Skip to content

Update TLS.md#1553

Open
hkspks wants to merge 2 commits intotasmota:masterfrom
hkspks:patch-1
Open

Update TLS.md#1553
hkspks wants to merge 2 commits intotasmota:masterfrom
hkspks:patch-1

Conversation

@hkspks
Copy link
Copy Markdown

@hkspks hkspks commented Apr 20, 2026

Added instructions to reset the TLS fingerprint - a common issue, if the fingerprint changes due to server reconfiguration.

Added instructions to reset the TLS fingerprint - a common issue, if the fingerprint changes due to server reconfiguration.
@s-hadinger
Copy link
Copy Markdown
Collaborator

I'm converned. If you zero both fingerprints, then you make your device very vulnerable. Your legit server will be recognized as first fingerprint. When a rogue server shows up, it will take the second slots, hence defeating the purpose.

You should keep the original fingerprint and zero only one of them at the same time.

@hkspks
Copy link
Copy Markdown
Author

hkspks commented Apr 21, 2026

Thanks @s-hadinger, let's add this to the doc just to remove one fingerprint. For my interest: How are the fingerprints set at a fresh installation? I wanted to trigger a "factory reset". Furthermore a speaking error message would be great on the console, if the fingerprint of the server has changed. I got the following message and was kind of lucky to find the source of the problem:

11:50:18.211 MQT: TLS connection error: 1 11:50:18.213 MQT: Connect failed to <server-ip>:8883, rc -2. Retry in 20 sec

@hkspks hkspks marked this pull request as draft April 21, 2026 06:01
Added the note, only to clear one fingerprint at a time
@hkspks hkspks marked this pull request as ready for review April 21, 2026 06:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants