diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index 38bd1e9086d..9d7e7502af5 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -544,7 +544,7 @@ menu "mbedTLS" config MBEDTLS_CONSTANT_TIME_PRIME_GEN bool "Constant-time prime generation" - default y + default n help Use mbedtls' constant-time small-factor test (a constant-time GCD against the product of all odd primes up to 997) when @@ -559,9 +559,9 @@ menu "mbedTLS" If disabled, the variable-time trial division that mbedtls used before version 3.6.7 is used instead, restoring key - generation performance. Only consider disabling this if no - untrusted code running on the device could observe the timing - of key generation operations. + generation performance. + + Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830 endmenu # Security hardening diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 2aa5bd9422c..3d7e86f44be 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -215,7 +215,7 @@ /* mbedtls 3.6.7 made the small-factor test used in prime generation * constant-time, which slows RSA key generation down roughly tenfold and * starves the idle task (the computation never yields the CPU). The - * constant-time variant is the default; when it is explicitly disabled, + * non constant-time variant is the default; when it is disabled, * fall back to the variable-time trial division from earlier releases. See * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c. */