
Transport Layer Security
(TLS)
Secure the connection between an XBee and Remote Manager with server
authentication
Digi XBee® 3 Cellular LTE-M/NB-IoT Global Smart Modem User Guide
181
If you have devices that have been upgraded in the field or manufactured prior to being pre-populated
with the Remote Manager certificate, you should follow the procedure below to add the necessary
certificate if server authentication is needed.
Step 1: Get the certificate
1. Navigate to the
Firmware Updates
section of the
Digi XBee 3 Cellular LTE-M/NB-IoT support
2. Click
Remote Manager TLS Public Certificate
to download the certificate .zip file.
3. Unzip the .zip file.
4. Calculate the SHA-256 hash to verify that the file is correct. The correct file will have an SHA-
256 hash of:
33d91e18668b0d8a9ec59c5f9f312c53ca2884adaa62337839e5495c26d2d64c
Step 2: Configure device
You should confirm that the default settings are correct. You can use either Remote Manager or XCTU
to verify these settings and place the certificate file in the correct location.
1. Verify the following settings:
Setting
Value
Bit 0 (mask 0x1) must be set. This enables the use of Digi Remote Manager within
the firmware.
Bit 1 (mask 0x2) must be set. When this value is set the Remote Manager TCP
connection will be secured with TLS.
By default will contain the value
/flash/cert/digi-remote-mgr.pem
. This is the file
system location where the firmware will look for the certificate to use.
2. Use XCTU or Remote Manager to place the downloaded and unzipped certificate file in the
location specified in the
$D
command.
Step 3: Verify that authentication is being performed
The next TCP connection to Remote Manager should only succeed if the server can be authenticated
using the provided certificate. You can confirm that the server has been authenticated.
1. Cause an active connection to Remote Manager. For example, you could set bit 0 for the
MO
command. Make sure that you do not clear bit 1.
2. After a short wait you should be able to see the device as connected in Remote Manager.
a.
b. Click
Device Management
.
c. Locate the device in the device list and verify that the connection icon in the left column is
blue and the hover tool tip says "Connected".
3. When the device is connected to Remote Manager, the
DI
command can take on any of the
three values shown below, based on the security level of the connection. Verify the that the
DI