diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c index 12d0cd803b7..0267280a6fa 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c @@ -32,6 +32,11 @@ #include "esp_heap_caps.h" +#include +#include "psa/crypto.h" + +#include "esp_heap_caps.h" + #define ECP_PRV_DER_MAX_BYTES ( 29 + 3 * MBEDTLS_ECP_MAX_BYTES ) #define ECP_PUB_DER_MAX_BYTES ( 30 + 2 * MBEDTLS_ECP_MAX_BYTES ) diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-rsa.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-rsa.c index 476876c605d..e9cd719cc34 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-rsa.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-rsa.c @@ -271,6 +271,25 @@ int crypto_private_key_decrypt_pkcs1_v15(struct crypto_private_key *key, } *outlen = output_len; + ret = mbedtls_pk_import_into_psa(pkey, &attributes, &key_id); + if (ret != 0) { + wpa_printf(MSG_ERROR, "failed to import key into PSA"); + ret = -1; + goto cleanup; + } + + size_t output_len = 0; + size_t heap_free_before = esp_get_free_heap_size(); + status = psa_asymmetric_decrypt(key_id, PSA_ALG_RSA_PKCS1V15_CRYPT, in, inlen, NULL, 0, out, *outlen, &output_len); + if (status != PSA_SUCCESS) { + printf("Failed to decrypt data, returned %d", (int) status); + ret = -1; + goto cleanup; + } + size_t heap_free_after = esp_get_free_heap_size(); + printf("Heap free before: %d, Heap free after: %d, used: %d\n", heap_free_before, heap_free_after, heap_free_before - heap_free_after); + *outlen = output_len; + cleanup: psa_reset_key_attributes(&key_attributes); if (key_id) {