The EVSE Directory · Field sheet · Cross-brand / Protocol · NET-C04
NET-C04Free sampleProxy MITM breaks certificate pin
Cross-brand / Protocol · DC Fast Chargers
Safety
Cert changes are security-sensitive — follow OEM/IT policy.
How it presents
Symptom
Proxy MITM breaks certificate pin — corporate proxy intercepts HTTPS and the charger rejects the substituted certificate. protocol field note: keep evidence scrubbed and prove the ranked cause before module RMA on NET-C04.
Root causes (by observed frequency)
- #1 SSL inspection enabled on EVSE VLAN
Chargers rarely trust corp roots
- #2 Explicit proxy config left over from lab image
- #3 CSMS certificate pin mismatch after proxy hop
- #4 Transparent proxy newly inserted by IT
Diagnostic procedure
1. Compare TLS peer certificate fingerprint to CSMS expected
Expected: Mismatch shows MITM
Tools: IT/OEM tools
2. Ask IT whether SSL inspect is on for this subnet
Expected: Yes/no
Tools: IT
3. Bypass/exclude CSMS hosts from inspection
Expected: Direct cert
Tools: IT
4. Remove erroneous explicit proxy settings on charger
Expected: No proxy
Tools: HMI
5. Retest handshake and Heartbeat
Tools: CSMS
The fix
MITM proxies break charger TLS pins — bypass inspection for CSMS hosts.
- Exclude charger CSMS traffic from SSL inspection. Document readings and scrubbed photos for NET-C04 before closing the ticket.
- Clear lab proxy leftovers from production images. Document readings and scrubbed photos for NET-C04 before closing the ticket.
- Do not install random corp roots on chargers unless OEM supports it.
- Confirm true CSMS certificate presents end-to-end. Document readings and scrubbed photos for NET-C04 before closing the ticket.
- Update network runbooks so future proxy projects skip EVSE VLANs.
Related entries
Related guides
Field confirmations (3) — subscribers only, one per account.
Missing a sibling fault? Request an entry