Defensive labs About 1 min read
MQTT TLS and ACL review
Review broker trust and topic permissions in a synthetic design. Check publisher and subscriber access, retained messages and replay handling.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.
On this page
Overview#
Lab class: Offline configuration/trace fixture or loopback protocol simulation
Procedure#
- Record the broker/product/version represented by the fixture, MQTT version, listener model, TLS policy, and client identity mechanism.
- Map one publisher and subscriber to exact allowed topic filters, sites/tenants and operations.
- Confirm publish and subscribe authorisation are independent and wildcard behaviour can't cross scope.
- Review retained messages, persistent sessions, session/message expiry, wills, shared subscriptions, queue limits and dead letter storage.
- Review TLS endpoint validation, client certificate or credential rotation and denial behaviour.
- Map synthetic cases for authorised publish/subscribe, denied cross site topic, malformed/oversized payload, duplicate event, session expiry, and reconnect to expected state transitions. A purpose built loopback simulator may model these transitions without implementing or contacting a broker.
- Record what QoS acknowledgement guarantees and what it doesn't guarantee downstream.
Stop conditions#
Don't start or contact a broker, connect to a network endpoint, enumerate real topics, publish operational looking alarms/commands, test resource exhaustion, or use real device credentials. Broker and product acceptance belongs to separately governed environment validation.
Evidence checklist#
- Fixture provenance and represented broker, MQTT, and configuration versions recorded
- Publisher and subscriber identities mapped to exact tenant/site/topic permissions
- Publish, subscribe, wildcard, retained message, and shared subscription authorisation reviewed independently
- Session expiry, wills, retained state, queue limits, overflow, reconnect, and duplicate behaviour mapped
- TLS identity, client credential lifecycle, denial, and downgrade expectations recorded
- Synthetic positive, cross scope denial, malformed, oversized, duplicate, expiry, and reconnect cases assessed
- QoS milestones kept distinct from downstream persistence or physical outcome
Sources#
- OASIS MQTT Version 5.0, accessed 25 August 2026.