For email, we embed the full certificate chain. For HTTPS and MQTTS we are essentially skipping the server certificate validation for now. Not sure how Mosquitto feels about self-signing. There are public free CAs out there though.
Well.... no progress on this -
I've tried two brokers and two clients. Any combination of no username/no password, username/password, TLS or no TLS works for the two broker configurations and two clients.
BUT the BRX doesn't work for anything other than no username/ no password.
I need to solve this problem. The error logs aren't helping me.
The attachments are for username/password only.
I'm digging through some wireshark logs now to find a clue......