feat(mbedtls): update to version 3.6.4

This commit is contained in:
Ashish Sharma
2025-07-04 17:34:00 +08:00
parent 7a329d5e91
commit a3af8972ae
5 changed files with 30 additions and 3 deletions
+9
View File
@@ -245,6 +245,15 @@ menu "mbedTLS"
See mbedTLS documentation for required API and more details.
config MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
bool "Enable keying material export"
default n
depends on MBEDTLS_TLS_ENABLED
help
Enable shared symmetric keys export for TLS sessions using mbedtls_ssl_export_keying_material()
after SSL handshake. The process for deriving the keys is specified in RFC 5705 for TLS 1.2
and in RFC 8446, Section 7.5, for TLS 1.3.
config MBEDTLS_PKCS7_C
bool "Enable PKCS number 7"
default y
@@ -1143,6 +1143,24 @@
#undef MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
#endif
/**
* \def MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
*
* When this option is enabled, the client and server can extract additional
* shared symmetric keys after an SSL handshake using the function
* mbedtls_ssl_export_keying_material().
*
* The process for deriving the keys is specified in RFC 5705 for TLS 1.2 and
* in RFC 8446, Section 7.5, for TLS 1.3.
*
* Comment this macro to disable mbedtls_ssl_export_keying_material().
*/
#ifdef CONFIG_MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#define MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#else
#undef MBEDTLS_SSL_KEYING_MATERIAL_EXPORT
#endif
/**
* \def MBEDTLS_SSL_CBC_RECORD_SPLITTING
*