# MQTTtls certificate

**URL:** <https://community.tago.io/t/mqtttls-certificate/818>\
**Category:** Devices and Connectors\
**Created:** [January 22, 2022, 5:02am UTC](https://community.tago.io/t/mqtttls-certificate/818 "2022-01-22T05:02:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex034/user_avatar/community.tago.io/system/32/24_2.png) [@system](https://community.tago.io/u/system)\
**Post date:** [January 22, 2022, 5:02am UTC](https://community.tago.io/t/mqtttls-certificate/818/1 "2022-01-22T05:02:42Z")

</div>

@Marcin Wx

Need to run MQTT with TLS. My MQTT client asks to import a certificate to run TLS. Where to get the certificate from?

---

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex034/user_avatar/community.tago.io/system/32/24_2.png) [@system](https://community.tago.io/u/system)\
**Post date:** [January 22, 2022, 5:02am UTC](https://community.tago.io/t/mqtttls-certificate/818/2 "2022-01-22T05:02:43Z")

</div>

@Felipe Lima

Hi @nautiner, we don’t support custom certificate yet (it is on our roadmap).

The MQTT certificate is for connection protect only, not for identify device. The certificate will renew once a year, check on your MQTT library to use auto TLS certification connection.

---

<div class="post-metadata">

**Author:** ![system](https://yyz2.discourse-cdn.com/flex034/user_avatar/community.tago.io/system/32/24_2.png) [@system](https://community.tago.io/u/system)\
**Post date:** [January 22, 2022, 5:02am UTC](https://community.tago.io/t/mqtttls-certificate/818/3 "2022-01-22T05:02:44Z")

</div>

@Marcin Wx

Thanks, I need to use mosquito/tls to publish data to [tago.io](http://tago.io) however it fails due to certificate verify error. Where to get the CA file from to enable publishing data with mosquitto\_pub? The command I use is as below:

mosquitto\_pub -h [mqtt.tago.io](http://mqtt.tago.io) -p 8883 -u token -P abcdefgf-abc-1234-5678-abcyyyyexxxx -m testmsg -t testtopic -d

I think I need to provide CA file with mosquitto --cafile option. Can you help?

---

<div class="post-metadata">

**Author:** ![arturcarvalho](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@arturcarvalho](https://community.tago.io/u/arturcarvalho)\
**Post date:** [June 25, 2025, 7:10pm UTC](https://community.tago.io/t/mqtttls-certificate/818/4 "2025-06-25T19:10:14Z")

</div>

Hi!  
Do you have any updates on the custom certificate update? Are we still using auto TLS certs?

Thank you.

---

<div class="post-metadata">

**Author:** ![vitorfdl](https://yyz2.discourse-cdn.com/flex034/user_avatar/community.tago.io/vitorfdl/32/1728_2.png) [@vitorfdl](https://community.tago.io/u/vitorfdl)\
**Post date:** [June 26, 2025, 1:47pm UTC](https://community.tago.io/t/mqtttls-certificate/818/5 "2025-06-26T13:47:59Z")

</div>

Hi @arturcarvalho

We haven’t implemented custom certificate support for the TagoIO Public Broker, which continues to use well-known CA authorities for auto TLS certificates.

For custom CA certificates or mTLS requirements, you can deploy your own MQTT broker through TagoDeploy. Currently, this requires a TagoDeploy project, but we’re developing a standalone version that will work with standard TagoIO multi-tenant accounts.

You can explore TagoDeploy options here: [https://tago.io/deploy](https://tago.io/deploy)  
[https://community.tago.io/t/tagodeploy-mqtt-broker-service](https://community.tago.io/t/tagodeploy-mqtt-broker-service)
