEgEw+OyQm
170
171 jgSubJrIqg0CAwEAAaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC
172
173 AYYwHQYDVR0OBBYEFIQYzIU07LwMlJQuCFmcx7IQTgoIMA0GCSqGSIb3DQEBCwUA
174
175 A4IBAQCY8jdaQZChGsV2USggNiMOruYou6r4lK5IpDB/G/wkjUu0yKGX9rbxenDI
176
177 U5PMCCjjmCXPI6T53iHTfIUJrU6adTrCC2qJeHZERxhlbI1Bjjt/msv0tadQ1wUs
178
179 N+gDS63pYaACbvXy8MWy7Vu33PqUXHeeE6V/Uq2V8viTO96LXFvKWlJbYK8U90vv
180
181 o/ufQJVtMVT8QtPHRh8jrdkPSHCa2XV4cdFyQzR1bldZwgJcJmApzyMZFo6IQ6XU
182
183 5MsI+yMRQ+hDKXJioaldXgjUkK642M4UwtBV8ob2xJNDd2ZhwLnoQdeXeGADbkpy
184
185 rqXRfboQnoZsG4q5WTP468SQvvG5
186
187 ~-~-~-~--END CERTIFICATE~-~-~-~--}
188
Xiaoling 23.4 189 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
Xiaoling 1.2 190
Bei Jinggeng 22.1 191 [[image:image-20240528174408-14.png]]
Xiaoling 1.2 192
193
194 After successful execution, as shown in the following figure.
195
Mengting Qiu 41.1 196 [[image:image-20250306113849-2.png||height="742" width="456"]]
Xiaoling 1.2 197
Xiaoling 23.4 198 Display (% style="color:blue" %)**"Successfully configured CA certificate."**(%%) If the configuration is successful, otherwise it is considered configuration failure.
Xiaoling 1.2 199
Xiaoling 23.2 200
Xiaoling 24.6 201 ==== 4.1.2.2 Configure client certificate ====
Xiaoling 1.2 202
Xiaoling 23.2 203
Xiaoling 1.2 204 Use the AT command AT+CLICERT as follows:
205
206 AT+CLICERT=~-~-~-~--BEGIN CERTIFICATE~-~-~-~--
207
208 MIIDWTCCAkGgAwIBAgIUYSpJUzfb4NTa76JJxd2th0fZA8swDQYJKoZIhvcNAQEL
209
210 BQAwTTFLMEkGA1UECwxCQW1hem9uIFdlYiBTZXJ2aWNlcyBPPUFtYXpvbi5jb20g
211
212 SW5jLiBMPVNlYXR0bGUgU1Q9V2FzaGluZ3RvbiBDPVVTMB4XDTI0MDUyNDA4MDI0
213
214 NVoXDTQ5MTIzMTIzNTk1OVowHjEcMBoGA1UEAwwTQVdTIElvVCBDZXJ0aWZpY2F0
215
216 ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMTdc1GQLVBohAeCJD6n
217
218 6WTFAFrygTch90a5wUr2bhlVuDxvEhEKNcmu5vOCo5agmfLWb2VCxgezgvQOBYQ8
219
220 1oTqXJNdl4tS0DICfqb/ogVHWGHRao67XyhbPNBS0j/nCPTIIk6+/NBeYPOjaG+p
221
222 utfXE7SGIEcc3RevkYkUJx6y+WH7MLjj1mufuXBVWIL1RrfrIRPw6auVk7dhS5rU
223
224 NvYcJa7Qd6gpAh1DzPj7ZECrv7fEIIBDEsSYOy6ToWtzqGIVcIAHBDfORB0Hcm+N
225
226 7wG3KDf61P4aWkLlkP5pRUaUIQdVblxginmx2K3n8t/WP7QcfITa191rjEVVBXmk
227
228 ROsCAwEAAaNgMF4wHwYDVR0jBBgwFoAUs8Caohh1ZGP8kjSn3rtxJiJJ9IswHQYD
229
230 VR0OBBYEFCjwGwqD7FG9UCNm3wjFQX4HixzfMAwGA1UdEwEB/wQCMAAwDgYDVR0P
231
232 AQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4IBAQBgqI49a4PBQZYrFM63TX3EHgdd
233
234 N6Pj7AytjO+SrKNMCSo/OtIvhDTxOocr1vKrux1Tw5qmrllrIXLtlGtbmln5DS6a
235
236 DTCLrjwcIFIabLxpx5DPY1WSMYvL04SW7d4Y+3SxOFNRotDSiomr8eIIac0d3HE2
237
238 B5b0SnWZgWbrhjNUgvwo8l8tA9DOGIr2MeQ5kPjudOOiYSR3HC0v+jviBMV6VX8M
239
240 LHVH3CRshHDKBGpV1NZ1RAm9EY/oRGtSiMsyjRh6hegC0vehwVxaC4w9qG0ASkzz
241
242 42OOGfNqhYnYDiKTEIkazaoAFpTKDejWBaL7W5VpthUkQOl67IyX+ohuUKTo
243
244 ~-~-~-~--END CERTIFICATE~-~-~-~--}
245
Xiaoling 23.4 246 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
Xiaoling 1.2 247
Bei Jinggeng 22.1 248 [[image:image-20240528174630-16.png||height="553" width="747"]]
Xiaoling 1.2 249
Xiaoling 23.4 250 Display (% style="color:blue" %)**"Successfully configured client certificate."**(%%) Configuration successful, otherwise configuration failed.
Xiaoling 1.2 251
Xiaoling 23.2 252
Xiaoling 24.6 253 ==== 4.1.2.3 Configure client private key ====
Xiaoling 1.2 254
Xiaoling 23.2 255
Xiaoling 1.2 256 Use the AT command AT+CLIKEY, as shown below
257
258 AT+CLIKEY=~-~-~-~--BEGIN RSA PRIVATE KEY~-~-~-~--
259
260 MIIEpAIBAAKCAQEAxN1zUZAtUGiEB4IkPqfpZMUAWvKBNyH3RrnBSvZuGVW4PG8S
261
262 EQo1ya7m84KjlqCZ8tZvZULGB7OC9A4FhDzWhOpck12Xi1LQMgJ+pv+iBUdYYdFq
263
264 jrtfKFs80FLSP+cI9MgiTr780F5g86Nob6m619cTtIYgRxzdF6+RiRQnHrL5Yfsw
265
266 uOPWa5+5cFVYgvVGt+shE/Dpq5WTt2FLmtQ29hwlrtB3qCkCHUPM+PtkQKu/t8Qg
267
268 gEMSxJg7LpOha3OoYhVwgAcEN85EHQdyb43vAbcoN/rU/hpaQuWQ/mlFRpQhB1Vu
269
270 XGCKebHYrefy39Y/tBx8hNrX3WuMRVUFeaRE6wIDAQABAoIBAFhAOcjvjBDGuaEw
271
272 CxV3al49HfqnSZuwg0xWSztSm2qKDcwxsnSnEhO2b1vsTW9h0YGV9Vv8gg/Dvkmv
273
274 23M7XqM4+IUraJsRZbl1etdcM4KQSCOZoF4Zyv+pXuq4pf31kQNCkHaikWzLUkUG
275
276 FPQxr0vA49mCYwfd/ZL3ppM/0IWmxRwloV1Gb9q8iDBUcJGSDokZnT7diUxzzOcd
277
278 +UJ6xUhFq1v46Y7vO+73XROLv34JEBC0bIw2ErL6+AbzhHwb2mkuSccG9Ks37g3Z
279
280 dyyjjj8hm1wvHWepuWqEssaiS3HD5zAsI0v85xS8RwNj3zLfd8o1WC666n3CO+ij
281
282 VdRmR4kCgYEA+/sEFxpfaRomqcLwJebZcZH06U1RfJFfnbH2/Q6fANf8zNxwWs9A
283
284 O+jyk/CLhHYRIk6VIOMQmWwEYgJ2eAHfw2Diwj4/0eqkGu+yZOS6KTCewxSV73vc
285
286 SvACramJy4y6yEgDN5onwR1XqfVMfA0LzTcSupHR/xvrpf/gCsNFPxUCgYEAyAFd
287
288 nMUhJFSq3pOogxA43aJSkA8YuDS3jpBkKQ6vx81APpIMabQauOxFDt488TZGP3Yy
289
290 lhpa/lfFIgu2K7CgV4dUp+JtJJoZ/F+ExxUUzdqB4zxzWywAcc3RebfwP6qASwFT
291
292 G3mXYci4tgNWR+k5CSsuLXDk/OT5uo5GeGAEc/8CgYEAk6V8uxDP8STKnNRFpN/E
293
294 b6CHciDE64m/DgbWY2cq0fK9BUjxaLRhvfj8EqVzCrWnyoNjLHcAJfW+B7PLuPvY
295
296 IoJlvE1/Vb/4UnQ7ApVnY3VCwaoRRNc9uIcz+pAJ1sRqOarAf9cLDkPkNwktvM5k
297
298 KOXpSnrhIms4w/bPT18l9xUCgYBsAMDKbXEuK0JyGw5+Z/4tQQCQpnZU0rLkm3ha
299
300 64FkxaORplBprEZZ4cyQ8NW78/EPSAadI/JLMp5TejuPcDvFyGCgoBcMEuNBc1tC
301
302 HlIzr3FAgl5Qt3wt+FTMA9YKq0nINxjn10s2FKwaLccj4f9YwiaXh0VAg22PnlDT
303
304 pBYDhQKBgQCMwyKXJ4zYiDRdvLvgKzeuKaU4KNQItHE4KORPfkecjPoENt4bKxDw
305
306 2EdNFQLIoqBHL1s+/8+SzhCI31V7pkTs1AqCxDExJS7+8Z5NQFQIo/jooUo0N80E
307
308 y3ZZS6OLOXXscEqhMogf1grfbabXM9OkgTIq43cPQHtMGQiFAtIJkg==
309
310 ~-~-~-~--END RSA PRIVATE KEY~-~-~-~--}
311
Xiaoling 23.4 312 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
Xiaoling 1.2 313
Bei Jinggeng 22.1 314 [[image:image-20240528174702-17.png]]
Xiaoling 1.2 315
Xiaoling 23.7 316 Display(% style="color:blue" %)** "Successfully configured client private key."**(%%) If the configuration is successful, otherwise it is considered configuration failure.
Xiaoling 1.2 317
Xiaoling 23.2 318
Xiaoling 24.6 319 ==== 4.1.2.4 Re-upgrade the firmware ====
Xiaoling 1.2 320
321
Mengting Qiu 32.1 322 After completing the certificate configuration, Burn the [[bootloader>>https://www.dropbox.com/sh/u0uzvvnn58yrie4/AAAvvF_KRveNgmDejzp23ziLa/NB-IoT/Bootloader?dl=0&subfolder_nav_tracking=1]] firmware first, then re-burn the original working [[firmware>>https://www.dropbox.com/sh/u0uzvvnn58yrie4/AACREHllkTe0rATD4ZOqddyga/NB-IoT?dl=0]].
Xiaoling 23.2 323
324
Mengting Qiu 52.3 325 ==== 4.1.2.5 Clear Certificates by Overwriting (For -NB/-NS Modules) ====
Mengting Qiu 48.2 326
327
Mengting Qiu 49.2 328 The -NB/-NS modules (BC660K) do not support clearing certificates via AT commands or firmware updates.
Mengting Qiu 48.2 329
Mengting Qiu 52.3 330 To effectively remove existing certificates, users may overwrite them with dummy data.
Mengting Qiu 49.8 331
Mengting Qiu 49.14 332
Mengting Qiu 49.2 333 To effectively "clear" existing certificates, users may overwrite them with arbitrary data by following these steps:
334
Mengting Qiu 49.9 335 **Scenario A:** Clearing Existing Certificates
Mengting Qiu 49.2 336
Mengting Qiu 49.14 337 1.Flash the certificate-provisioning firmware: **[[Set up TLS certificate - Dropbox>>https://www.dropbox.com/scl/fo/1ykfsesmr3702tj3kp663/AOOyH1GiVEOGR41gASuiDk0?rlkey=1q7a1b5yvjgt87d16w8tt0cum&st=vdy765ut&dl=0||data-sider-select-id="830d1b64-cb24-48b3-91e4-49da5c3f0783"]]**
Mengting Qiu 49.9 338
Mengting Qiu 49.13 339 2. Use the standard AT commands (AT+CACERT, AT+CLICERT, AT+CLIKEY) to write non-certificate data (e.g., random strings like 123456).
Mengting Qiu 49.4 340 Example:
Mengting Qiu 49.2 341
Mengting Qiu 49.5 342 AT+CACERT=123456}
Mengting Qiu 49.2 343
Mengting Qiu 49.5 344 AT+CLICERT=123456}
Mengting Qiu 49.3 345
Mengting Qiu 49.5 346 AT+CLIKEY=123456}
347
Mengting Qiu 49.15 348
Mengting Qiu 49.14 349
Mengting Qiu 49.15 350 2. Check for success responses after each command:
351
Mengting Qiu 51.2 352 [[image:1753772253801-330.png||height="495" width="620"]]
Mengting Qiu 50.1 353
Mengting Qiu 52.1 354 * If you get "Failure", retry or check module connectivity.
Mengting Qiu 50.1 355
Mengting Qiu 49.16 356 3. Later, when you have real certificates, overwrite the dummy data with actual certificates.
Mengting Qiu 49.15 357
Mengting Qiu 49.17 358
Bei Jinggeng 24.2 359 == 4.2  For -CB /-CS model ==
Xiaoling 1.2 360
Mengting Qiu 36.1 361 === 4.2.1 Upgrade the firmware to configure TLS firmware to set the certificate ===
Bei Jinggeng 24.2 362
363
364 User can change device firmware to::
365
366 * Update with new features.
367
368 * Fix bugs.
369
370 Firmware and changelog can be downloaded from : **[[Set up TLS certificate - Dropbox>>https://www.dropbox.com/scl/fo/mk9u5ux3cfo94ke0s67ik/ADOIOdwIQfCO2WUZt0MxXyU?rlkey=7o6uaywrebbnsvuj4r0r694x6&st=smrmjj7t&dl=0||data-sider-select-id="830d1b64-cb24-48b3-91e4-49da5c3f0783"]]**
371
372 Methods to Update Firmware:
373
374 * Update through UART TTL interface : **[[Instruction>>url:http://wiki.dragino.com/xwiki/bin/view/Main/UART_Access_for_NB_ST_BC660K-GL/#H4.2UpdateFirmware28Assumethedevicealreadyhaveabootloader29]]**.
375
Xiaoling 24.5 376 === 4.2.2 Configure certificate ===
Bei Jinggeng 24.2 377
378
379 After upgrade the firmware, the serial port displays as follows:
380
Mengting Qiu 43.1 381 [[image:image-20250306114107-2.png||height="371" width="744"]]
Bei Jinggeng 24.2 382
383
Xiaoling 24.5 384 ==== 4.2.2.1 Configure CA certificate ====
Bei Jinggeng 24.2 385
Bei Jinggeng 25.1 386 (% style="color:red" %)**Note:You should select one of the certificates.Either CA1 or CA3 can be used**
Bei Jinggeng 24.2 387
388 Please input the certificate in PEM format for the user.
389
390 Use the AT command AT+CACERT as follows:
391
392 AT+CACERT=~-~-~-~--BEGIN CERTIFICATE~-~-~-~--
393
394 MIIDQTCCAimgAwIBAgITBmyfz5m/jAo54vB4ikPmljZbyjANBgkqhkiG9w0BAQsF
395
396 ADA5MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRkwFwYDVQQDExBBbWF6
397
398 b24gUm9vdCBDQSAxMB4XDTE1MDUyNjAwMDAwMFoXDTM4MDExNzAwMDAwMFowOTEL
399
400 MAkGA1UEBhMCVVMxDzANBgNVBAoTBkFtYXpvbjEZMBcGA1UEAxMQQW1hem9uIFJv
401
402 b3QgQ0EgMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALJ4gHHKeNXj
403
404 ca9HgFB0fW7Y14h29Jlo91ghYPl0hAEvrAIthtOgQ3pOsqTQNroBvo3bSMgHFzZM
405
406 9O6II8c+6zf1tRn4SWiw3te5djgdYZ6k/oI2peVKVuRF4fn9tBb6dNqcmzU5L/qw
407
408 IFAGbHrQgLKm+a/sRxmPUDgH3KKHOVj4utWp+UhnMJbulHheb4mjUcAwhmahRWa6
409
410 VOujw5H5SNz/0egwLX0tdHA114gk957EWW67c4cX8jJGKLhD+rcdqsq08p8kDi1L
411
412 93FcXmn/6pUCyziKrlA4b9v7LWIbxcceVOF34GfID5yHI9Y/QCB/IIDEgEw+OyQm
413
414 jgSubJrIqg0CAwEAAaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMC
415
416 AYYwHQYDVR0OBBYEFIQYzIU07LwMlJQuCFmcx7IQTgoIMA0GCSqGSIb3DQEBCwUA
417
418 A4IBAQCY8jdaQZChGsV2USggNiMOruYou6r4lK5IpDB/G/wkjUu0yKGX9rbxenDI
419
420 U5PMCCjjmCXPI6T53iHTfIUJrU6adTrCC2qJeHZERxhlbI1Bjjt/msv0tadQ1wUs
421
422 N+gDS63pYaACbvXy8MWy7Vu33PqUXHeeE6V/Uq2V8viTO96LXFvKWlJbYK8U90vv
423
424 o/ufQJVtMVT8QtPHRh8jrdkPSHCa2XV4cdFyQzR1bldZwgJcJmApzyMZFo6IQ6XU
425
426 5MsI+yMRQ+hDKXJioaldXgjUkK642M4UwtBV8ob2xJNDd2ZhwLnoQdeXeGADbkpy
427
428 rqXRfboQnoZsG4q5WTP468SQvvG5
429
430 ~-~-~-~--END CERTIFICATE~-~-~-~--}
431
432 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
433
434 [[image:image-20240528174408-14.png]]
435
436
437 After successful execution, as shown in the following figure.
438
Mengting Qiu 45.1 439 [[image:image-20250306134213-1.png]]
Bei Jinggeng 24.2 440
441 Display (% style="color:blue" %)**"Successfully configured CA certificate."**(%%) If the configuration is successful, otherwise it is considered configuration failure.
442
443
Xiaoling 24.5 444 ==== 4.2.2.2 Configure client certificate ====
Bei Jinggeng 24.2 445
446
447 Use the AT command AT+CLICERT as follows:
448
449 AT+CLICERT=~-~-~-~--BEGIN CERTIFICATE~-~-~-~--
450
451 MIIDWTCCAkGgAwIBAgIUYSpJUzfb4NTa76JJxd2th0fZA8swDQYJKoZIhvcNAQEL
452
453 BQAwTTFLMEkGA1UECwxCQW1hem9uIFdlYiBTZXJ2aWNlcyBPPUFtYXpvbi5jb20g
454
455 SW5jLiBMPVNlYXR0bGUgU1Q9V2FzaGluZ3RvbiBDPVVTMB4XDTI0MDUyNDA4MDI0
456
457 NVoXDTQ5MTIzMTIzNTk1OVowHjEcMBoGA1UEAwwTQVdTIElvVCBDZXJ0aWZpY2F0
458
459 ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMTdc1GQLVBohAeCJD6n
460
461 6WTFAFrygTch90a5wUr2bhlVuDxvEhEKNcmu5vOCo5agmfLWb2VCxgezgvQOBYQ8
462
463 1oTqXJNdl4tS0DICfqb/ogVHWGHRao67XyhbPNBS0j/nCPTIIk6+/NBeYPOjaG+p
464
465 utfXE7SGIEcc3RevkYkUJx6y+WH7MLjj1mufuXBVWIL1RrfrIRPw6auVk7dhS5rU
466
467 NvYcJa7Qd6gpAh1DzPj7ZECrv7fEIIBDEsSYOy6ToWtzqGIVcIAHBDfORB0Hcm+N
468
469 7wG3KDf61P4aWkLlkP5pRUaUIQdVblxginmx2K3n8t/WP7QcfITa191rjEVVBXmk
470
471 ROsCAwEAAaNgMF4wHwYDVR0jBBgwFoAUs8Caohh1ZGP8kjSn3rtxJiJJ9IswHQYD
472
473 VR0OBBYEFCjwGwqD7FG9UCNm3wjFQX4HixzfMAwGA1UdEwEB/wQCMAAwDgYDVR0P
474
475 AQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUAA4IBAQBgqI49a4PBQZYrFM63TX3EHgdd
476
477 N6Pj7AytjO+SrKNMCSo/OtIvhDTxOocr1vKrux1Tw5qmrllrIXLtlGtbmln5DS6a
478
479 DTCLrjwcIFIabLxpx5DPY1WSMYvL04SW7d4Y+3SxOFNRotDSiomr8eIIac0d3HE2
480
481 B5b0SnWZgWbrhjNUgvwo8l8tA9DOGIr2MeQ5kPjudOOiYSR3HC0v+jviBMV6VX8M
482
483 LHVH3CRshHDKBGpV1NZ1RAm9EY/oRGtSiMsyjRh6hegC0vehwVxaC4w9qG0ASkzz
484
485 42OOGfNqhYnYDiKTEIkazaoAFpTKDejWBaL7W5VpthUkQOl67IyX+ohuUKTo
486
487 ~-~-~-~--END CERTIFICATE~-~-~-~--}
488
489 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
490
491 [[image:image-20240528174630-16.png||height="553" width="747"]]
492
493 Display (% style="color:blue" %)**"Successfully configured client certificate."**(%%) Configuration successful, otherwise configuration failed.
494
495
Xiaoling 24.5 496 ==== 4.2.2.3 Configure client private key ====
Bei Jinggeng 24.2 497
498
499 Use the AT command AT+CLIKEY, as shown below
500
501 AT+CLIKEY=~-~-~-~--BEGIN RSA PRIVATE KEY~-~-~-~--
502
503 MIIEpAIBAAKCAQEAxN1zUZAtUGiEB4IkPqfpZMUAWvKBNyH3RrnBSvZuGVW4PG8S
504
505 EQo1ya7m84KjlqCZ8tZvZULGB7OC9A4FhDzWhOpck12Xi1LQMgJ+pv+iBUdYYdFq
506
507 jrtfKFs80FLSP+cI9MgiTr780F5g86Nob6m619cTtIYgRxzdF6+RiRQnHrL5Yfsw
508
509 uOPWa5+5cFVYgvVGt+shE/Dpq5WTt2FLmtQ29hwlrtB3qCkCHUPM+PtkQKu/t8Qg
510
511 gEMSxJg7LpOha3OoYhVwgAcEN85EHQdyb43vAbcoN/rU/hpaQuWQ/mlFRpQhB1Vu
512
513 XGCKebHYrefy39Y/tBx8hNrX3WuMRVUFeaRE6wIDAQABAoIBAFhAOcjvjBDGuaEw
514
515 CxV3al49HfqnSZuwg0xWSztSm2qKDcwxsnSnEhO2b1vsTW9h0YGV9Vv8gg/Dvkmv
516
517 23M7XqM4+IUraJsRZbl1etdcM4KQSCOZoF4Zyv+pXuq4pf31kQNCkHaikWzLUkUG
518
519 FPQxr0vA49mCYwfd/ZL3ppM/0IWmxRwloV1Gb9q8iDBUcJGSDokZnT7diUxzzOcd
520
521 +UJ6xUhFq1v46Y7vO+73XROLv34JEBC0bIw2ErL6+AbzhHwb2mkuSccG9Ks37g3Z
522
523 dyyjjj8hm1wvHWepuWqEssaiS3HD5zAsI0v85xS8RwNj3zLfd8o1WC666n3CO+ij
524
525 VdRmR4kCgYEA+/sEFxpfaRomqcLwJebZcZH06U1RfJFfnbH2/Q6fANf8zNxwWs9A
526
527 O+jyk/CLhHYRIk6VIOMQmWwEYgJ2eAHfw2Diwj4/0eqkGu+yZOS6KTCewxSV73vc
528
529 SvACramJy4y6yEgDN5onwR1XqfVMfA0LzTcSupHR/xvrpf/gCsNFPxUCgYEAyAFd
530
531 nMUhJFSq3pOogxA43aJSkA8YuDS3jpBkKQ6vx81APpIMabQauOxFDt488TZGP3Yy
532
533 lhpa/lfFIgu2K7CgV4dUp+JtJJoZ/F+ExxUUzdqB4zxzWywAcc3RebfwP6qASwFT
534
535 G3mXYci4tgNWR+k5CSsuLXDk/OT5uo5GeGAEc/8CgYEAk6V8uxDP8STKnNRFpN/E
536
537 b6CHciDE64m/DgbWY2cq0fK9BUjxaLRhvfj8EqVzCrWnyoNjLHcAJfW+B7PLuPvY
538
539 IoJlvE1/Vb/4UnQ7ApVnY3VCwaoRRNc9uIcz+pAJ1sRqOarAf9cLDkPkNwktvM5k
540
541 KOXpSnrhIms4w/bPT18l9xUCgYBsAMDKbXEuK0JyGw5+Z/4tQQCQpnZU0rLkm3ha
542
543 64FkxaORplBprEZZ4cyQ8NW78/EPSAadI/JLMp5TejuPcDvFyGCgoBcMEuNBc1tC
544
545 HlIzr3FAgl5Qt3wt+FTMA9YKq0nINxjn10s2FKwaLccj4f9YwiaXh0VAg22PnlDT
546
547 pBYDhQKBgQCMwyKXJ4zYiDRdvLvgKzeuKaU4KNQItHE4KORPfkecjPoENt4bKxDw
548
549 2EdNFQLIoqBHL1s+/8+SzhCI31V7pkTs1AqCxDExJS7+8Z5NQFQIo/jooUo0N80E
550
551 y3ZZS6OLOXXscEqhMogf1grfbabXM9OkgTIq43cPQHtMGQiFAtIJkg==
552
553 ~-~-~-~--END RSA PRIVATE KEY~-~-~-~--}
554
555 (% style="color:red" %)**Note: Be sure to add a terminator "}" at the end of the command. Otherwise, the command will not execute successfully.**
556
557 [[image:image-20240528174702-17.png]]
558
559 Display(% style="color:blue" %)** "Successfully configured client private key."**(%%) If the configuration is successful, otherwise it is considered configuration failure.
560
561
Mengting Qiu 46.1 562 ==== 4.2.2.4 Re-upgrade the firmware ====
Bei Jinggeng 24.2 563
Xiaoling 24.4 564
Mengting Qiu 46.1 565 After completing the certificate configuration, Burn the [[bootloader>>https://www.dropbox.com/scl/fo/ztlw35a9xbkomu71u31im/AE23WqlQ8CKU4cuy-sP1JkM/Utility/NB-IoT%20Bootloader?rlkey=ojjcsw927eaow01dgooldq3nu&e=1&subfolder_nav_tracking=1&dl=0]] firmware first, then re-burn the original working [[firmware>>https://www.dropbox.com/scl/fo/ztlw35a9xbkomu71u31im/ANd2flSqspRRXl-ksF6gUqk/LTE-M?dl=0&rlkey=ojjcsw927eaow01dgooldq3nu&subfolder_nav_tracking=1]].
566
567
568 ==== 4.2.2.5 For -CB /-CS model Certificate setting error/change certificate ====
569
570
Bei Jinggeng 24.2 571 (% data-sider-select-id="7c5a8abc-e707-467b-ac02-db0a89098320" %)When you set the wrong certificate or you need to re-set another certificate.
572 Please use the following three commands:
573
Xiaoling 24.4 574 (% style="color:blue" %)**AT+DELCLIKEY}**
Bei Jinggeng 24.2 575
Xiaoling 24.4 576 (% style="color:blue" %)**AT+DELCLICERT}**
Bei Jinggeng 24.2 577
Xiaoling 24.7 578 (% style="color:blue" %)**AT+DELCACERT}**(%%)
579 (% style="color:blue" %)
Bei Jinggeng 24.2 580
Xiaoling 24.4 581 (% style="color:red" %)**Note: 1.When there is no certificate on the device, a deletion error will be displayed.
Bei Jinggeng 24.2 582 2.When the device already has a certificate, using the command to configure the certificate again will display a configuration error.**
583
584
585 = (% data-sider-select-id="6b5deb69-539b-42e1-a7bc-a300eb1fea73" %)5. Configure draginoNB-device(%%) =
586
Bei Jinggeng 22.1 587 == 5.1 Configure the data format sent by the device ==
588
Xiaoling 23.2 589
Xiaoling 23.7 590 (% style="color:blue" %)**AT+PRO=3,5**(%%) (Data is in Json format of MQTT)
Xiaoling 1.2 591
592
Bei Jinggeng 22.1 593 == 5.2 Set server address ==
Xiaoling 1.2 594
Xiaoling 23.2 595
Xiaoling 23.7 596 (% style="color:blue" %)**AT+SERVADDR=an5tk94sdgjat-ats.iot.us-east-1.amazonaws.com,8883**
Xiaoling 1.2 597
598
Xiaoling 23.2 599 == 5.3 Set up private and public topics ==
Xiaoling 1.2 600
Xiaoling 23.2 601
Xiaoling 1.2 602 AWS does not limit topics, so you can set any topic
603
Xiaoling 23.7 604 (% style="color:blue" %)**AT+SUBTOPIC=Any**
Xiaoling 1.2 605
Xiaoling 23.7 606 (% style="color:blue" %)**AT+PUBTOPIC=Any**
Xiaoling 1.2 607
608
Bei Jinggeng 22.1 609 == 5.4 Set the TLS mode ==
Xiaoling 1.2 610
Xiaoling 23.2 611
Bei Jinggeng 24.2 612 (% data-sider-select-id="cf7bb573-8375-4479-9801-df8bb7dab3ba" style="color:blue" %)**AT+TLSMOD=1,2**
Xiaoling 1.2 613
Xiaoling 23.7 614 To use the TLS mode certificate function, users need to configure the (% style="color:blue" %)**AT+TLSMOD**(%%) command.
Xiaoling 1.2 615
Xiaoling 23.7 616 (% style="color:blue" %)**AT+TLSMOD=1,0** (%%) ~/~/ No authentication
Xiaoling 1.2 617
Xiaoling 23.7 618 (% style="color:blue" %)**AT+TLSMOD=1,1** (%%) ~/~/ Perform server authentication
Xiaoling 1.2 619
Xiaoling 23.7 620 (% style="color:blue" %)**AT+TLSMOD=1,2** (%%) ~/~/ Perform server and client authentication if requested by the remote server.(In AWS we recommend using this mode)
Xiaoling 1.2 621
622
Bei Jinggeng 24.2 623 (% data-sider-select-id="f443b9bc-1195-4fe2-965d-7de84f78747f" %)
Xiaoling 24.4 624 == 5.5 Set the MQOS ==
Xiaoling 1.2 625
Xiaoling 24.4 626
Bei Jinggeng 24.2 627 (% data-sider-select-id="cf7bb573-8375-4479-9801-df8bb7dab3ba" style="color:blue; font-weight:bold" %)**AT+MQOS**(% data-sider-select-id="cf7bb573-8375-4479-9801-df8bb7dab3ba" style="color:blue" %)**=XX (Depends on your server configuration)**
Xiaoling 23.2 628
Bei Jinggeng 24.2 629 Please find it in AWS's MQTT test client
630
631 [[image:image-20240529164339-1.png||height="480" width="927"]]
632
633
634 (% data-sider-select-id="fef22158-6e5e-46e4-b59e-fe457e562376" %)
635 == 5.6 Restart the device ==
636
637
Bei Jinggeng 22.1 638 = 6. View data on AWS =
Xiaoling 1.2 639
Xiaoling 23.2 640 == 6.1 Find MQTT test client in test ==
Xiaoling 1.2 641
Xiaoling 23.2 642
Xiaoling 1.2 643 In the fourth step, fill in the topics you subscribed to before
644
Xiaoling 23.7 645 (% style="color:blue" %)**AT+PUBTOPIC=XXXX**
Xiaoling 1.2 646
647 If you forget your previous topic, you can fill in #,subscribe to all topics
648
Bei Jinggeng 22.1 649 [[image:image-20240528175111-18.png||height="409" width="1014"]]
Xiaoling 1.2 650
651
Xiaoling 23.5 652 == 6.2 The data published information in Subscriptions ==
Xiaoling 1.2 653
Bei Jinggeng 22.1 654
655 [[image:image-20240528175133-19.png||height="563" width="1022"]]
656
657 [[image:image-20240528175154-20.png||height="752" width="1042"]]