fix(esp-tls): Keep deprecated use_secure_element field for compatibility

Restore the use_secure_element field in esp_tls_cfg_t, esp_tls_cfg_server_t
and httpd_ssl_config_t, and esp_transport_ssl_use_secure_element(), as
deprecated no-ops so that existing code keeps compiling. Setting them now
fails at runtime with ESP_ERR_NOT_SUPPORTED, as the feature is accessed
via the esp_key_config_t interface. To be removed in the next major release.
This commit is contained in:
Aditya Patwardhan
2026-07-15 12:40:55 +05:30
parent 8bf9c476cf
commit 8fe74703bc
8 changed files with 72 additions and 4 deletions
+14
View File
@@ -189,6 +189,13 @@ typedef struct esp_tls_cfg {
underneath socket will be configured in non
blocking mode after tls session is established */
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
Use `client_key` (esp_key_config_t) together with
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
Kept only for source compatibility; will be removed in
the next major release. */
int timeout_ms; /*!< Network timeout in milliseconds.
Note: If this value is not set, by default the timeout is
set to 10 seconds. If you wish that the session should wait
@@ -340,6 +347,13 @@ typedef struct esp_tls_cfg_server {
esp_tls_ecdsa_curve_t ecdsa_curve; /*!< ECDSA curve to use (SECP256R1 or SECP384R1) */
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
Use `server_key` (esp_key_config_t) together with
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
Kept only for source compatibility; will be removed in
the next major release. */
uint32_t tls_handshake_timeout_ms; /*!< TLS handshake timeout in milliseconds.
Note: If this value is not set, by default the timeout is
set to 10 seconds. If you wish that the session should wait
+18
View File
@@ -752,6 +752,15 @@ static esp_err_t set_server_config(esp_tls_cfg_server_t *cfg, esp_tls_t *tls)
#endif // CONFIG_ESP_TLS_SERVER_MIN_AUTH_MODE_OPTIONAL
}
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
* The field is kept for source compatibility only. */
if (cfg->use_secure_element) {
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use server_key (esp_key_config_t) with "
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
return ESP_ERR_NOT_SUPPORTED;
}
if (cfg->server_key != NULL && cfg->server_key->source == ESP_KEY_SOURCE_BUFFER) {
/* Unified key config with buffer source */
esp_tls_pki_t pki = {
@@ -1025,6 +1034,15 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t
#endif
}
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
* The field is kept for source compatibility only. */
if (cfg->use_secure_element) {
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use client_key (esp_key_config_t) with "
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
return ESP_ERR_NOT_SUPPORTED;
}
if (cfg->client_key != NULL && cfg->client_key->source == ESP_KEY_SOURCE_BUFFER) {
/* Unified key config with buffer source */
esp_tls_pki_t pki = {