Merge branch 'fix/tls-session-verify-and-hostname-warn_v5.3' into 'release/v5.3'

fix(esp-tls): fix TLS session resumption bypassing CA verification and clarify skip_common_name behavior (v5.3)

See merge request espressif/esp-idf!48932
This commit is contained in:
Mahavir Jain
2026-06-08 20:39:51 +05:30
2 changed files with 12 additions and 6 deletions
+9 -2
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -189,7 +189,14 @@ typedef struct esp_tls_cfg {
const char *common_name; /*!< If non-NULL, server certificate CN must match this name.
If NULL, server certificate CN must match hostname. */
bool skip_common_name; /*!< Skip any validation of server certificate CN field */
bool skip_common_name; /*!< When true, esp-tls skips the call to
mbedtls_ssl_set_hostname(). This disables BOTH
server-hostname matching against the certificate
(CN/SAN) and Server Name Indication (SNI), not just
the legacy CN field. Only set on loopback / debug
clients that can tolerate the loss of hostname
authentication. Must be false for SNI to function
correctly. */
tls_keep_alive_cfg_t *keep_alive_cfg; /*!< Enable TCP keep-alive timeout for SSL connection */
+3 -4
View File
@@ -739,6 +739,9 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t
}
free(use_host);
} else {
ESP_LOGW(TAG, "skip_common_name=true: hostname matching and SNI disabled. "
"This disables ALL server-name authentication (CN/SAN/SNI), not just CN. "
"Only intended for loopback / debug clients.");
mbedtls_ssl_set_hostname(&tls->ssl, NULL);
}
@@ -813,10 +816,6 @@ esp_err_t set_client_config(const char *hostname, size_t hostlen, esp_tls_cfg_t
#else
ESP_LOGE(TAG, "psk_hint_key configured but not enabled in menuconfig: Please enable ESP_TLS_PSK_VERIFICATION option");
return ESP_ERR_INVALID_STATE;
#endif
#ifdef CONFIG_ESP_TLS_CLIENT_SESSION_TICKETS
} else if (cfg->client_session != NULL) {
ESP_LOGD(TAG, "Resuing the saved client session");
#endif
} else {
#ifdef CONFIG_ESP_TLS_SKIP_SERVER_CERT_VERIFY