X.509

Certificates come with a highly organized hierarchical naming structure that consists of organization, organizational unit(s), and Distinguished Names (DN) or Common Names (CN). Referencing AWS support for provisioning X.509 certificates, we can see that AWS allows for the one-click generation of a device certificate. In the following example, we generate a device certificate with a generic IoT device common name and a lifetime of 33 years. The one-click generation also (centrally) creates the public/private key pair. If possible, it is recommended that you generate your certificates locally by, firstly, generating a key pair on the device and, secondly, uploading a CSR to the AWS IoT service. This allows for customized tailoring of ...

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.