mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp-tls): Keep deprecated use_secure_element field for compatibility
Restore the use_secure_element field in esp_tls_cfg_t, esp_tls_cfg_server_t and httpd_ssl_config_t, and esp_transport_ssl_use_secure_element(), as deprecated no-ops so that existing code keeps compiling. Setting them now fails at runtime with ESP_ERR_NOT_SUPPORTED, as the feature is accessed via the esp_key_config_t interface. To be removed in the next major release.
This commit is contained in:
@@ -189,6 +189,13 @@ typedef struct esp_tls_cfg {
|
||||
underneath socket will be configured in non
|
||||
blocking mode after tls session is established */
|
||||
|
||||
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
|
||||
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
|
||||
Use `client_key` (esp_key_config_t) together with
|
||||
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
|
||||
Kept only for source compatibility; will be removed in
|
||||
the next major release. */
|
||||
|
||||
int timeout_ms; /*!< Network timeout in milliseconds.
|
||||
Note: If this value is not set, by default the timeout is
|
||||
set to 10 seconds. If you wish that the session should wait
|
||||
@@ -340,6 +347,13 @@ typedef struct esp_tls_cfg_server {
|
||||
|
||||
esp_tls_ecdsa_curve_t ecdsa_curve; /*!< ECDSA curve to use (SECP256R1 or SECP384R1) */
|
||||
|
||||
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
|
||||
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
|
||||
Use `server_key` (esp_key_config_t) together with
|
||||
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
|
||||
Kept only for source compatibility; will be removed in
|
||||
the next major release. */
|
||||
|
||||
uint32_t tls_handshake_timeout_ms; /*!< TLS handshake timeout in milliseconds.
|
||||
Note: If this value is not set, by default the timeout is
|
||||
set to 10 seconds. If you wish that the session should wait
|
||||
|
||||
@@ -752,6 +752,15 @@ static esp_err_t set_server_config(esp_tls_cfg_server_t *cfg, esp_tls_t *tls)
|
||||
#endif // CONFIG_ESP_TLS_SERVER_MIN_AUTH_MODE_OPTIONAL
|
||||
}
|
||||
|
||||
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
|
||||
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
|
||||
* The field is kept for source compatibility only. */
|
||||
if (cfg->use_secure_element) {
|
||||
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use server_key (esp_key_config_t) with "
|
||||
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
|
||||
return ESP_ERR_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
if (cfg->server_key != NULL && cfg->server_key->source == ESP_KEY_SOURCE_BUFFER) {
|
||||
/* Unified key config with buffer source */
|
||||
esp_tls_pki_t pki = {
|
||||
@@ -1025,6 +1034,15 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t
|
||||
#endif
|
||||
}
|
||||
|
||||
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
|
||||
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
|
||||
* The field is kept for source compatibility only. */
|
||||
if (cfg->use_secure_element) {
|
||||
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use client_key (esp_key_config_t) with "
|
||||
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
|
||||
return ESP_ERR_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
if (cfg->client_key != NULL && cfg->client_key->source == ESP_KEY_SOURCE_BUFFER) {
|
||||
/* Unified key config with buffer source */
|
||||
esp_tls_pki_t pki = {
|
||||
|
||||
Reference in New Issue
Block a user