Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SIM7600 SSL support 🤯 #767

Open
wants to merge 3 commits into
base: master
Choose a base branch
from
Open

Conversation

ghost
Copy link

@ghost ghost commented Jan 5, 2024

What

Native SSL support for the SIM7600. Use in the same way you would for 7080:

#define TINY_GSM_MODEM_SIM7600
TinyGsm modem(SerialAT);
TinyGsmClientSecure client(modem, 0);  // be sure to only use mux 0 or 1, it's all the chip allows!
HttpClient http(client, SERVER, PORT);

In your runtime code, before making any requests, you may need to add

        client.setCertificate(AWS_CERT_CA);  // e.g. static const char AWS_CERT_CA[] PROGMEM = R"EOF(BEGIN CERTIFICATE-----...

You DO NOT! need any additional SSL libraries for this code to work!

Tested On

  • HTTPS GET thanks to HttpsClient.ino example
  • HTTPS GET and POST thanks to custom code to wiremockapi
  • HTTPS OTA update from AWS S3 bucket using custom code (happy to share on request)

Known/Suspected Bugs

  • Doesn't work on Beeceptor HTTPS (works fine on HTTP). Maybe I'm using the wrong certs, I've tried a few options.
  • Haven't tested using both MUXs (you can have up to 2 HTTPS connections, in theory)
  • Haven't tried mix-and-matching HTTPS and HTTP connections, which SIMCOM reckons you can do.
  • Sorry if linting/formatting isn't on-point. My cpp linter did not like your layout at all 😂

@Lextan276
Copy link

Lextan276 commented Jan 11, 2024

Hello @Matt-Stedman-HardStuff, @Matt-Stedman
It's a great job. Can you share your custom code for OTA AWS S3?

@Matt-Stedman
Copy link

@Lextan276 I've drafted an example here: https://github.com/Hard-Stuff/EXAMPLES-SIMCOM_OTA
Hopefully it's clear enough for ya, let me know if you have any questions

@floBik
Copy link

floBik commented Jan 23, 2024

Hi @Matt-Stedman

I was also working on implementing ssl support for the SIM7600. Are you aware that your added certificates have no effect on the connection? You need to enable authentication with the following AT command AT+CSSLCFG="authmode",0,1 otherwise the server will not be verified. Unfortunately this causes some problems with the connection, at the moment I have not been able to solve them, I am working on it.

@ghost ghost marked this pull request as draft January 25, 2024 09:28
@ghost
Copy link
Author

ghost commented Jan 25, 2024

@floBik you're absolutely right! I actually got it working on HTTPS but without the certs, or something, but yeah it needed authmode to connect to certain servers including AWS.

There's another branch I've got where I was trying to get MQTTS working over UDP as in the unsecure mode, but I'm still struggling to get that part working. But, in that branch I DO have the authmode and I think that addresses your thought.

I've switched this MR to a draft and when I'm back from travelling I'll test the MQTTS functionality again, and either way I'll adjust the MR accordingly.
If you want to use my MQTTS branch as a base and figure out why it's not working then it saves us from having to implement the SIMCOM MQTTS AT functions.

@floBik
Copy link

floBik commented Feb 6, 2024

Hello @Matt-Stedman-HardStuff ,

After some time I got the authentication working. I tested the CA authentication and also the client authentication successfully. For me it also works for MQTT with SSL while using the PubSubClient library.

I have opened a pull request in your branch for my solution. If you have any questions or so feel free to message me.

@floBik
Copy link

floBik commented Feb 7, 2024

An additional note: some servers require a Server Name Indication (SNI), which is not currently supported by my Solution. This is because the SIM7600 only supports this feature from firmware version 2.0 ? earlier versions do not seem to be able to provide the SNI. If you want to use it and your firmware is able to do so, you need to enable it with the following AT command: AT+CSSLCFG=”enableSNI”,<ssl_ctx_index>,1

added SSL authmode support for SIM7600 (#1)
@ghost
Copy link
Author

ghost commented Feb 7, 2024

@floBik Just confirmed your code works for both MQTTS and HTTPS. Currently works with AWS, doesn't work with Airtable HTTP (but I've consistently had issues with this even on WiFi), so I'm giving it a 👍 on my end!

Thanks for the help, and nice work!

@ghost ghost marked this pull request as ready for review February 7, 2024 18:33
@floBik floBik mentioned this pull request Apr 2, 2024
@live-alchemy
Copy link

live-alchemy commented Apr 4, 2024

@vshymanskyy @SRGDamia1 kindly requesting you to take a look at this PR if you've a moment! would unblock our team :D

for others coming here, I was able to get a working HTTP client with SSL over LTE and Wifi by using this SSLClient library

@Matt-Stedman
Copy link

Matt-Stedman commented Apr 9, 2024

Hi all,

I'm Matt (Ghost, above! Just been combining my GitHub accounts).

I can confirm I've been using this PR for a few months now and @floBik you did an excellent job, works perfectly!
Yes, I think @vshymanskyy and @SRGDamia1 should look to test and if they're happy merge this, as it's now also a forked dependency on a few internal and public libraries I manage, which is a bit of a blocker!

@live-alchemy, if you're using platformio or similar you can temporarily make your dependency git@github.com:Hard-Stuff/TinyGSM.git. My very rudimentary testing suggests that using the SIMCOM built-in SSL is about twice as fast as trying to do SSL encryption on the ESP32/MCU first!

BenUniqcode pushed a commit to BenUniqcode/TinyGSM that referenced this pull request Apr 13, 2024
@BenUniqcode
Copy link

Thanks for this PR, it looks useful. However I've run into an issue which I think is a bug in this change:

   bool modemGetConnected(uint8_t mux) {
     // Read the status of all sockets at once
-    sendAT(GF("+CIPCLOSE?"));
-    if (waitResponse(GF("+CIPCLOSE:")) != 1) {
+    sendAT(GF("+CIPOPEN?"));
+    if (waitResponse(GF("+CIPOPEN:")) != 1) {
       // return false;  // TODO:  Why does this not read correctly?
     }
     for (int muxNo = 0; muxNo < TINY_GSM_MUX_COUNT; muxNo++) {
-      // +CIPCLOSE:<link0_state>,<link1_state>,...,<link9_state>
-      bool muxState = stream.parseInt();
-      if (sockets[muxNo]) { sockets[muxNo]->sock_connected = muxState; }
+      // +CIPOPEN:<mux>,<State or blank...>
+      String state = stream.readStringUntil('\n');
+      if (state.indexOf(',') > 0) { sockets[muxNo]->sock_connected = true; }
+      waitResponse(GF("+CIPOPEN:"));
     }
     waitResponse();  // Should be an OK at the end
     if (!sockets[mux]) return false;

Anyway, what happens is that you are doing one too many waitResponses for "+CIPOPEN". So the last one will always timeout, and it will also capture the "OK", so the following waitResponse() that is looking for that will also time out. This creates a significant delay every time modemGetConnected() is called - which is a lot. Before I added your PR, my connection and sending a few (non-SSL) MQTT messages would take about 7 seconds; with this bug it takes more like 60 seconds!

Why did you change it from CIPCLOSE? That presents all the information that modemGetConnected() requires in a more compact form, and seems to work fine.

@koushikDeb
Copy link

This lib is smooth .. Thanks for the help 👍 ..

For beginners like me sample working code

HardwareSerial SerialAT(1);

TinyGsm modem(SerialAT);
TinyGsmClientSecure client(modem,0);


client.setCACert(root_ca); // to set the https cert 

Note: cherry pick it on top of 0.11.7

@reusables-official
Copy link

@koushikDeb @Matt-Stedman

Thanks you two, I was able to connect to my API over SSL using git@github.com:Hard-Stuff/TinyGSM.git
At first glance it does seem a fair bit more performant than wrapping an SSLClient!

@Manojkumar0308
Copy link

#define TINY_GSM_MODEM_SIM7600
TinyGsm modem(SerialAT);
TinyGsmClientSecure client(modem, 0); // be sure to only use mux 0 or 1, it's all the chip allows!
HttpClient http(client, SERVER, PORT);

i run tinygsm https.ino and it gives error for tinygsmclientsecure this should be not in this scope why

@Gspohu
Copy link

Gspohu commented Aug 20, 2024

Hello,

I've had the opportunity to test the changes proposed in PR #767, and everything is functioning well in my setup. I'm looking forward to seeing these enhancements in the main branch.

Could you share any insights on when this PR might be merged into the main repository?

Thank you for your efforts and looking forward to your feedback!

@Matt-Stedman
Copy link

Hi @Gspohu and all, check out #808 (@floBik's MR). It is a bumped version of this and is more likely to be pulled in future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

9 participants