# MQTT with TLS on PFC300

**URL:** <https://www.wago.community/t/mqtt-with-tls-on-pfc300/2636>\
**Category:** Hardware and Linux\
**Created:** [March 16, 2026, 11:40am UTC](https://www.wago.community/t/mqtt-with-tls-on-pfc300/2636 "2026-03-16T11:40:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pehaa](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pehaa](https://www.wago.community/u/pehaa)\
**Post date:** [March 16, 2026, 11:40am UTC](https://www.wago.community/t/mqtt-with-tls-on-pfc300/2636/1 "2026-03-16T11:40:24Z")

</div>

I’m trying to connect to MQTT broker running in AWS cloud using post 8883 and TLS certificate. Here are my settings in WBM. Currently I’m able to connect to the broker and send messages from my code. But when sending a message my receiving end (mousquitto\_sub) gives this error. “MOSQ\_OPT\_SSL\_CTX\_WITH\_DEFAULTS used without specifying cafile, capath or psk.” indicating that PLC is not providing CA file. Now, I’m not familiar with certificates, so I wonder if the default “/etc/ssl/certs/ca-certificates.crt” is not sufficient in this case? Or, am I missing something else?

 ![image](https://us1.discourse-cdn.com/flex016/uploads/wago/original/2X/1/1920fb4ed8067f73e946e58de4f9f53cd6474aee.png)

---

<div class="post-metadata">

**Author:** ![joe\_a](https://sea2.discourse-cdn.com/flex016/user_avatar/www.wago.community/joe_a/32/137_2.png) [@joe\_a](https://www.wago.community/u/joe_a)\
**Post date:** [March 16, 2026, 1:59pm UTC](https://www.wago.community/t/mqtt-with-tls-on-pfc300/2636/2 "2026-03-16T13:59:25Z")

</div>

From my experience, the broker in AWS should provide the certs in a CA.zip file. Once you have those files, you can FTP into that specified path within the controller.
