From 232685bae9c0b1c3bf00d88d03384e39a5e771ff Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Sat, 4 Apr 2026 10:23:00 +0530 Subject: [PATCH] fix(esp-tls): close CA-verification bypass during session resumption The session-resumption else-if in set_client_config() short-circuited the CA verification chain when only client_session was supplied. Remove the branch so session-only configs fall through to the normal error / skip-verify path; resumption no longer silently disables CA validation. --- components/esp-tls/esp_tls_mbedtls.c | 4 ---- 1 file changed, 4 deletions(-) diff --git a/components/esp-tls/esp_tls_mbedtls.c b/components/esp-tls/esp_tls_mbedtls.c index 37a22b5fa42..9f64bb24622 100644 --- a/components/esp-tls/esp_tls_mbedtls.c +++ b/components/esp-tls/esp_tls_mbedtls.c @@ -813,10 +813,6 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t #else ESP_LOGE(TAG, "psk_hint_key configured but not enabled in menuconfig: Please enable ESP_TLS_PSK_VERIFICATION option"); return ESP_ERR_INVALID_STATE; -#endif -#ifdef CONFIG_ESP_TLS_CLIENT_SESSION_TICKETS - } else if (cfg->client_session != NULL) { - ESP_LOGD(TAG, "Resuing the saved client session"); #endif } else { #ifdef CONFIG_ESP_TLS_SKIP_SERVER_CERT_VERIFY