Ashish Sharma
cfae960f2e
feat(mbedtls): add option to choose constant-time prime generation
2026-07-21 16:03:27 +08:00
Ashish Sharma
1646e69781
feat(mbedtls): update to version 3.6.7
2026-07-21 15:47:46 +08:00
Mahavir Jain
dec92ae69a
Merge branch 'fix/ecdsa_ecc_hw_input_validation_v5.4' into 'release/v5.4'
...
Validate ECDSA signature range and harden ECC memory power-down (v5.4)
See merge request espressif/esp-idf!49444
2026-06-23 11:29:49 +05:30
harshal.patil
551fad393d
test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver
2026-06-22 11:17:50 +05:30
harshal.patil and Ashish Sharma
abcbe87e2d
fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down
...
Co-Authored-By: Ashish Sharma <ashish.sharma@espressif.com >
2026-06-22 11:17:50 +05:30
Kapil Gupta
9ce6228b0f
fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
...
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-22 09:01:18 +05:30
Kapil Gupta
e9586fa03a
fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
...
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-22 09:01:18 +05:30
Ashish Sharma
385c1f5d8e
fix(mbedtls): fixes build failure with clang21
...
Closes https://github.com/espressif/esp-idf/issues/18456
2026-06-09 14:04:22 +08:00
Jiang Guang Ming
1c9d738fde
fix(mbedtls): fix ROM mbedTLS threading alt issues
2026-05-19 15:51:19 +08:00
Ashish Sharma
f5d24a7e91
fix(protocomm): fixes potential issues that can lead to crash during device provisioning
2026-04-29 16:22:24 +08:00
Ashish Sharma
832fbe67e8
change(mbedtls): adds CVE-2025-66442 to exclude list.
...
The CVE is applicable with Clang using LLVM's select-optimize feature. ESP-IDF uses GCC as default compiler and sets -Os as the default optimisation flag
2026-04-27 14:11:34 +08:00
Ashish Sharma
6449eaeeab
feat(mbedtls): update to version 3.6.6
2026-04-07 10:31:58 +08:00
Evgeny Torbin
f7395255da
test: format all test scripts
2026-03-11 07:34:34 +01:00
harshal.patil
dff987476b
fix(mbedlts/aes): Ensure cache coherency when DMA writes to cacheable PSRAM buffers
2026-01-14 11:22:20 +05:30
Mahavir Jain
a0e8f64199
Merge branch 'feat/update_mbedtls_3.6.5_v5.4' into 'release/v5.4'
...
feat(mbedtls): update to version 3.6.5 (v5.4)
See merge request espressif/esp-idf!43245
2025-11-18 09:41:14 +05:30
Ashish Sharma
0f639a9c8b
feat(mbedtls): update to version 3.6.5
2025-11-11 16:48:46 +08:00
Kapil Gupta
3cf1f74776
fix(mbedtls): Addressed comments on PR15679
2025-10-06 11:27:16 +05:30
Deomid rojer Ryabkov
f04b08af12
feat(mbedtls): Add mbedtls_esp_random()
...
Suitable for passing as f_rng to various Mbed-TLS APIs that require it
2025-10-06 11:27:15 +05:30
harshal.patil
93473a0558
change(mbedtls/ecdsa): The ECDSA module of ESP32-H2 ECO5 does not use MPI module
2025-08-13 20:38:12 +05:30
harshal.patil
e761d83cf8
fix(mbedtls/gcm): Allow enabling GCM fallback only if software GCM is available
2025-07-25 08:48:16 +05:30
Mahavir Jain
a1b7cc9f65
Merge branch 'feature/support_ds_peripheral_rsa_decryption_v5.4' into 'release/v5.4'
...
feat(mbedtls): Add support for RSA decryption with DS peripheral (v5.4)
See merge request espressif/esp-idf!40450
2025-07-22 10:36:14 +05:30
Jiang Jiang Jian
e839ed589c
Merge branch 'feature/enable_support_for_deterministic_mode_and_ecdsa_192_v5.4' into 'release/v5.4'
...
enable support for deterministic mode and ecdsa 192 in ESP32H2 (v5.4)
See merge request espressif/esp-idf!39541
2025-07-11 13:47:39 +08:00
Ashish Sharma
89fa1559d9
feat(mbedtls): adds support for RSA decryption with DS peripheral
2025-07-10 11:29:44 +08:00
nilesh.kale
cebbedbac2
feat: enable support for deterministic mode for esp32h2
2025-07-09 13:05:56 +08:00
nilesh.kale
497fc7ed18
feat: enabled ECDSA-P192 support for ESP32H2
2025-07-09 13:05:56 +08:00
Ashish Sharma
98fa9a3829
feat(mbedtls): update to version 3.6.4
2025-07-04 17:36:08 +08:00
Mahavir Jain
858a988d6e
Merge branch 'feat/adding_different_strategy_to_perform_tls_using_dynamic_feature_v5.4' into 'release/v5.4'
...
Add configuration to control dynamic buffer strategy in mbedtls (v5.4)
See merge request espressif/esp-idf!39920
2025-06-27 10:42:24 +05:30
Mahavir Jain
72775cd61c
Merge branch 'fix/suppress_cert_bundle_serial_number_warning_v5.4' into 'release/v5.4'
...
fix(mbedtls/esp_crt_bundle): Suppress non-negative serial number warning (v5.4)
See merge request espressif/esp-idf!39402
2025-06-26 13:39:08 +05:30
hrushikesh.bhosale
d7b3e3b978
feat(mbedtls): Add configuration to control dynamic buffer strategy in mbedtls
...
Problem:
1. In low-memory scenarios, the dynamic buffer feature can fail due to memory fragmentation.
2. It requires a contiguous 16KB heap chunk, but continuous allocation and deallocation of
the RX buffer can lead to fragmentation.
3. If another component allocates memory between these operations, it can break up the
available 16KB block, causing allocation failure.
Solution:
1. Introduce configurable strategy for using dynamic buffers in TLS connections.
2. For example, convert RX buffers to static after the TLS handshake.
3. Allow users to select the strategy via a new field in the esp_http_client_cfg_t structure.
4. The strategy can be controlled independently for each TLS session.
2025-06-26 12:22:44 +05:30
wanckl
ea03622621
ci(esp32c61): remove c61 support from readme on 5.4
2025-06-17 15:09:40 +08:00
harshal.patil and Mahavir Jain
f81c69eabc
fix(mbedtls/esp_crt_bundle): Suppress non-negative serial number warning
...
Co-authored-by: Mahavir Jain <mahavir.jain@espressif.com >
2025-05-26 13:34:38 +05:30
Jiang Jiang Jian
45d95b1bd8
Merge branch 'fix/fix_esp32p4_retention_cost_v5.4' into 'release/v5.4'
...
fix(esp_hw_support): optimize retention cost and update sleep time compensation (v5.4)
See merge request espressif/esp-idf!38744
2025-05-06 14:18:49 +08:00
harshal.patil
05353d8d8f
fix(mbedtls): Fix config dependencies when ROM mbedtls is used
2025-04-29 10:53:06 +05:30
wuzhenghui
33aca83c63
change(ci): remove esp32c5 from readme since esp32c5 skipped CI build
2025-04-25 17:13:27 +08:00
Ashish Sharma
605206b69f
feat(mbedtls): new config to allow weak cert verification
2025-04-16 09:50:24 +08:00
Ashish Sharma
7578913742
feat(mbedtls): update to version 3.6.3
2025-04-16 09:50:24 +08:00
harshal.patil
96f48cd1cf
feat(mbedtls): Make mbedtls SHA1 support configurable
2025-04-01 12:40:55 +05:30
Ashish Sharma
a83a0ab02b
fix(component/mbedtls): Adds github root cert to cmn_crt_authorities.csv
2025-03-18 14:36:18 +08:00
Aditya Patwardhan
b301e03f57
feat(docs): Update minimizing binary size
...
The ESP32-H2 software countermeasure may not be necessary
for ESP32-H2 v1.2 and above, this commit updates
the relevant documentation
2025-02-20 21:03:10 +08:00
Aditya Patwardhan
2ff128ebf4
fix(soc): Fixed ECDSA register compatibility
2025-02-20 21:03:10 +08:00
Aditya Patwardhan
3bcafe77d8
fix(hal): Make the ECDSA countermeasure dynamically applicable
...
This commit makes the ECDSA countermeasure dynamically applicable
across different revisions of the ESP32H2 SoC.
2025-02-20 21:03:10 +08:00
Mahavir Jain
748d29b5ad
feat(ecc): enable ECC constant time mode for ESP32-H2 ECO5
2025-02-20 21:03:10 +08:00
harshal.patil
7d803e661e
feat(hal/aes): Enable pseudo rounds function during AES operations
2025-01-21 12:28:23 +05:30
harshal.patil
e0312feddb
fix(mbedtls/aes): Fix external memory corruption caused due to unaligned length cache sync
...
Fixes the memory corruption issue that arises due to external memory cache sync of unaligned
length bytes when L2 cache line size is greater than the L1 cache line size
2024-11-21 12:15:57 +05:30
Harshal Patil
27f11f87f5
Merge branch 'feat/mbedtls_size_optimization' into 'master'
...
Fix the increase in build size of mbedtls while upgrading to v3.x
See merge request espressif/esp-idf!34179
2024-10-26 01:20:40 +08:00
harshal.patil
4cdfdac18c
fix(mbedtls): Fix the increase in build size of mbedtls when upgrading to v3.x
2024-10-24 14:45:57 +05:30
harshal.patil
c2b71a3855
ci(mbedtls): Fix component dependencies for security-related test apps
2024-10-24 14:45:56 +05:30
nilesh.kale
854101959d
feat: enable security related testcases for c5 and c61
2024-10-21 14:24:36 +05:30
nilesh.kale
dacb9a57cb
feat(mbedtls): update mbedtls version to 3.6.2
2024-10-18 11:59:31 +05:30
harshal.patil and Hanno
3957e59f1a
feat(mbedtls/esp_crt_bundle): Move dummy cert to .rodata to save 408B from dram
...
Co-authored-by: Hanno <h.binder@web.de >
2024-10-16 16:21:28 +05:30