[Yandex Cloud documentation](../../../index.md) > [Yandex IoT Core](../../index.md) > [Step-by-step guides](../index.md) > Managing certificates > Managing broker certificates

# Managing broker certificates

{% note warning %}

Yandex IoT Core is no longer available to new users. 

Current users can create resources until November 1, 2026. Afterwards, the service will go read-only and cease to operate on December 1, 2026. For more information on the timing and procedure, see [Service shutdown](../../sunset.md).

{% endnote %}

{% note info %}

The broker is at the [Preview](../../../overview/concepts/launch-stages.md) stage.

{% endnote %}

To start exchanging messages between broker clients, you must [log in](../../concepts/authorization.md). This section describes how to manage broker certificates for the relevant authorization method.

{% note info %}

When using an X.509 certificate along with a password, the password has higher priority.

{% endnote %}

- [Viewing a list of broker certificates](broker-certificates.md#list-cert)
- [Adding a certificate to a broker](broker-certificates.md#add-cert)
- [Deleting a broker certificate](broker-certificates.md#delete-cert)

To access a [broker](../../concepts/index.md#broker), use its unique ID or name. For info on how to get the unique broker ID or name, see [Getting information about a broker](../broker/broker-list.md).

## Getting a list of broker certificates {#broker-certificates-list}

{% list tabs group=instructions %}

- Management console {#console}

   1. In the [management console](https://console.yandex.cloud), select the folder where the broker is located.
   1. Navigate to **IoT Core**.
   1. In the left-hand panel, select **Brokers**.
   1. Select the broker. A list of certificates will be displayed in the **Certificates** section.

- CLI {#cli}

  If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).

  The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  Get a list of broker certificates:

  ```bash
  yc iot broker certificate list --broker-name my-broker
  ```

  Result:

  ```text
  +------------------------------------------+---------------------+
  |               FINGERPRINT                |     CREATED AT      |
  +------------------------------------------+---------------------+
  | 0f511ea32139178edf73afb953a9cc********** | 2019-05-29 16:46:23 |
  | 589ce1605019eeff7bb0992f290be0********** | 2019-05-29 16:40:48 |
  +------------------------------------------+---------------------+
  ```

- API {#api}

  To get a list of broker certificates, use the [listCertificates](../../broker/api-ref/Broker/listCertificates.md) REST API method for the [Broker](../../broker/api-ref/Broker/index.md) resource or the [BrokerService/ListCertificates](../../broker/api-ref/grpc/Broker/listCertificates.md) gRPC API call.

{% endlist %}

## Adding a certificate {#add-cert}

{% list tabs group=instructions %}

- Management console {#console}

   1. In the [management console](https://console.yandex.cloud), select the folder to add the broker certificate to.
   1. Navigate to **IoT Core**.
   1. In the left-hand panel, select **Brokers**.
   1. Select the appropriate broker from the list.
   1. On the **Overview** page, go to the **Certificates** section and click **Add certificate**.

      - To add a file:

         1. Select the `File` method.
         1. Click **Attach file**.
         1. Select the certificate file on your computer and click **Open**.
         1. Click **Add**.

      - To add text:

         1. Select the `Text` method.
         1. Insert the certificate body in the **Content** field.
         1. Click **Add**.

- CLI {#cli}

  If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).
    
  The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  Add a certificate to the broker:

  ```bash
  yc iot broker certificate add \
    --broker-name my-broker \
    --certificate-file broker-cert.pem
  ```

  Where:
  * `--broker-name`: Broker name.
  * `--certificate-file`: Path to the public part of the certificate.
  
  Result:
  ```text
  broker_id: b91ki3851h**********
  fingerprint: 589ce1605...
  certificate_data: |
    -----BEGIN CERTIFICATE-----
    MIIE/jCCAuagAw...
    -----END CERTIFICATE-----
  created_at: "2019-05-29T16:40:48.230Z"
  ```

- Terraform {#tf}

  With [Terraform](https://www.terraform.io/), you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.
  
  Terraform is distributed under the [Business Source License](https://github.com/hashicorp/terraform/blob/main/LICENSE). The [Yandex Cloud provider for Terraform](https://github.com/yandex-cloud/terraform-provider-yandex) is distributed under the [MPL-2.0](https://www.mozilla.org/en-US/MPL/2.0/) license.
  
  For more information about the provider resources, see the guides on the [Terraform](https://www.terraform.io/docs/providers/yandex/index.html) website or [its mirror](../../../terraform/index.md).
  
  If you do not have Terraform yet, [install it and configure the Yandex Cloud provider](../../../tutorials/infrastructure-management/terraform-quickstart.md#install-terraform).
  
  
  To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), [authenticate](../../../terraform/authentication.md) using the appropriate method.

  To add a certificate to a broker created using Terraform:

  1. In the configuration file, describe the resources you want to create:

     * `yandex_iot_core_broker`: Broker parameters:
       * `name`: Broker name.
       * `description`: Broker description.
       * `certificates`: List of broker certificates for authentication with [certificates](../../concepts/authorization.md#certs).

      Example broker description in the Terraform configuration:

      ```hcl
      resource "yandex_iot_core_broker" "my_broker" {
        name        = "test-broker"
        description = "test broker for terraform provider documentation"
      ...
        certificates = [
          file("<path_to_first_certificate_file>"),
          file("<path_to_second_certificate_file>")
        ]
      ...
      }
      ```

      For more on the properties of the `yandex_iot_core_broker` resource, see [this provider guide](../../../terraform/resources/iot_core_broker.md).
  1. In the command line, change to the folder where you edited the configuration file.
  1. Make sure the configuration file is correct using this command:

      ```bash
      terraform validate
      ```

      If the configuration is valid, you will get this message:
     
      ```bash
      Success! The configuration is valid.
      ```

  1. Run this command:

      ```bash
      terraform plan
      ```

      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
  1. Apply the configuration changes:

      ```bash
      terraform apply
      ```

  1. Confirm the changes: type `yes` into the terminal and press **Enter**.

      You can verify broker certificates using the [management console](https://console.yandex.cloud) or this [CLI](../../../cli/quickstart.md) command:

      ```bash
      yc iot broker certificate list --broker-name <broker_name>
      ```

- API {#api}

  To add a certificate to a broker, use the [addCertificate](../../broker/api-ref/Broker/addCertificate.md) REST API method for the [Broker](../../broker/api-ref/Broker/index.md) resource or the [BrokerService/AddCertificate](../../broker/api-ref/grpc/Broker/addCertificate.md) gRPC API call.

{% endlist %}

## Deleting a certificate {#delete-cert}

{% list tabs group=instructions %}

- Management console {#console}

   1. In the [management console](https://console.yandex.cloud), select the folder to delete the broker certificate from.
   1. Navigate to **IoT Core**.
   1. In the left-hand panel, select **Brokers**.
   1. Select the appropriate broker from the list.
   1. On the **Overview** page, go to the **Certificates** section.
   1. In the line with the certificate, click ![image](../../../_assets/console-icons/ellipsis.svg) and select **Delete** from the drop-down list.
   1. In the window that opens, click **Delete**.

- CLI {#cli}

  If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).
    
  The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. Delete a broker certificate:

      ```bash
      yc iot broker certificate delete --broker-name my-broker --fingerprint 0f...
      ```

  1. Make sure the certificate was deleted:

      ```bash
      yc iot broker certificate list --broker-name my-broker
	    ```

	    Result:
	  
	    ```text
      +-------------+------------+
      | FINGERPRINT | CREATED AT |
      +-------------+------------+
      +-------------+------------+
      ```

- Terraform {#tf}

  With [Terraform](https://www.terraform.io/), you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.
  
  Terraform is distributed under the [Business Source License](https://github.com/hashicorp/terraform/blob/main/LICENSE). The [Yandex Cloud provider for Terraform](https://github.com/yandex-cloud/terraform-provider-yandex) is distributed under the [MPL-2.0](https://www.mozilla.org/en-US/MPL/2.0/) license.
  
  For more information about the provider resources, see the guides on the [Terraform](https://www.terraform.io/docs/providers/yandex/index.html) website or [its mirror](../../../terraform/index.md).
  
  If you do not have Terraform yet, [install it and configure the Yandex Cloud provider](../../../tutorials/infrastructure-management/terraform-quickstart.md#install-terraform).
  
  
  To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), [authenticate](../../../terraform/authentication.md) using the appropriate method.

  To delete a broker certificate created using Terraform:

  1. Open the Terraform configuration file and delete the certificate value in the `certificates` block, in the broker description fragment. To remove all certificates, delete the entire `certificates` section.

      Example broker description in the Terraform configuration:

      ```hcl
      resource "yandex_iot_core_broker" "my_broker" {
        name        = "test-broker"
        description = "test broker for terraform provider documentation"
      ...
        certificates = [
          file("<path_to_first_certificate_file>"),
          file("<path_to_second_certificate_file>")
        ]
      ...
      }
      ```

      For more on the properties of the `yandex_iot_core_broker` resource, see [this provider guide](../../../terraform/resources/iot_core_broker.md).
  1. In the command line, change to the folder where you edited the configuration file.
  1. Make sure the configuration file is correct using this command:

      ```bash
      terraform validate
      ```

      If the configuration is valid, you will get this message:
     
      ```bash
      Success! The configuration is valid.
      ```

  1. Run this command:

      ```bash
      terraform plan
      ```

      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
  1. Apply the configuration changes:

      ```bash
      terraform apply
      ```

  1. Confirm the changes: type `yes` into the terminal and press **Enter**.

      You can verify broker certificates using the [management console](https://console.yandex.cloud) or this [CLI](../../../cli/quickstart.md) command:

      ```bash
      yc iot broker certificate list --broker-name <broker_name>
      ```

- API {#api}

  To delete a broker certificate, use the [deleteCertificate](../../broker/api-ref/Broker/deleteCertificate.md) REST API method for the [Broker](../../broker/api-ref/Broker/index.md) resource or the [BrokerService/DeleteCertificate](../../broker/api-ref/grpc/Broker/deleteCertificate.md) gRPC API call.

{% endlist %}