feat(mbedtls): enable cross signed certificate verification support by default

This commit is contained in:
Ashish Sharma
2026-07-17 18:12:56 +08:00
parent a89931243c
commit 2c4bcab8d2
5 changed files with 16 additions and 5 deletions
@@ -91,7 +91,7 @@ With this functionality enabled, certificate verification is performed in a mann
.. note::
Enabling cross-signed certificate support increases run-time heap utilization by approximately 700 bytes, but reduces the flash footprint as the bundle size is reduced.
Enabling cross-signed certificate support increases peak run-time heap usage during the TLS handshake by approximately 1 KB. This is a transient allocation (a candidate CA certificate built during certificate verification) that is freed once the handshake completes, and the exact amount scales with the maximum supported RSA key size. It also reduces the flash footprint, as the bundle size is reduced.
Key Points:
@@ -404,6 +404,10 @@ The following table shows typical memory usage with different configs when the :
These values are subject to change with changes in configuration options and versions of Mbed TLS.
.. note::
:ref:`CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY` is enabled by default. If cross-signed certificate chains are not required, disabling it reduces peak heap usage during the TLS handshake by approximately 1 KB, at the cost of a larger certificate bundle in flash. See :doc:`/api-reference/protocols/esp_crt_bundle` for details.
Reducing Binary Size
^^^^^^^^^^^^^^^^^^^^