Defensive labs About 1 min read

MQTT TLS and ACL review

Review broker trust and topic permissions in a synthetic design. Check publisher and subscriber access, retained messages and replay handling.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.

Verification and testing

Overview#

Lab class: Offline configuration/trace fixture or loopback protocol simulation

Procedure#

  1. Record the broker/product/version represented by the fixture, MQTT version, listener model, TLS policy, and client identity mechanism.
  2. Map one publisher and subscriber to exact allowed topic filters, sites/tenants and operations.
  3. Confirm publish and subscribe authorisation are independent and wildcard behaviour can't cross scope.
  4. Review retained messages, persistent sessions, session/message expiry, wills, shared subscriptions, queue limits and dead letter storage.
  5. Review TLS endpoint validation, client certificate or credential rotation and denial behaviour.
  6. Map synthetic cases for authorised publish/subscribe, denied cross site topic, malformed/oversized payload, duplicate event, session expiry, and reconnect to expected state transitions. A purpose built loopback simulator may model these transitions without implementing or contacting a broker.
  7. Record what QoS acknowledgement guarantees and what it doesn't guarantee downstream.

Stop conditions#

Don't start or contact a broker, connect to a network endpoint, enumerate real topics, publish operational looking alarms/commands, test resource exhaustion, or use real device credentials. Broker and product acceptance belongs to separately governed environment validation.

Evidence checklist#

  • Fixture provenance and represented broker, MQTT, and configuration versions recorded
  • Publisher and subscriber identities mapped to exact tenant/site/topic permissions
  • Publish, subscribe, wildcard, retained message, and shared subscription authorisation reviewed independently
  • Session expiry, wills, retained state, queue limits, overflow, reconnect, and duplicate behaviour mapped
  • TLS identity, client credential lifecycle, denial, and downgrade expectations recorded
  • Synthetic positive, cross scope denial, malformed, oversized, duplicate, expiry, and reconnect cases assessed
  • QoS milestones kept distinct from downstream persistence or physical outcome

Sources#

Section overview · Wiki home