# OCPP connectivity

> How to configure a charging station's OCPP settings to connect to Road's charging-station management backend.

When ordering a charging station it often comes pre-configured with an existing OCPP backend. The OCPP backend provides connectivity to the Charging Station Management System (CSMS) and allows an operator to run and earn money.

When a provider such as E-Flux and other Road-powered CPOs are pre-configured on a charging station, there is no configuration needed.

In the case that you need to manually configure the OCPP settings for your charging station, please follow instructions below.

## Production environment

In order to connect to Road's OCPP backend the charging station will need configuration of the correct OCPP endpoint.

The required provider slug is given to you by your account representative, and it is different from the `Provider ID`. Set it under **Personalise** on this page and the endpoints below will show yours.

### OCPP 1.6 and OCPP 2.0.1

SSL (See below for more information):

```
wss://ocpp.road.io/{{providerSlug}}
```

Non-SSL connection (not recommended):

```
ws://ocpp.road.io/{{providerSlug}}
```

Sim card IPSec tunnel (requires VPN sim card):

```
ws://ocpp-internal.road.io/{{providerSlug}}
```

After a reboot, your charging station should show up in the [Charging stations view in your dashboard](https://{{customDNS}}/charging-stations).

> Debugging your connection
>
> You can do a plain HTTP call to http://ocpp.road.io/health to see if the OCPP server can be reached from the EVSE network.

## Connection security

Our OCPP backends are available via a Cloudflare protected SSL endpoint:

```
wss://ocpp.road.io/{{providerSlug}}
```

Note that certain hardware providers require extra steps to make an SSL connection work. This can involve hardware specific configuration or custom firmware versions that embed root Certificate Authorities.

### Root CAs

All operating systems manage a database of "Root Certificate Authorities" (Root CAs) that allow seamless connections to SSL endpoints.

If a hardware vendor does not keep a database of Root CAs, you may need to provide them with a set of Root CAs to establish an SSL connection.

The certificates served against our OCPP backend are currently signed by Google Trust Services (GTS). The Root CA certificates required to be trusted, which can be downloaded via <https://pki.goog/repository/> , are:

- GTS Root R1 (RSA)
- GTS Root R2 (RSA)
- GTS Root R3 (ECDSA)
- GTS Root R4 (ECDSA)
- GlobalSign R4 (ECDSA)

> **Root CA limits**
>
> Some hardware vendors have restrictions on the quantity of Root CA certificates that can be initially installed, as well as supported public key types. If you face any such difficulties, prioritise installing GTS Root R1 and GTS Root R2 initially.

Let's Encrypt is used as a backup certificate issuer, in case there are any issues relating to certificate issuance via GTS. Therefore, it is recommended that the Root CA certificates relating to Let's Encrypt issued certificates are also installed. The Root CA certificates required to be trusted, which can be downloaded via <https://letsencrypt.org/certificates/> , are:

- ISRG Root X1 (RSA)
- ISRG Root X2 (ECDSA)

### Private Connection

For hardware that cannot support SSL connections, we offer an alternative connectivity method based on mobile network configuration. This option, available exclusively with a Road-provided SIM card installed in the charging station, and allows for secure communication without SSL. This approach leverages a secure, private APN and IPSec tunnel to connect the charging station to Road's OCPP backend, ensuring safe data transmission within a controlled network environment.

To configure this connection, users should reach out to their account representative, who will provide the necessary setup instructions.
