mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(mbedtls): Raise error for certificate files with unsupported extension
gen_crt_bundle.py only parses files ending in .pem or .der, but silently ignored anything else. A PEM certificate named e.g. ca.crt was skipped without a word, and since the build invokes the script with -q, even the "Successfully added 0 certificates" hint was suppressed. The build then succeeded and embedded a bundle without the certificate, and the problem only surfaced at runtime as a TLS verification failure. A file passed directly via --input, which is what CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH points at, is now expected to be a certificate: an unsupported extension raises an InputError and fails the build with a message naming the file and the two accepted extensions. Files found while scanning a directory keep being skipped, as a certificate directory may legitimately contain other files, but a warning is now printed unconditionally so it is visible in the build log. Also document the requirement in the Kconfig help text and in the esp_crt_bundle documentation. Closes https://github.com/espressif/esp-idf/issues/18933
This commit is contained in:
@@ -30,6 +30,10 @@ Most configuration is done through menuconfig. CMake generates the bundle accord
|
||||
* :menuitem:`CONFIG_MBEDTLS_DEFAULT_CERTIFICATE_BUNDLE`: decide which certificates to include from the complete root certificate list.
|
||||
* :menuitem:`CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH`: specify the path of any additional certificates to embed in the bundle.
|
||||
|
||||
.. note::
|
||||
|
||||
Only PEM encoded certificates with a ``.pem`` extension and DER encoded certificates with a ``.der`` extension are parsed. The extension must match the encoding of the file, for example a PEM encoded certificate saved as ``.crt`` is not accepted. If :ref:`CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH` points directly at a file with any other extension, the build fails; if such a file is found inside a certificate directory, it is skipped and a warning is printed.
|
||||
|
||||
To enable the bundle when using ESP-TLS simply pass the function pointer to the bundle attach function:
|
||||
|
||||
.. code-block:: c
|
||||
|
||||
Reference in New Issue
Block a user