Setting up client certificate authentication
You have established which of the authentication requirements apply to the target broker (see “Client certificate authentication”).
If the broker requires it, you have generated a device-specific client certificate, and submitted it for import into the broker’s Trust Store.
If the broker requires it, you have generated a device-specific client certificate and it has been signed by the broker’s trusted CA certificate. The certificate and CSR might be generated in Workbench using the Certificate Management Tool.
You are running Workbench on a PC and are connected to a controller station.
- The broker generally presents its own certificate during the connection handshake. If this certificate is not signed by a well-established CA that is pre-existing in the station’s System Trust Store, perform one of the following:
Connect once to generate a warning in the station’s Certificate Manager Allowed Hosts tab. Review the entry and approve the certificate.
- Pre-install the public certificate of either the broker’s TLS certificate or its CA certificate into the stations User Trust Store.

