Kapil Gupta
c41dd724d4
fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
...
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-29 15:43:31 +08:00
Kapil Gupta
86f6192f10
fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
...
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-29 15:43:31 +08:00
Mahavir Jain
96008173aa
Merge branch 'fix/rsa_ds_driver_constant_time_v6.0' into 'release/v6.0'
...
Fix/rsa ds driver constant time (v6.0)
See merge request espressif/esp-idf!49699
2026-06-29 11:23:54 +05:30
Mahavir Jain
4163417ff1
Merge branch 'feat/support_rom_psa_mbedtls_v6.0' into 'release/v6.0'
...
feat(mbedtls): enable ESP32-C2(Rev2.0) ROM mbedTLS crypto for PSA (v6.0)
See merge request espressif/esp-idf!48843
2026-06-29 11:22:33 +05:30
Mahavir Jain
732111f75a
Merge branch 'feat/esp_tee_backports_v6.0' into 'release/v6.0'
...
feat(esp_tee): Feature/fixes backports to `release/v6.0`
See merge request espressif/esp-idf!48486
2026-06-29 11:21:13 +05:30
Mahavir Jain
e082ad95da
Merge branch 'fix/memory_leak_cross_signed_cert_verify_v6.0' into 'release/v6.0'
...
fix(esp_crt_bundle): fixes verification failures with cross signed certificates (v6.0)
See merge request espressif/esp-idf!48624
2026-06-29 11:17:37 +05:30
Ashish Sharma
f92ccb1348
fix(rsa_ds): make RSA-OAEP unpadding constant-time
2026-06-16 14:46:24 +08:00
Ashish Sharma
c313d339ab
fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time
2026-06-16 14:46:24 +08:00
Laukik Hase
39a4cf5e56
feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations
2026-06-12 10:04:07 +05:30
Laukik Hase
f37a2cd35b
feat(esp_tee): Remove unused components from the PSA Crypto library
2026-06-12 10:03:03 +05:30
harshal.patil
3195c942da
fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down
2026-06-09 15:02:59 +05:30
Jiang Jiang Jian
948a5277ef
Merge branch 'fix/fix_mbedtls_fs_io_psa_storage_v6.0' into 'release/v6.0'
...
fix(mbedtls): keep psa crypto storage enabled with ITS backend (v6.0)
See merge request espressif/esp-idf!48622
2026-06-03 16:44:19 +08:00
Ashish Sharma
a1f1d90729
fix(esp_crt_bundle): fixes verification with cross signed cert
2026-06-03 11:35:24 +08:00
Ashish Sharma
0d8ff68f8a
fix(esp_crt_bundle): fixes a potential memory leak with cross signed certificates
...
Closes https://github.com/espressif/esp-idf/issues/18512
Closes https://github.com/espressif/esp-idf/issues/18550
2026-06-03 11:31:27 +08:00
Jiang Jiang Jian
59032327db
Merge branch 'fix/mbedtls-psa-constant-time-and-zeroization_v6.0' into 'release/v6.0'
...
fix(mbedtls): use constant-time compare for MAC verify and zeroize key material (v6.0)
See merge request espressif/esp-idf!48729
2026-06-02 20:12:59 +08:00
Aditya Patwardhan
f77a7d16ec
fix(mbedtls): use constant-time compare and zeroize key material
...
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.
Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-30 23:15:44 +05:30
Aditya Patwardhan
4fb4dbda90
fix(mbedtls): correct inverted NULL check in esp_hmac_abort_opaque
...
esp_hmac_abort_opaque() had an inverted guard that called
mbedtls_platform_zeroize() on the context only when the context pointer
was NULL, dereferencing NULL and skipping cleanup of valid contexts.
Effect:
* Calling the abort path with a NULL pointer crashes (NULL write)
instead of being a safe no-op.
* The valid (non-NULL) HMAC opaque operation context is never zeroized
on abort, leaving sensitive intermediate HMAC state and key handle
references in operation memory until the buffer is overwritten or
freed.
Fix: invert the check so zeroization runs only when the context pointer
is non-NULL.
2026-05-30 23:15:42 +05:30
Jiang Jiang Jian
9d24b38a42
Merge branch 'fix/bring_back_ecjpake_config_v6.0' into 'release/v6.0'
...
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C (v6.0)
See merge request espressif/esp-idf!48623
2026-05-29 17:27:59 +08:00
Mahavir Jain
b31c2753bc
Merge branch 'fix/fix_psa_ecdsa_driver_missing_checks_v6.0' into 'release/v6.0'
...
fix(mbedtls): fixes missing check before ecdsa verify (v6.0)
See merge request espressif/esp-idf!48947
2026-05-28 21:05:31 +05:30
harshal.patil
40de3df854
test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver
2026-05-27 11:38:14 +05:30
Ashish Sharma
9de91ed9e5
fix(mbedtls): fixes missing check before ecdsa verify
2026-05-27 11:38:13 +05:30
Jiang Guang Ming
da5f99a518
fix(mbedtls): make threading implementation exclusive
...
Ensure the pthread and alternate threading implementations cannot be enabled at the same time.
2026-05-25 13:52:12 +08:00
Jiang Guang Ming
9320f709bd
feat(mbedtls): enable PSA threading alt with ROM mbedTLS
2026-05-25 10:08:33 +08:00
Jiang Guang Ming
dd28e303d5
fix(mbedtls): support ROM mbedTLS crypto in bootloader
2026-05-25 10:08:25 +08:00
Jiang Guang Ming
6eb7f181a2
feat(mbedtls): enable ROM mbedTLS pytest with esp32c2 rev2.0
2026-05-25 10:07:47 +08:00
Jiang Guang Ming
6ae3fa39f4
feat(mbedtls): enable ESP32-C2(Rev2.0) ROM crypto for PSA
2026-05-25 10:04:10 +08:00
Ashish Sharma
7f8dc336a6
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C
2026-05-18 14:56:18 +08:00
Ashish Sharma
94d456326c
fix(mbedtls): keep psa crypto storage enabled with ITS backend
...
Closes https://github.com/espressif/esp-idf/issues/18555
2026-05-18 14:51:53 +08:00
harshal.patil
d8808f90b9
test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app
2026-05-15 09:28:47 +05:30
harshal.patil
513efdf89a
refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps
2026-05-15 09:28:42 +05:30
harshal.patil
1d6b5f219e
feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver
2026-05-15 09:17:09 +05:30
Jiang Jiang Jian
6d6aa6cccd
Merge branch 'fix/fix_https_server_linux_build_v6.0' into 'release/v6.0'
...
fix(https_server): fixes failing example build for linux target (v6.0)
See merge request espressif/esp-idf!48205
2026-05-12 18:07:17 +08:00
Ashish Sharma
1d0cdd5602
fix(https_server): fixes failing example build for linux target
2026-05-10 19:29:25 +08:00
Ashish Sharma
04ec0ab538
feat(bootloader_support): remove P192 curve support
2026-05-10 19:16:12 +08:00
Ashish Sharma
5cc0eaaf9a
fix(esp_tee): optimise build size by removing unused configs
2026-05-10 19:16:12 +08:00
Ashish Sharma
eaac238545
fix(mbedtls): remove deprecated configs and migrate to PSA
2026-05-10 19:16:12 +08:00
Ashish Sharma
b86a1231fb
feat(mbedtls): update to version 4.1.1
2026-05-10 19:16:12 +08:00
Mahavir Jain
2eff46ca25
Merge branch 'fix/preserve_flash_layout_compatibiliy_of_hw_ecdsa_keys_psa_v6.0' into 'release/v6.0'
...
Persistent Storage Format for PSA Opaque ESP-Keys (v6.0)
See merge request espressif/esp-idf!47424
2026-05-07 10:17:43 +05:30
Mahavir Jain
954a2b3cbb
Merge branch 'fix/supported_key_mgr_key_types_check_v6.0' into 'release/v6.0'
...
fix(esp_security): guard key manager APIs against unsupported chip revs (v6.0)
See merge request espressif/esp-idf!48008
2026-05-07 10:13:25 +05:30
harshal.patil
1141c48750
change(mbedtls): Add tee key id length validation in the ESP-ECDSA PSA driver
2026-05-04 18:21:01 +05:30
harshal.patil
4f0915d7f6
test(mbedtls): Add a test for opaque HMAC driver verification
2026-05-04 18:21:01 +05:30
harshal.patil
c923685b0f
fix(mbedtls): Flash compatibility across multiple key sources (ECDSA, HMAC)
2026-05-04 18:21:00 +05:30
nilesh.kale
1f506e7a54
test(esp_security): re-enable crypto drivers test app for ESP32P4
...
Also remove common_components dep for security-related tests
2026-05-04 18:18:20 +05:30
Guillaume Souchere
ed9eefd94b
fix(mbedtls): compile esp_mem.c in IDF component lib instead of builtin target
...
esp_mem.c in the builtin target via
target_sources(builtin PRIVATE ...) called from the parent CMakeLists.
This cross-directory source injection causes CMake's Ninja generator on
Windows to produce unstable TARGET_PDB/RSP_FILE paths across
reconfigures, changing the ninja command hash and forcing a re-archive
of libmbed-builtin.a on every cmake run — even when no source changed.
This broke test_rebuild_source_files.
Fix by adding esp_mem.c to the IDF mbedtls component library
(mbedtls_srcs) instead. The final ELF link uses --start-group, so
builtin's platform.o resolves esp_mbedtls_mem_calloc/free from the
component library regardless of archive order. esp_mem.c is IDF-specific
code (heap_caps_calloc, sdkconfig.h) and belongs in the port layer, not
in any submodule target.
2026-05-04 09:02:53 +02:00
Ashish Sharma
0eef7b4d4e
fix(mbedtls): remove not required MBEDTLS_TLS_DISABLED config
...
Closes https://github.com/espressif/esp-idf/issues/18458
2026-04-27 14:54:19 +08:00
Mahavir Jain
7503c552f5
Merge branch 'fix/fix_protocomm_sec2_input_validations_v6.0' into 'release/v6.0'
...
fix(protocomm): fixes potential issues that can lead to crash during device provisioning (v6.0)
See merge request espressif/esp-idf!47305
2026-04-09 11:51:01 +05:30
Ashish Sharma
bda099031e
fix(mbedtls): reenable RSA 4096 bit key performance test
2026-04-09 10:26:10 +08:00
Ashish Sharma
9b4cacf9cb
fix(protocomm): fixes potential issues that can lead to crash during device provisioning
2026-04-07 11:09:37 +08:00
harshal.patil
ca3b9ca7d3
fix(mbedtls/rsa_ds): Preserve compatibility by reverting the modified esp_ds_data_ctx_t size
2026-03-26 14:06:07 +05:30
harshal.patil
2339834e4a
fix(esp_security): Enable Key Manager clocks even for efuse key operations
...
The Key Manager holds a key usage register, thus, the Key Manager peripheral
clock must be enabled even for efuses-based key operations to route the
crypto operations to correctly to the efuses (default is Key Manager)
2026-03-24 16:23:16 +05:30