After restoring a backup, MQTT isn't working anymore

Updated: 2026-09-04 09:32:28

Symptoms

After restoring a CoCoS backup from one system onto another, the MQTT connections (used by connectors, services and webapplications) aren't working anymore.

Details

After restoring a backup from one system (with MQTT-configuration "A") onto another system (with MQTT-configuration "B"), the configuration files for CoCoS are copied/restored, but the MQTT-configuration of the system itself isn't changed. Because of this, after restoring a backup, the MQTT configuration will be broken.

Application

This mainly happens when restoring a backup from one system onto another system, not sharing the same MQTT configuration. Due to this, the username and/or password for the MQTT-user won't match anymore. The MQTT-credentials/mosquitto configuration located at /etc/mosquitto/ is not included in the backup, but the CoCoS configuration files (/etc/cocos/gateway.conf and /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php) are included in the backup. Because of this, a "mismatch" occurs when restoring a backup from one system onto another.

How to detect this:

The following commands/steps can be used to detect MQTT issues after restoring a back-up:

Executing the command below for finding MQTT related messages/errors/warnings in the cocos-syslog shows messages like:

  •  Disconnected from server '127.0.0.1:1884'
  •  Error connecting with server '127.0.0.1:1884'.
  • [WARN] MQTT: Failed to connect, for reason 'Connecting with MQTT server failed (NotAuthorized).'

 

tail -f /var/log/cocos-syslog.log -n 10000 | grep -i "MQTT"

image.png

Execute the command below to "listen" onto the current MQTT connection:

 

 

/usr/local/cocos/production/bin/tools/listen-mqtt.sh

image.png

Solution / Resolution / How To

This issue can be solved 2 ways, please read the options below carefully before choosing one:

  1. Overwrite the MQTT configuration for CoCoS, based on the configuration on the system.
    When choosing this option, the configuration restored from the backup has to be adjusted to match the configuration on the system. If the credentials for MQTT on the CoCoS system are unknown, this option won't be possible without resetting them. Also, changing the MQTT configuration as restored from the backup will have to be executed every time the same backup is restored again. 
  2. Overwrite the MQTT configuration on the system, based on the configuration for CoCoS.
    When choosing this option, the existing MQTT configuration of the system will be changed. This can be an issue when the MQTT configuration is more extensive than the "standard configuration" as set up during the installation of a new CoCoS system. Especially when, for example, bridging configurations have been applied, modifying the existing MQTT configuration can cause other features to stop working after the adjustment for CoCoS!
1. Overwrite the MQTT configuration for CoCoS, based on the configuration on the system.

When the credentials for the CoCoS MQTT-user and password are known (because the password is encypted in file /etc/mosquitto/passwords/mosquitto_passwords.txt, without knowing them, it's not possible to enter them in the configurationfiles for CoCoS), two files have to be adjusted. In the examples below, the username "CoCoS" and password "12345" will be used. When the MQTT-user and password are unknown, use the instructions mentioned in 2. Overwrite the MQTT configuration on the system, based on the configuration for CoCoS.

Open the file /etc/cocos/cocosMqtt.conf and change the values in keys "username" and "password". Use the command below:

nano /etc/cocos/cocosMqtt.conf

image.png

Open the file /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php and change the values in keys "username" and "password".

 

nano /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php

image.png

Restart all services and connectors, using the command below:

 

 

supervisorctl restart all

2. Overwrite the MQTT configuration on the system, based on the configuration for CoCoS.

When the credentials for the CoCoS MQTT-user and password are unknown (because the password is encypted in file/etc/mosquitto/passwords/mosquitto_passwords.txt, without knowing them, it's not possible to enter them in the configurationfiles for CoCoS), the configuration files for mosquitto have to be adjusted/a new configuration has to be applied.

Open the file /etc/cocos/cocosMqtt.conf or /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php to find out the username and password in the CoCoS backup. Use one of the commands below:

 

nano /etc/cocos/cocosMqtt.conf
nano /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php

 

In the examples below, the username "CoCoS" and password "12345" will be used.

image.png

image.png
Remove the existing password-file, used by Mosquitto, using the command below:

rm /etc/mosquitto/passwords/mosquitto_passwords.txt 


Create a new password-file/add a new user into the password file, using the command below.

touch /etc/mosquitto/passwords/mosquitto_passwords.txt
mosquitto_passwd -b /etc/mosquitto/passwords/mosquitto_passwords.txt <username> <password>

Replace <username> and <password> with the password from the MQTT configuration in the backup, like in the example below:

 

touch /etc/mosquitto/passwords/mosquitto_passwords.txt
mosquitto_passwd -b /etc/mosquitto/passwords/mosquitto_passwords.txt CoCoS 12345

image.png

Update the ACL-file for authenticated access to make sure the correct username is entered. Use the command below:

nano /etc/mosquitto/acl/acl_authenticated.conf

Make sure the user that the username from the backup is able to readwrite topics, using the configuration below.

# Allow the CoCoS user to read/write
#
user <username>
topic readwrite #

Replace <username> and <password> with the password from the MQTT configuration in the backup, like in the example below:

 

# Allow the CoCoS user to read/write
#
user CoCoS
topic readwrite #

image.png

Restart Mosquitto, using the command below:


systemctl restart mosquitto

Test/check

To test/check the new configuration after updating /etc/cocos/cocosMqtt.conf and /usr/local/cocos/production/httpdocs/configs/mqtt.configs.php or after updating and restarting mosquitto, use the command below to check if the MQTT credentials are correct:

/usr/local/cocos/production/bin/tools/listen-mqtt.sh

When all credentials are ok, this script should output all mqtt messages published onto the broker. If not, follow the steps on this page again.

image.png

References

Related Git issues: