mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
Merge branch 'feat/enable_cross_signed_cert_suppport_default_v6.1' into 'release/v6.1'
feat(mbedtls): enable cross signed certificate verification support by default (v6.1) See merge request espressif/esp-idf!50534
This commit is contained in:
@@ -91,7 +91,7 @@ With this functionality enabled, certificate verification is performed in a mann
|
||||
|
||||
.. note::
|
||||
|
||||
Enabling cross-signed certificate support increases run-time heap utilization by approximately 700 bytes, but reduces the flash footprint as the bundle size is reduced.
|
||||
Enabling cross-signed certificate support increases peak run-time heap usage during the TLS handshake by approximately 1 KB. This is a transient allocation (a candidate CA certificate built during certificate verification) that is freed once the handshake completes, and the exact amount scales with the maximum supported RSA key size. It also reduces the flash footprint, as the bundle size is reduced.
|
||||
|
||||
Key Points:
|
||||
|
||||
|
||||
@@ -406,6 +406,10 @@ The following table shows typical memory usage with different configs when the :
|
||||
|
||||
These values are subject to change with changes in configuration options and versions of Mbed TLS.
|
||||
|
||||
.. note::
|
||||
|
||||
:ref:`CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY` is enabled by default. If cross-signed certificate chains are not required, disabling it reduces peak heap usage during the TLS handshake by approximately 1 KB, at the cost of a larger certificate bundle in flash. See :doc:`/api-reference/protocols/esp_crt_bundle` for details.
|
||||
|
||||
|
||||
Reducing Binary Size
|
||||
^^^^^^^^^^^^^^^^^^^^
|
||||
|
||||
Reference in New Issue
Block a user