feat(mbedtls): update to version 3.6.4

This commit is contained in:
Ashish Sharma
2025-07-04 17:36:31 +08:00
parent e3eeb9d79c
commit 256145a1fe
5 changed files with 30 additions and 3 deletions
+9
View File
@@ -245,6 +245,15 @@ menu "mbedTLS"
See mbedTLS documentation for required API and more details.
config MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
bool "Enable keying material export"
default n
depends on MBEDTLS_TLS_ENABLED
help
Enable shared symmetric keys export for TLS sessions using mbedtls_ssl_export_keying_material()
after SSL handshake. The process for deriving the keys is specified in RFC 5705 for TLS 1.2
and in RFC 8446, Section 7.5, for TLS 1.3.
config MBEDTLS_PKCS7_C
bool "Enable PKCS #7"
default y
@@ -1114,6 +1114,24 @@
#undef MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
#endif
/**
* \def MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
*
* When this option is enabled, the client and server can extract additional
* shared symmetric keys after an SSL handshake using the function
* mbedtls_ssl_export_keying_material().
*
* The process for deriving the keys is specified in RFC 5705 for TLS 1.2 and
* in RFC 8446, Section 7.5, for TLS 1.3.
*
* Comment this macro to disable mbedtls_ssl_export_keying_material().
*/
#ifdef CONFIG_MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#define MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#else
#undef MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#endif
/**
* \def MBEDTLS_SSL_CBC_RECORD_SPLITTING
*