How to update changing certificate requirements with AWS IoT Core
Blog
This article explains how to update certificate requirements for AWS IoT Core due to Symantec Server ICA expiration and TLS version upgrades.
- Symantec Server ICA expires October 31, 2023; new certificate based on VeriSign G5
- AWS IoT Core control plane and new endpoints switching to TLS 1.2 minimum by default
- Existing customer endpoints remain unchanged for backward compatibility
- Migrate to Amazon Trust Services (ATS) signed Root CA certificates for better security
- Use configurable endpoints to control TLS policy and migrate devices incrementally
- Avoid certificate pinning; pin to ATS Root CA instead of intermediate certificates
- Devices using ATS certificates unaffected; Symantec users must verify TLS implementation
- Test device compatibility with large server certificates using AWS IoT Device Advisor
Customers should migrate to ATS endpoints and TLS 1.2+ to ensure security and compatibility with AWS IoT Core's certificate updates.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.