From eaac238545073e4e2bb0b8e73fb5b5751443cab2 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Thu, 30 Apr 2026 17:22:34 +0800 Subject: [PATCH] fix(mbedtls): remove deprecated configs and migrate to PSA --- components/mbedtls/Kconfig | 29 +--- .../config/mbedtls_preset_default.conf | 2 - .../mbedtls/port/include/mbedtls/esp_config.h | 131 ++++++------------ examples/openthread/ot_br/sdkconfig.defaults | 1 - examples/openthread/ot_cli/sdkconfig.defaults | 1 - .../deep_sleep/sdkconfig.defaults | 1 - .../light_sleep/sdkconfig.defaults | 1 - .../openthread/ot_trel/sdkconfig.defaults | 1 - 8 files changed, 47 insertions(+), 120 deletions(-) diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index a4d29f3ce46..76084d006df 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -392,8 +392,7 @@ menu "mbedTLS" config MBEDTLS_X509_CREATE_C bool "X.509 certificate creation" default n - depends on MBEDTLS_BIGNUM_C && \ - MBEDTLS_PK_WRITE_C && MBEDTLS_MD_C + depends on MBEDTLS_PK_WRITE_C && MBEDTLS_MD_C help Support for creating X.509 certificates and CSRs. @@ -729,7 +728,7 @@ menu "mbedTLS" config MBEDTLS_KEY_EXCHANGE_ECJPAKE bool "Enable ECJPAKE based ciphersuite modes" - depends on MBEDTLS_ECJPAKE_C && MBEDTLS_ECP_DP_SECP256R1_ENABLED + depends on MBEDTLS_ECP_DP_SECP256R1_ENABLED default n help Enable to support ciphersuites with prefix TLS-ECJPAKE-WITH- @@ -978,21 +977,9 @@ menu "mbedTLS" endmenu menu "Asymmetric Ciphers" - config MBEDTLS_BIGNUM_C - bool "Enable multiple precision integer (bignum) support" - default y - help - Enable support for multiple precision integer (bignum) operations. - - This is required for RSA, DSA, DHM, ECDH and ECDSA. - - If you don't need any of these algorithms, you can disable this option - to save code size. - config MBEDTLS_RSA_C bool "RSA public key cryptosystem" default y - select MBEDTLS_BIGNUM_C help Enable RSA. Needed to use RSA-xxx TLS ciphersuites. @@ -1091,7 +1078,6 @@ menu "mbedTLS" config MBEDTLS_DHM_C bool "Diffie-Hellman-Merkle key exchange (DHM)" default n - select MBEDTLS_BIGNUM_C depends on MBEDTLS_ECP_C help Enable DHM. Needed to use DHE-xxx TLS ciphersuites. @@ -1107,13 +1093,6 @@ menu "mbedTLS" help Enable ECDH. Needed to use ECDHE-xxx TLS ciphersuites. - config MBEDTLS_ECJPAKE_C - bool "Elliptic curve J-PAKE" - depends on MBEDTLS_ECP_C - default n - help - Enable ECJPAKE. Needed to use ECJPAKE-xxx TLS ciphersuites. - config MBEDTLS_ECDSA_C bool "Elliptic Curve DSA" depends on MBEDTLS_ECDH_C && MBEDTLS_ECP_C @@ -1354,7 +1333,7 @@ menu "mbedTLS" config MBEDTLS_HARDWARE_MPI bool "Enable hardware MPI (bignum) acceleration" default y - depends on !SPIRAM_CACHE_WORKAROUND_STRATEGY_DUPLDST && SOC_MPI_SUPPORTED && MBEDTLS_BIGNUM_C + depends on !SPIRAM_CACHE_WORKAROUND_STRATEGY_DUPLDST && SOC_MPI_SUPPORTED help Enable hardware accelerated multiple precision integer operations. @@ -1586,7 +1565,7 @@ menu "mbedTLS" bool "Enable PKCS number 7" default y depends on MBEDTLS_ASN1_PARSE_C && MBEDTLS_PK_PARSE_C && \ - MBEDTLS_X509_CRT_PARSE_C && MBEDTLS_X509_CRL_PARSE_C && MBEDTLS_BIGNUM_C && MBEDTLS_MD_C + MBEDTLS_X509_CRT_PARSE_C && MBEDTLS_X509_CRL_PARSE_C && MBEDTLS_MD_C help Enable PKCS number 7 core for using PKCS number 7-formatted signatures. diff --git a/components/mbedtls/config/mbedtls_preset_default.conf b/components/mbedtls/config/mbedtls_preset_default.conf index c838311f33f..69c12156b7e 100644 --- a/components/mbedtls/config/mbedtls_preset_default.conf +++ b/components/mbedtls/config/mbedtls_preset_default.conf @@ -10,7 +10,6 @@ CONFIG_MBEDTLS_VERSION_C=n CONFIG_MBEDTLS_HAVE_TIME=y CONFIG_MBEDTLS_PLATFORM_TIME_ALT=n CONFIG_MBEDTLS_HAVE_TIME_DATE=n -CONFIG_MBEDTLS_BIGNUM_C=y CONFIG_MBEDTLS_INTERNAL_MEM_ALLOC=y CONFIG_MBEDTLS_EXTERNAL_MEM_ALLOC=n CONFIG_MBEDTLS_DEFAULT_MEM_ALLOC=n @@ -116,7 +115,6 @@ CONFIG_MBEDTLS_ECP_C=y CONFIG_MBEDTLS_ECP_NIST_OPTIM=y CONFIG_MBEDTLS_ECP_FIXED_POINT_OPTIM=n CONFIG_MBEDTLS_ECDH_C=y -CONFIG_MBEDTLS_ECJPAKE_C=n CONFIG_MBEDTLS_ECDSA_C=y CONFIG_MBEDTLS_PK_PARSE_EC_EXTENDED=y CONFIG_MBEDTLS_PK_PARSE_EC_COMPRESSED=y diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index fd1435c4c0e..014f450c5a6 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -532,16 +532,15 @@ * * Comment macros to disable the curve and functions for it */ -/* Short Weierstrass curves (supporting ECP, ECDH, ECDSA) */ +/* Short Weierstrass curves (supporting ECDH, ECDSA) */ #ifdef CONFIG_MBEDTLS_ECP_DP_SECP256R1_ENABLED -#define MBEDTLS_ECP_DP_SECP256R1_ENABLED +#define PSA_WANT_ECC_SECP_R1_256 1 #else -#undef MBEDTLS_ECP_DP_SECP256R1_ENABLED +#undef PSA_WANT_ECC_SECP_R1_256 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED -#define MBEDTLS_ECP_DP_SECP384R1_ENABLED +#define PSA_WANT_ECC_SECP_R1_384 1 #else -#undef MBEDTLS_ECP_DP_SECP384R1_ENABLED #undef PSA_WANT_ECC_SECP_R1_384 #endif #ifdef CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_192_BITS @@ -550,38 +549,35 @@ #undef PSA_WANT_ECC_SECP_R1_192 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_SECP521R1_ENABLED -#define MBEDTLS_ECP_DP_SECP521R1_ENABLED +#define PSA_WANT_ECC_SECP_R1_521 1 #else -#undef MBEDTLS_ECP_DP_SECP521R1_ENABLED +#undef PSA_WANT_ECC_SECP_R1_521 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_SECP256K1_ENABLED -#define MBEDTLS_ECP_DP_SECP256K1_ENABLED +#define PSA_WANT_ECC_SECP_K1_256 1 #else -#undef MBEDTLS_ECP_DP_SECP256K1_ENABLED +#undef PSA_WANT_ECC_SECP_K1_256 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_BP256R1_ENABLED -#define MBEDTLS_ECP_DP_BP256R1_ENABLED +#define PSA_WANT_ECC_BRAINPOOL_P_R1_256 1 #else -#undef MBEDTLS_ECP_DP_BP256R1_ENABLED +#undef PSA_WANT_ECC_BRAINPOOL_P_R1_256 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_BP384R1_ENABLED -#define MBEDTLS_ECP_DP_BP384R1_ENABLED +#define PSA_WANT_ECC_BRAINPOOL_P_R1_384 1 #else -#undef MBEDTLS_ECP_DP_BP384R1_ENABLED +#undef PSA_WANT_ECC_BRAINPOOL_P_R1_384 #endif #ifdef CONFIG_MBEDTLS_ECP_DP_BP512R1_ENABLED -#define MBEDTLS_ECP_DP_BP512R1_ENABLED +#define PSA_WANT_ECC_BRAINPOOL_P_R1_512 1 #else -#undef MBEDTLS_ECP_DP_BP512R1_ENABLED +#undef PSA_WANT_ECC_BRAINPOOL_P_R1_512 #endif -/* Montgomery curves (supporting ECP) */ +/* Montgomery curves */ #ifdef CONFIG_MBEDTLS_ECP_DP_CURVE25519_ENABLED -#define MBEDTLS_ECP_DP_CURVE25519_ENABLED +#define PSA_WANT_ECC_MONTGOMERY_255 1 #else -#undef MBEDTLS_ECP_DP_CURVE25519_ENABLED -#endif -#ifdef MBEDTLS_ECP_DP_CURVE448_ENABLED -#undef MBEDTLS_ECP_DP_CURVE448_ENABLED +#undef PSA_WANT_ECC_MONTGOMERY_255 #endif /** @@ -1836,29 +1832,7 @@ #undef MBEDTLS_BASE64_C #endif -/** - * \def MBEDTLS_BIGNUM_C - * - * Enable the multi-precision integer library. - * - * Module: library/bignum.c - * library/bignum_core.c - * library/bignum_mod.c - * library/bignum_mod_raw.c - * Caller: library/dhm.c - * library/ecp.c - * library/ecdsa.c - * library/rsa.c - * library/rsa_alt_helpers.c - * library/ssl_tls.c - * - * This module is required for RSA, DHM and ECC (ECDH, ECDSA) support. - */ -#ifdef CONFIG_MBEDTLS_BIGNUM_C -#define MBEDTLS_BIGNUM_C -#else -#undef MBEDTLS_BIGNUM_C -#endif +/* MBEDTLS_BIGNUM_C is deprecated in mbedtls 4.x - PSA handles bignum internally */ /** * \def MBEDTLS_CAMELLIA_C @@ -2120,9 +2094,9 @@ * Requires: MBEDTLS_ECP_C */ #ifdef CONFIG_MBEDTLS_ECDH_C -#define MBEDTLS_ECDH_C +#define PSA_WANT_ALG_ECDH 1 #else -#undef MBEDTLS_ECDH_C +#undef PSA_WANT_ALG_ECDH #endif /** @@ -2141,51 +2115,26 @@ * short Weierstrass curve. */ #ifdef CONFIG_MBEDTLS_ECDSA_C -#define MBEDTLS_ECDSA_C +#define PSA_WANT_ALG_ECDSA 1 #else -#undef MBEDTLS_ECDSA_C +#undef PSA_WANT_ALG_ECDSA #endif -/** - * \def MBEDTLS_ECJPAKE_C - * - * Enable the elliptic curve J-PAKE library. - * - * \warning This is currently experimental. EC J-PAKE support is based on the - * Thread v1.0.0 specification; incompatible changes to the specification - * might still happen. For this reason, this is disabled by default. - * - * Module: library/ecjpake.c - * Caller: - * - * This module is used by the following key exchanges: - * ECJPAKE - * - * Requires: MBEDTLS_ECP_C and MBEDTLS_MD_C - * - */ -#ifdef CONFIG_MBEDTLS_ECJPAKE_C -#define MBEDTLS_ECJPAKE_C -#else -#undef MBEDTLS_ECJPAKE_C -#endif - -/** - * \def MBEDTLS_ECP_C - * - * Enable the elliptic curve over GF(p) library. - * - * Module: library/ecp.c - * Caller: library/ecdh.c - * library/ecdsa.c - * library/ecjpake.c - * - * Requires: MBEDTLS_BIGNUM_C and at least one MBEDTLS_ECP_DP_XXX_ENABLED - */ +/* MBEDTLS_ECP_C is deprecated in mbedtls 4.x - use PSA ECC key types instead */ #ifdef CONFIG_MBEDTLS_ECP_C -#define MBEDTLS_ECP_C +#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC 1 +#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT 1 +#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT 1 +#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE 1 +#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE 1 +#define PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY 1 #else -#undef MBEDTLS_ECP_C +#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC +#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT +#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT +#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE +#undef PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE +#undef PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY #endif /** @@ -2563,10 +2512,16 @@ * Requires: MBEDTLS_BIGNUM_C, MBEDTLS_OID_C */ #ifdef CONFIG_MBEDTLS_RSA_C -#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR 1 +#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC 1 +#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT 1 +#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT 1 +#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE 1 #define PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY 1 #else -#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR +#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC +#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT +#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT +#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE #undef PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY #endif diff --git a/examples/openthread/ot_br/sdkconfig.defaults b/examples/openthread/ot_br/sdkconfig.defaults index 4fc9ff7f751..f0f8e7f5894 100644 --- a/examples/openthread/ot_br/sdkconfig.defaults +++ b/examples/openthread/ot_br/sdkconfig.defaults @@ -14,7 +14,6 @@ CONFIG_MBEDTLS_SSL_PROTO_DTLS=y CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=y # end of TLS Key Exchange Methods -CONFIG_MBEDTLS_ECJPAKE_C=y # end of mbedTLS # diff --git a/examples/openthread/ot_cli/sdkconfig.defaults b/examples/openthread/ot_cli/sdkconfig.defaults index eabd3d39628..13f8537d33e 100644 --- a/examples/openthread/ot_cli/sdkconfig.defaults +++ b/examples/openthread/ot_cli/sdkconfig.defaults @@ -13,7 +13,6 @@ CONFIG_PARTITION_TABLE_MD5=y # CONFIG_MBEDTLS_SSL_PROTO_DTLS=y CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=y -CONFIG_MBEDTLS_ECJPAKE_C=y # end of mbedTLS # diff --git a/examples/openthread/ot_sleepy_device/deep_sleep/sdkconfig.defaults b/examples/openthread/ot_sleepy_device/deep_sleep/sdkconfig.defaults index 416e9349fb2..8a57ae889c4 100644 --- a/examples/openthread/ot_sleepy_device/deep_sleep/sdkconfig.defaults +++ b/examples/openthread/ot_sleepy_device/deep_sleep/sdkconfig.defaults @@ -11,7 +11,6 @@ CONFIG_PARTITION_TABLE_FILENAME="partitions.csv" # CONFIG_MBEDTLS_SSL_PROTO_DTLS=y CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=y -CONFIG_MBEDTLS_ECJPAKE_C=y # end of mbedTLS # diff --git a/examples/openthread/ot_sleepy_device/light_sleep/sdkconfig.defaults b/examples/openthread/ot_sleepy_device/light_sleep/sdkconfig.defaults index 03acbcb41c0..2b8111f6abf 100644 --- a/examples/openthread/ot_sleepy_device/light_sleep/sdkconfig.defaults +++ b/examples/openthread/ot_sleepy_device/light_sleep/sdkconfig.defaults @@ -11,7 +11,6 @@ CONFIG_PARTITION_TABLE_FILENAME="partitions.csv" # CONFIG_MBEDTLS_SSL_PROTO_DTLS=y CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=y -CONFIG_MBEDTLS_ECJPAKE_C=y # end of mbedTLS # diff --git a/examples/openthread/ot_trel/sdkconfig.defaults b/examples/openthread/ot_trel/sdkconfig.defaults index 367f2d10ced..1232a900b11 100644 --- a/examples/openthread/ot_trel/sdkconfig.defaults +++ b/examples/openthread/ot_trel/sdkconfig.defaults @@ -13,7 +13,6 @@ CONFIG_PARTITION_TABLE_MD5=y # CONFIG_MBEDTLS_SSL_PROTO_DTLS=y CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=y -CONFIG_MBEDTLS_ECJPAKE_C=y # end of mbedTLS #