mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
feat(mbedtls): enable cross signed certificate verification support by default
This commit is contained in:
committed by
Mahavir Jain
parent
6a0c7764e7
commit
b508d7bf9b
@@ -91,7 +91,7 @@ With this functionality enabled, certificate verification is performed in a mann
|
||||
|
||||
.. note::
|
||||
|
||||
Enabling cross-signed certificate support increases run-time heap utilization by approximately 700 bytes, but reduces the flash footprint as the bundle size is reduced.
|
||||
Enabling cross-signed certificate support increases peak run-time heap usage during the TLS handshake by approximately 1 KB. This is a transient allocation (a candidate CA certificate built during certificate verification) that is freed once the handshake completes, and the exact amount scales with the maximum supported RSA key size. It also reduces the flash footprint, as the bundle size is reduced.
|
||||
|
||||
Key Points:
|
||||
|
||||
|
||||
@@ -406,6 +406,10 @@ The following table shows typical memory usage with different configs when the :
|
||||
|
||||
These values are subject to change with changes in configuration options and versions of Mbed TLS.
|
||||
|
||||
.. note::
|
||||
|
||||
:ref:`CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY` is enabled by default. If cross-signed certificate chains are not required, disabling it reduces peak heap usage during the TLS handshake by approximately 1 KB, at the cost of a larger certificate bundle in flash. See :doc:`/api-reference/protocols/esp_crt_bundle` for details.
|
||||
|
||||
|
||||
Reducing Binary Size
|
||||
^^^^^^^^^^^^^^^^^^^^
|
||||
|
||||
Reference in New Issue
Block a user