Preparing for production
To use the Cellular: LwM2M Client sample in production, you must prepare the sample for production by completing the following steps:
Program the Cellular: AT Client sample to your device.
Provision the identity and security credentials.
Program the LwM2M client sample.
The following sections provide the guidelines on setting up the sample for production using AVSystem’s Coiote Device Management server.
You must program the Cellular: AT Client sample to your device to control the security tags in the modem.
See the nRF91x1 AT Commands Reference Guide or nRF9160 AT Commands Reference Guide for documentation on each AT command.
Also, you must provision the bootstrap credentials for the security tag (that you have specified in
CONFIG_LWM2M_CLIENT_UTILS_BOOTSTRAP_TLS_TAG Kconfig option) to the cellular modem.
To provision the credentials, complete the following steps:
Ensure that you have removed the previous security tags from the modem by issuing the
Identify the device IMEI by issuing the command
AT+CGSN 352656100367872 OK
Create an identity
urn:imei:<IMEI CODE>based on the IMEI of your device. For the example in previous step, the identity of the device is
Generate a secure PSK key and store that to the security tag. For example, to write the key
000102030405060708090a0b0c0d0e0f, run the following commands:
AT%CMNG=0,<TAG>,4,"urn:imei:352656100367872" OK AT%CMNG=0,<TAG>,3,"000102030405060708090a0b0c0d0e0f" OK
For automated provisioning of credentials, you can use the script
provision.py that is available in the
If you use AVSystem’s Coiote Device Management server, you must set your username and password for the server as environment variables when you run the script.
See the following code:
# Setup phase [nrf@dev]:~/scripts# export COIOTE_PASSWD='my-password' [nrf@dev]:~/scripts# export COIOTE_USER='my-username' # Run [nrf@dev]:~/scripts# ./provision.py AT interface ready Identity: urn:imei:352656100394546 Security tag 35724862 cleared PSK credentials stored to sec_tag 35724862 Coiote: Deleted device urn:imei:352656100394546 Coiote: Deleted device urn:imei:352656100394546-bs Coiote: Created device urn:imei:352656100394546 to domain /IoT/NordicSemi/Interop/
When Leshan demo server is used, script does not require password:
# Run [nrf@dev]:~/scripts# ./provision.py --leshan [INFO] provision.py - Identity: urn:imei:351358814369747 [INFO] device.py - Security tag 35724861 cleared [INFO] device.py - Security tag 35724862 cleared [INFO] device.py - PSK credentials stored to sec_tag 35724862
You can now program the device with the final sample image.
To configure and program the sample, complete the following steps:
Make the sample programmable to multiple devices by removing all hard coded credentials. This can be done by setting the CONFIG_APP_LWM2M_PSK Kconfig option to empty value.
Enable bootstrapping using the configuration overlay file
overlay-leshan-bootstrap.conf. Bootstrapping is required for an LwM2M client to rotate security credentials.
Prepare the production script or steps for your nRF91 Series device.
Program the sample.