Skip to Main Content
Cumulocity IoT Feedback Portal
Status Likely to support/improve
Created by Guest
Created on Aug 24, 2023

LwM2M PSK should not be available in plaintext

The LwM2M config (including PSK ID and keys for bootstrap and server authentication) is available/displayed in plaintext through the API and UI.

This is in contrast to the secure provisioning of standard device credentials (password), which cannot be accessed in plaintext beyond the bootstrap registration process.

Once provisioned/generated, the PSK should not be accessible in plaintext.

  • Attach files
  • Admin
    Aaron Raab
    Reply
    |
    Aug 31, 2023

    Hi Martin, thank you for raising this topic. We do agree here and already have discussed this internally. I can’t commit on a specific timeline, but this is definitely a topic we want to address.