Devices fail to reconnect

@cesanta considering I could build a new FW with update ca.pem do you think it’s higher risk to attempt live push/overwrite of the ca.pem file or to just flash a new firmware?

Since mDash has rolled back the certificate can you suggest a way for us to validate that any new certs pushed to devices will actually work once the certificate is rolled in ~30 days?

Is there another address we can try to hit or something that is using the new certs?
I’m reading about openssl and curl and potentially how to recreate a call using a specific ca-bundle.pem to try and simulate this, any ideas would be much appreciated