AssistNow uses standard TLS server authentication. Clients should validate the server certificate chain against a trusted root CA. A client certificate and private key are not required unless mutual TLS (mTLS) is explicitly configured.
For maximum compatibility and long-term robustness, AWS recommends including the full Amazon Trust Services root set in custom trust stores: Amazon Root CA 1, Amazon Root CA 2, Amazon Root CA 3, Amazon Root CA 4, and Starfield Services Root Certificate Authority G2. AWS does not recommend pinning individual leaf or intermediate certificates because they may be rotated over time.
u-blox currently has no plans to change the certificate authority used by AssistNow. However, AWS may periodically rotate server or intermediate certificates as part of normal certificate lifecycle management. For this reason, devices should trust the Amazon Trust Services root CAs rather than a specific server certificate. If a future change requiring customer action were anticipated, u-blox would communicate it through the normal customer notification channels.
The current Amazon Trust Services root certificates are published here: