# How to use MQTT with TLS for Home Assistant?

**URL:** <https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046>\
**Category:** MQTT\
**Tags:** mqtt, home-assistant, mosquitto\
**Created:** [November 10, 2021, 11:00am UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046 "2021-11-10T11:00:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![stigvi](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/stigvi/32/35697_2.png) [@stigvi](https://www.thethingsnetwork.org/forum/u/stigvi)\
**Post date:** [November 10, 2021, 11:00am UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/1 "2021-11-10T11:00:19Z")

</div>

Hi. I have recently upgraded to V3, but I am struggling with the mqtt connection. I am using Mosquitto as an addon to Home Assistant and if I remember it correctly, I had to download and reference the mqtt-ca.pem found here: [https://www.thethingsnetwork.org/docs/applications/mqtt/api/](https://www.thethingsnetwork.org/docs/applications/mqtt/api/)  
But I suppose that is not a valid certificate when using eu1.cloud.thethings.network:8883  
Is there a new certificate to use? I have searched, but cannot find any.

---

<div class="post-metadata">

**Author:** ![htdvisser](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/htdvisser/32/45312_2.png) [@htdvisser](https://www.thethingsnetwork.org/forum/u/htdvisser)\
**Post date:** [November 10, 2021, 2:13pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/2 "2021-11-10T14:13:37Z")

</div>

The Things Stack Community Edition and The Things Stack Cloud use certificates that are trusted by your operating system, so you don’t need to configure custom certificate anymore.

If you work with `mosquitto_sub`, you can use the `--tls-use-os-certs` flag to make it use the certificates from your operating system.

---

<div class="post-metadata">

**Author:** ![stigvi](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/stigvi/32/35697_2.png) [@stigvi](https://www.thethingsnetwork.org/forum/u/stigvi)\
**Post date:** [November 10, 2021, 4:17pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/3 "2021-11-10T16:17:09Z")

</div>

> [@htdvisser](#):
>
> If you work with `mosquitto_sub`, you can use the `--tls-use-os-certs` flag to make it use the certificates from your operating system.

No, my only option is to configure mosquitto with a conf file. And I didn’t find a “tls use os certs” option.

And Mosquitto is run in a Docker and I have no control of the os certificates

---

<div class="post-metadata">

**Author:** ![cslorabox](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/cslorabox/32/35697_2.png) [@cslorabox](https://www.thethingsnetwork.org/forum/u/cslorabox)\
**Post date:** [November 10, 2021, 6:17pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/4 "2021-11-10T18:17:47Z")

</div>

> [@stigvi](#):
>
> And Mosquitto is run in a Docker and I have no control of the os certificates

Each docker container is effectively its own operating system, so actually this gives you even more control of such things - being able to uniquely configure things that would traditionally be system wide is half the point of docker.

> [@](#):
>
> my only option is to configure mosquitto with a conf file.

You can most certainly customize the command line used to invoke mosquitto.

It would appear that eu1.cloud.thethings.network:8883 is currently serving up a short term certificate signed by Let’s Encrypt, so what you need to do is validate it through the chain up through Let’s Encrypt and ISRG Root X1 rather than pinning this short lived certificate specifically.

If “ISRG Root X1” isn’t already there, that’s what you’d need to add to your docker config, or else pass explicitly to mosquitto

---

<div class="post-metadata">

**Author:** ![stigvi](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/stigvi/32/35697_2.png) [@stigvi](https://www.thethingsnetwork.org/forum/u/stigvi)\
**Post date:** [November 10, 2021, 6:50pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/5 "2021-11-10T18:50:50Z")

</div>

No, this docker is not maintained by me and I have little control over it. I cannot customize the command line either.

But I think I just power down the Dragino LPS8 for good and buy some zigbee sensors (temperature and humidity) instead. There is a working zigbee net there so that is a cheaper solution than burning hours on this.

---

<div class="post-metadata">

**Author:** ![cslorabox](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/cslorabox/32/35697_2.png) [@cslorabox](https://www.thethingsnetwork.org/forum/u/cslorabox)\
**Post date:** [November 10, 2021, 7:10pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/6 "2021-11-10T19:10:24Z")

</div>

An immutable docker configuration that can’t deal with periodically re-issued Let’s Encrypt certificates doesn’t really sound like something production grade. And immutability isn’t really something that exists anyway, unless it’s a machine instance belonging to someone else.

But nevermind.

There’s fairly limited overlap in the use cases of LoRaWAN and zigbee given the drastic differences in the radio technology which they use.

If Zigbee meets your functional needs, then zigbee is probably what you should be using - nevermind the momentary software configuration learning curve.

Maybe you can give that LoRaWAN gateway to someone who will use it, or put it on ebay or something and recover some of your cost while seeing that it does get used.

---

<div class="post-metadata">

**Author:** ![bluejedi](https://www.thethingsnetwork.org/forum/user_avatar/www.thethingsnetwork.org/bluejedi/32/44639_2.png) [@bluejedi](https://www.thethingsnetwork.org/forum/u/bluejedi)\
**Post date:** [November 10, 2021, 8:39pm UTC](https://www.thethingsnetwork.org/forum/t/how-to-use-mqtt-with-tls-for-home-assistant/53046/7 "2021-11-10T20:39:07Z")

</div>

To use TTN with MQTT in Home Assistant use MQTT bridging.

To enable TLS with bridging see:

> [@Cannot connect to MQTT over the port 8883](https://www.thethingsnetwork.org/forum/t/cannot-connect-to-mqtt-over-the-port-8883/52700/2):
>
> You may need to explicitly set the capath and protocol version parameters. Assuming that you are using Mosquitto with MQTT bridging: In mosquitto.conf to the bridge settings add: bridge\_capath /etc/ssl/certs bridge\_protocol\_version mqttv311 (Above capath works for Home Assistant (OS) but may require a different value for your OS/distribution.)
