fix(https_x509_bundle): replace unreliable external URL in https_x509_bundle example

Replace howsmyssl.com with letsencrypt.org in the https_x509_bundle
example. howsmyssl.com is a third-party server that is frequently
unreachable from CI, causing flaky test failures. letsencrypt.org
chains to the same ISRG Root X1 CA, so the custom certificate bundle
validation coverage is identical.

Since letsencrypt.org was already present in the full bundle URL list,
remove the duplicate entry and reduce MAX_URLS from 9 to 8. All 6
unique root CAs in the stress test are still covered.

For the QEMU stress test, increase per-connection timeout from 30s to
60s and final completion timeout from 60s to 180s. QEMU emulated
network is 3-5x slower than real hardware for TLS handshakes.

(cherry picked from commit d6596eff3a)
(squashed with commit 995c0f129e)
This commit is contained in:
Hrushikesh Bhosale
2026-04-17 14:38:59 +05:30
committed by hrushikesh.bhosale
parent 6e51126e72
commit af58b0c058
2 changed files with 6 additions and 7 deletions

View File

@@ -1,7 +1,7 @@
/* HTTPS GET Example using plain mbedTLS sockets
*
* Contacts the howsmyssl.com API via TLS v1.2 and reads a JSON
* response.
* Connects to multiple HTTPS servers and validates their certificates
* using the certificate bundle.
*
* Adapted from the ssl_client1 example in mbedtls.
*
@@ -44,16 +44,15 @@
#include "esp_crt_bundle.h"
#if CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL
#define MAX_URLS 9
#define MAX_URLS 8
#else
#define MAX_URLS 2
#endif
static const char *web_urls[MAX_URLS] = {
"https://www.howsmyssl.com/a/check",
"https://letsencrypt.org",
"https://espressif.com",
#if CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL
"https://letsencrypt.org",
"https://www.identrust.com",
"https://www.globalsign.com",
"https://www.sectigo.com",

View File

@@ -70,5 +70,5 @@ def test_examples_protocol_https_x509_bundle_default_crt_bundle_stress_test(dut:
# start test
num_URLS = int(dut.expect(r'Connecting to (\d+) URLs', timeout=30)[1].decode())
for _ in range(num_URLS):
dut.expect(r'Connection established to ([\s\S]*)', timeout=30)
dut.expect('Completed {} connections'.format(num_URLS), timeout=60)
dut.expect(r'Connection established to ([\s\S]*)', timeout=60)
dut.expect('Completed {} connections'.format(num_URLS), timeout=180)