# Long term server certificate

**URL:** https://community.hivemq.com/t/long-term-server-certificate/2641
**Category:** MQTT
**Created:** [January 23, 2024, 1:09pm UTC](https://community.hivemq.com/t/long-term-server-certificate/2641 "2024-01-23T13:09:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![zandonella](https://avatars.discourse-cdn.com/v4/letter/z/e36b37/32.png) [@zandonella](https://community.hivemq.com/u/zandonella)
#### Post date: [January 23, 2024, 1:09pm UTC](https://community.hivemq.com/t/long-term-server-certificate/2641/1 "2024-01-23T13:09:08Z")

</div>

Hi,  
is there a long term (at least 10 years) server certificate for HiveMQ broker?

Thank you.

---

<div class="post-metadata">

### Author: ![AaronTLFranz](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.hivemq.com/aarontlfranz/32/638_2.png) [@AaronTLFranz](https://community.hivemq.com/u/AaronTLFranz)
#### Post date: [January 23, 2024, 3:18pm UTC](https://community.hivemq.com/t/long-term-server-certificate/2641/2 "2024-01-23T15:18:34Z")

</div>

Hello @zandonella ,

To start, welcome to the HiveMQ Community! We are always happy to see new faces interested in MQTT.

This question is dependent on the version of HiveMQ that you are currently utilizing. For [self-managed brokers](https://www.hivemq.com/products/hivemq-self-managed/), these certificates are generated by the user implementing TLS/SSL, and as a result the duration of the certificate will be determined during the certificate chain creation process.

For HiveMQ Cloud brokers, the current certificate is always available from the ‘FAQ’ section of our community forum ([here](https://community.hivemq.com/t/frequently-asked-questions/514)), or via direct link ([here](https://letsencrypt.org/certs/isrgrootx1.pem)). This currently has an expiration of June 4th, 2035.

Additionally, Cloud users utilizing Starter, Professional, or Enterprise tiers are able to provide their own certificates as well, similarly to self-hosted users, which allows for users to provide their own certificates, and as a result dictate their own expiration periods. A blog post regarding this feature is available [here](https://www.hivemq.com/blog/enhance-iot-security-client-certificate-authentication/).

Best,  
Aaron from the HiveMQ Team

---

<div class="post-metadata">

### Author: ![zandonella](https://avatars.discourse-cdn.com/v4/letter/z/e36b37/32.png) [@zandonella](https://community.hivemq.com/u/zandonella)
#### Post date: [January 23, 2024, 4:45pm UTC](https://community.hivemq.com/t/long-term-server-certificate/2641/3 "2024-01-23T16:45:55Z")

</div>

Thank you for answer.  
I not sure if I’ve understood when you speak of “Cloud users utilizing Starter, Professional, or Enterprise tiers”: I understand I could create client certificates but what about server certificate? Could I generate and set also it?

Best regards,  
Paolo

---

<div class="post-metadata">

### Author: ![AaronTLFranz](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.hivemq.com/aarontlfranz/32/638_2.png) [@AaronTLFranz](https://community.hivemq.com/u/AaronTLFranz)
#### Post date: [January 23, 2024, 9:55pm UTC](https://community.hivemq.com/t/long-term-server-certificate/2641/4 "2024-01-23T21:55:43Z")

</div>

Hello @zandonella ,

Thank you for the follow-up!

When utilizing HiveMQ Cloud, there are a number of available authentication methods available, depending on the chosen plan. Here is a quick snapshot of our [pricing page](https://www.hivemq.com/pricing/) showing a list of these available methods and their associated plans :

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/hivemq1/original/1X/b15325bb58ef0bbd5b6df7555ed9d82b44689cfe.png)

When looking at a Cloud environment using a Starter plan, for example, the “Access Management” portion of the page dictates certificate-based authentication methods.

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/hivemq1/original/1X/afff59ad0254af0255ad3c057cfec49fc98a33c2.png)  
This allows users to upload a public key certificate, identifying your root certificate authority, in order to allow client authentication based upon certificates.

Additional methods are available on a more custom basis as noted on our pricing page, and can be discussed and reviewed directly with our Sales teams, available [here](https://www.hivemq.com/contact/?btn=fm-professional).

Best,  
Aaron from the HiveMQ Team
