mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp-tls): address MR review comments for SE PSA driver
- esp_tls_mbedtls: require cert when PSA-backed server/client key is set - esp_tls_mbedtls: drop redundant pk_init/x509_crt_init (calloc handles it) - psa SE driver: copy callbacks/opaque_key by value (no lifetime coupling) - psa SE driver: replace atomic CAS with simple null check on register - psa SE driver: use sig_len from sign callback with bounds validation - psa SE driver: validate pubkey_len returned by export_pubkey callback - psa SE driver: check hash sub-alg in RSA PKCS1V15 branch of validate_request - psa SE driver: align secure_element_register_callbacks doc with value-copy impl - esp_https_server: initialize server_key in HTTPD_SSL_CONFIG_DEFAULT - mbedtls: move SECURE_ELEMENT_DRIVER_ENABLED to esp_config.h for parity with ESP_ECDSA_DRIVER_ENABLED; drop target_compile_definitions - docs: fix esp_tls_cfg_t -> esp_http_client_config_t cross-reference - docs: check psa_import_key() status in ESP-TLS PSA example - hints/error_output: point at CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED
This commit is contained in:
@@ -255,8 +255,12 @@ ESP-TLS 支持通过 PSA Crypto 不透明驱动接口在 ESP32 系列芯片上
|
||||
};
|
||||
|
||||
psa_key_id_t psa_key_id;
|
||||
psa_import_key(&key_attr, (const uint8_t *)&opaque_key,
|
||||
sizeof(opaque_key), &psa_key_id);
|
||||
psa_status_t status = psa_import_key(&key_attr, (const uint8_t *)&opaque_key,
|
||||
sizeof(opaque_key), &psa_key_id);
|
||||
if (status != PSA_SUCCESS) {
|
||||
/* 处理错误 - 通常表示安全元件回调未注册或属性无效。 */
|
||||
return;
|
||||
}
|
||||
|
||||
/* 配置 ESP-TLS 使用 PSA 密钥 */
|
||||
esp_key_config_t key_config = {
|
||||
|
||||
Reference in New Issue
Block a user