Abstract

MQTT Security Context allows secure command writes through MQTT Engine and MQTT Transmission by using custom tag permissions to authorize a tag write based on user.

When using Ignition Security Context, the user authorization is encrypted and included with the published write event message from MQTT Engine. At MQTT Transmission, if the user is authorized to write to the tag, this results in a successful write, and the tag change is published. If the user is not authorized to write to the tag, there is no action taken. 

Review the Standard Tag Properties table for details on setting the Security property.  

To use this feature you must be using MQTT Engine and MQTT Transmission modules 4.0.10 or greater and Ignition 8.1.11 or greater


This page describes the MQTT Engine and MQTT Transmission configurations required to use MQTT Security Context.

MQTT Engine Configuration

In the Ignition Gateway web UI, navigate to the MQTT Engine Settings in the left side bar. From the Main tab, set the following elements in the Command Setting section.

Block Node Commands and/or Block Devices Commands must be de-selected for the Include Security Context feature to be enabled

MQTT Transmission Configuration

In the Ignition Gateway web UI, navigate to the MQTT Transmission Settings in the left side bar. From the Transmitters tab, for each transmitter set the following elements in the Command Setting section.