mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
Merge branch 'fix/keep_use_secure_element_v6.0' into 'release/v6.0'
fix(esp-tls): Keep deprecated use_secure_element field for compatibility (v6.0) See merge request espressif/esp-idf!50780
This commit is contained in:
@@ -189,6 +189,13 @@ typedef struct esp_tls_cfg {
|
||||
underneath socket will be configured in non
|
||||
blocking mode after tls session is established */
|
||||
|
||||
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
|
||||
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
|
||||
Use `client_key` (esp_key_config_t) together with
|
||||
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
|
||||
Kept only for source compatibility; will be removed in
|
||||
the next major release. */
|
||||
|
||||
int timeout_ms; /*!< Network timeout in milliseconds.
|
||||
Note: If this value is not set, by default the timeout is
|
||||
set to 10 seconds. If you wish that the session should wait
|
||||
@@ -340,6 +347,13 @@ typedef struct esp_tls_cfg_server {
|
||||
|
||||
esp_tls_ecdsa_curve_t ecdsa_curve; /*!< ECDSA curve to use (SECP256R1 or SECP384R1) */
|
||||
|
||||
bool use_secure_element; /*!< @deprecated No longer functional; setting this to true
|
||||
makes the connection fail with ESP_ERR_NOT_SUPPORTED.
|
||||
Use `server_key` (esp_key_config_t) together with
|
||||
CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead.
|
||||
Kept only for source compatibility; will be removed in
|
||||
the next major release. */
|
||||
|
||||
uint32_t tls_handshake_timeout_ms; /*!< TLS handshake timeout in milliseconds.
|
||||
Note: If this value is not set, by default the timeout is
|
||||
set to 10 seconds. If you wish that the session should wait
|
||||
|
||||
@@ -752,6 +752,15 @@ static esp_err_t set_server_config(esp_tls_cfg_server_t *cfg, esp_tls_t *tls)
|
||||
#endif // CONFIG_ESP_TLS_SERVER_MIN_AUTH_MODE_OPTIONAL
|
||||
}
|
||||
|
||||
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
|
||||
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
|
||||
* The field is kept for source compatibility only. */
|
||||
if (cfg->use_secure_element) {
|
||||
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use server_key (esp_key_config_t) with "
|
||||
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
|
||||
return ESP_ERR_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
if (cfg->server_key != NULL && cfg->server_key->source == ESP_KEY_SOURCE_BUFFER) {
|
||||
/* Unified key config with buffer source */
|
||||
esp_tls_pki_t pki = {
|
||||
@@ -1025,6 +1034,15 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t
|
||||
#endif
|
||||
}
|
||||
|
||||
/* use_secure_element is deprecated and non-functional: the cryptoauthlib
|
||||
* mbedTLS-ALT integration is not compatible with the PSA-based mbedTLS.
|
||||
* The field is kept for source compatibility only. */
|
||||
if (cfg->use_secure_element) {
|
||||
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use client_key (esp_key_config_t) with "
|
||||
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
|
||||
return ESP_ERR_NOT_SUPPORTED;
|
||||
}
|
||||
|
||||
if (cfg->client_key != NULL && cfg->client_key->source == ESP_KEY_SOURCE_BUFFER) {
|
||||
/* Unified key config with buffer source */
|
||||
esp_tls_pki_t pki = {
|
||||
|
||||
@@ -132,6 +132,12 @@ struct httpd_ssl_config {
|
||||
/** Enable tls session tickets */
|
||||
bool session_tickets;
|
||||
|
||||
/** @deprecated No longer functional; setting this to true makes server start fail with
|
||||
* ESP_ERR_NOT_SUPPORTED. Use `server_key` (esp_key_config_t) together with
|
||||
* CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. Kept only for source
|
||||
* compatibility; will be removed in the next major release. */
|
||||
bool use_secure_element;
|
||||
|
||||
/** User callback for esp_https_server */
|
||||
esp_https_server_user_cb *user_cb;
|
||||
|
||||
|
||||
@@ -348,6 +348,15 @@ static esp_err_t create_secure_context(const struct httpd_ssl_config *config, ht
|
||||
#endif
|
||||
}
|
||||
|
||||
/* use_secure_element is deprecated and non-functional; it is kept only for
|
||||
* source compatibility. */
|
||||
if (config->use_secure_element) {
|
||||
ESP_LOGE(TAG, "use_secure_element is no longer supported. Use server_key (esp_key_config_t) with "
|
||||
"CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. See the ESP-TLS migration guide.");
|
||||
ret = ESP_ERR_NOT_SUPPORTED;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
if (config->use_ecdsa_peripheral) {
|
||||
#ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN
|
||||
(*ssl_ctx)->tls_cfg->use_ecdsa_peripheral = config->use_ecdsa_peripheral;
|
||||
|
||||
@@ -206,6 +206,18 @@ void esp_transport_ssl_set_common_name(esp_transport_handle_t t, const char *com
|
||||
*/
|
||||
void esp_transport_ssl_set_ciphersuites_list(esp_transport_handle_t t, const int *ciphersuites_list);
|
||||
|
||||
/**
|
||||
* @brief Set the ssl context to use secure element (atecc608a) for client(device) private key and certificate
|
||||
*
|
||||
* @deprecated No longer functional; the TLS connection will fail with ESP_ERR_NOT_SUPPORTED when
|
||||
* this option is set. Use esp_transport_ssl_set_client_key_config() (esp_key_config_t)
|
||||
* together with CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED instead. Kept only for
|
||||
* source compatibility; will be removed in the next major release.
|
||||
*
|
||||
* @param t ssl transport
|
||||
*/
|
||||
void esp_transport_ssl_use_secure_element(esp_transport_handle_t t);
|
||||
|
||||
/**
|
||||
* @brief Set the ds_data handle in ssl context.(used for the digital signature operation)
|
||||
*
|
||||
|
||||
@@ -494,6 +494,14 @@ void esp_transport_ssl_set_ciphersuites_list(esp_transport_handle_t t, const int
|
||||
ssl->cfg.ciphersuites_list = ciphersuites_list;
|
||||
}
|
||||
|
||||
/* Deprecated and non-functional; kept only for source compatibility. Setting
|
||||
* use_secure_element makes the connection fail with ESP_ERR_NOT_SUPPORTED. */
|
||||
void esp_transport_ssl_use_secure_element(esp_transport_handle_t t)
|
||||
{
|
||||
GET_SSL_FROM_TRANSPORT_OR_RETURN(ssl, t);
|
||||
ssl->cfg.use_secure_element = true;
|
||||
}
|
||||
|
||||
#ifdef CONFIG_MBEDTLS_CERTIFICATE_BUNDLE
|
||||
void esp_transport_ssl_crt_bundle_attach(esp_transport_handle_t t, esp_err_t ((*crt_bundle_attach)(void *conf)))
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user