![WTE TReX-460 User Manual Download Page 246](http://html1.mh-extra.com/html/wte/trex-460/trex-460_user-manual_1000427246.webp)
TReX User Manual v15.30 Firmware
When setting up multiple TReX devices, the only the Server Private Key, the Server Certificate
Request, the Server Certificate and the DH Parameters need to be regenerated for each device.
The security of the generated server certificates is only as secure as the storage of the CA
certificate and CA private key. Ensure that these files are not easily accessible. It is best
practice to keep a log of all attempts to access these files.
In the event that any required files are missing or invalid, the TReX will reject any further
attempts by the client to connect.
Operating as a TLS Client
When operating as a client, the TReX does not require any certificate or key files to be present
in the internal storage as certificates are provided by the server. However, it should be ensured
that the server being used supports the following cipher suites:
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x67)
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
(0x33)
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
(0x16)
No additional tasks need to be performed when using MQTT with TLS enabled. When
connecting to a server the authentication process begins automatically. In the event of a failed
connection, the TReX will attempt to reconnect after a period of five seconds.
Once a connection has been established, the TReX operates identically as when TLS is
disabled. There is no additional formatting to the information sent or received on the
application level.
Refer to the Specifications section for more information about the specific TLS protocol used.
Notes
When operating with a TLS connection, the connection to the web page interface is not
encrypted and should not be considered secure.
As with standard TCP connections, the TReX device only supports a single TLS connection at
a time when configured as a server. Care should be taken when integrating the device into a
network that only approved and trusted clients are able to connect to the device.
TLS Connection Error Codes
Error Code
Error
1
Certificate file missing or invalid
© WTE Limited, 2022 – Christchurch New Zealand
Page 246 of 302
Summary of Contents for TReX-460
Page 87: ...TReX User Manual v15 30 Firmware WTE Limited 2022 Christchurch New Zealand Page 87 of 302...
Page 286: ...TReX User Manual v15 30 Firmware WTE Limited 2022 Christchurch New Zealand Page 286 of 302...
Page 302: ...TReX User Manual v15 30 Firmware WTE Limited 2022 Christchurch New Zealand Page 302 of 302...