You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ESP32向AWS IoT发布证书创建请求后未收到响应

问题排查与解决方案

1. 策略权限验证

确认声明证书绑定的IoT策略必须显式包含以下权限,不能仅用通配符覆盖:

  • 允许发布到$aws/certificates/create/json
  • 允许订阅$aws/certificates/create/json/accepted和$aws/certificates/create/json/rejected
  • 允许接收上述两个响应主题的消息

示例正确策略片段:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iot:Publish",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:topic/$aws/certificates/create/json"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:topicfilter/$aws/certificates/create/json/accepted"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:topicfilter/$aws/certificates/create/json/rejected"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Receive",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:topic/$aws/certificates/create/json/accepted"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Receive",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:topic/$aws/certificates/create/json/rejected"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Connect",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:client/${iot:ClientId}"
    }
  ]
}

替换REGION和ACCOUNT_ID为实际值,${iot:ClientId}确保连接权限与设备客户端ID绑定。

2. 订阅时机与QoS设置

  • 必须等待订阅accepted和rejected主题成功后,再发布创建证书的请求,否则响应消息会丢失。
  • 订阅时将QoS设为1,保证消息可靠传递。示例代码:
if (mqttClient.subscribe("$aws/certificates/create/json/accepted", 1) && 
    mqttClient.subscribe("$aws/certificates/create/json/rejected", 1)) {
  Serial.println("订阅成功");
} else {
  Serial.println("订阅失败");
}

3. 发布消息格式验证

发布到$aws/certificates/create/json的消息必须是合法JSON,即使是空对象也可。示例正确内容:

{}

若格式错误,AWS IoT可能无法正常推送rejected响应,需确保发布时完成正确的JSON序列化。

4. 客户端ID与连接状态检查

  • 设备使用的客户端ID不能包含特殊字符,且无其他设备复用同一ID导致连接被踢。
  • 确保MQTT连接始终保持在线,若连接断开重连,需重新执行订阅操作。

5. AWS IoT日志排查

打开AWS IoT控制台的CloudWatch日志功能,查看以下内容:

  • 是否有该声明证书的AccessDenied日志,定位权限问题
  • 是否有响应消息生成但转发失败的记录,确认AWS侧是否正常推送

6. 消息接收回调验证

确保代码中正确实现MQTT消息回调,能捕获并打印响应:

void callback(char* topic, byte* payload, unsigned int length) {
  Serial.print("收到主题: ");
  Serial.println(topic);
  Serial.print("消息内容: ");
  for (int i = 0; i < length; i++) {
    Serial.print((char)payload[i]);
  }
  Serial.println();
}

初始化时绑定回调:

mqttClient.setCallback(callback);

内容的提问来源于stack exchange,提问作者MoFiggin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 05:58:21