SARA-G3 and SARA-U2 series - System Integration Manual 
UBX-13000995 - R26    System description 
    Page 83 of 217 
1.13.8 SSL/TLS 
  Not supported by SARA-G300 and SARA-G310 modules. 
  Not supported by SARA-G340-00S and SARA-G350-00S / SARA-G350-00X modules. 
 
The modules support the Secure Sockets Layer (SSL) / Transport Layer Security (TLS) to provide security over the 
FTP and HTTP protocols with certificate key sizes defined as follows:. 
  SARA-G3 series 
o  Trusted root CA certificate: 4096 bits 
o  Client certificate: 4096 bits 
o  Client private key: 1024 bits 
  SARA-U2 series 
o  Trusted root CA certificate: 4096 bits 
o  Client certificate: 4096 bits 
o  Client private key: 4096 bits 
The SSL/TLS support provides different connection security aspects: 
  Server  authentication
37
:  use  of  the  server  certificate  verification  against  a  specific  trusted  certificate  or  a 
trusted certificates list 
  Client authentication
37
: use of the client certificate and the corresponding private key 
  Data security and integrity: data encryption and Hash Message Authentication Code (HMAC) generation 
The security aspects used during a connection depend on the SSL/TLS configuration and features supported.  
Table 16 contains the settings of the default SSL/TLS profile and Table 17 to Table 21 report the main SSL/TLS 
supported  capabilities  of  the  products.  For  a  complete  list  of  supported  configurations  and  settings,  see  the 
u-blox AT Commands Manual [3]. 
 
Certificates validation level 
The server certificate will not be checked or verified 
The server can use any of the TLS1.0/TLS1.1/TLS1.2 versions for the 
connection 
The cipher suite will be negotiated in the handshake process 
Trusted root certificate internal name 
No certificate will be used for the server authentication 
Expected server host-name 
No server host-name is expected 
Client certificate internal name 
No client certificate will be used 
Client private key internal name 
No client private key will be used 
Client private key password 
No client private key password will be used 
No pre-shared key password will be used 
Table 16: Default SSL/TLS profile 
 
  
37
 Not supported by the “00” product version