IoT Edge certificate renewal

%3CLINGO-SUB%20id%3D%22lingo-sub-1405967%22%20slang%3D%22en-US%22%3EIoT%20Edge%20certificate%20renewal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1405967%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20implementing%20an%20IoT%20Edge%20on%20a%20lot%20of%20Devices%20which%20will%20be%20at%20remote%20locations.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20cleared%20out%20that%20IoT%20Edge%20can%20use%20up%20to%203%20certificates%3A%3C%2FP%3E%3COL%3E%3CLI%3ECertificate%20to%20perform%20the%20TLS%20communication%20with%20IoT%20Hub%3C%2FLI%3E%3CLI%3EDevice%20certificates%20for%20internal%20use%20with%20modules%2C%20leave%20devices%2C%20etc.%3C%2FLI%3E%3CLI%3EDPS%20(Optional%20is%20you%20use%20certificates)%3C%2FLI%3E%3C%2FOL%3E%3CP%3EWe%20are%20currently%20looking%20for%20a%20solution%20for%20point%201%20and%202.%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20We%20understand%20that%20this%20can%20be%20solved%20with%20keeping%20IoT%20Edge%20up-to-date%2C%20but%20how%20do%20perform%20this%20is%20these%20devices%20are%20Remote%20and%20we%20have%20a%20lot%20of%20them%3F%20I%20know%20this%20will%20not%20happen%20that%20often%20that%20this%20certificate%20will%20expire%20but%20still%20it%20can%2C%20so%20we%20want%20to%20be%20prepared.%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Device%20certificates%20should%20also%20be%20renewed%20from%20time%20to%20time.%20How%20can%20you%20also%20orchestrated%20form%20IoT%20Hub%3F%20We%20currently%20where%20thinking%20of%20building%20a%20module%2C%20but%20when%20the%20device%20comes%20online%20again%20after%20some%20time%20and%20in%20the%20main%20time%2C%20the%20certificate%20has%20expired%2C%20than%20the%20module%20is%20not%20able%20to%20talk%20to%20IoT%20Hub.%20Or%20do%20you%20just%20install%20a%20device%20certificate%20a%20installation%20which%20will%20have%20an%20expiration%20date%20longer%20then%20the%20expected%20device%20lifetime%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20help%20and%20insights%20on%20this%20topic.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKr%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESteven%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1405967%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ecertificates%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIoT%20Devices%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIoT%20Edge%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Regular Visitor

Hi all,

 

We are currently implementing an IoT Edge on a lot of Devices which will be at remote locations. 

 

We have cleared out that IoT Edge can use up to 3 certificates:

  1. Certificate to perform the TLS communication with IoT Hub
  2. Device certificates for internal use with modules, leave devices, etc.
  3. DPS (Optional is you use certificates)

We are currently looking for a solution for point 1 and 2. 

1. We understand that this can be solved with keeping IoT Edge up-to-date, but how do perform this is these devices are Remote and we have a lot of them? I know this will not happen that often that this certificate will expire but still it can, so we want to be prepared. 

2. Device certificates should also be renewed from time to time. How can you also orchestrated form IoT Hub? We currently where thinking of building a module, but when the device comes online again after some time and in the main time, the certificate has expired, than the module is not able to talk to IoT Hub. Or do you just install a device certificate a installation which will have an expiration date longer then the expected device lifetime?

 

Thanks for the help and insights on this topic.

 

Kr,

 

Steven

0 Replies