Commit Graph
741 Commits
Author SHA1 Message Date
Ashish Sharma cfae960f2e feat(mbedtls): add option to choose constant-time prime generation 2026-07-21 16:03:27 +08:00
Ashish Sharma 1646e69781 feat(mbedtls): update to version 3.6.7 2026-07-21 15:47:46 +08:00
Mahavir Jain dec92ae69a Merge branch 'fix/ecdsa_ecc_hw_input_validation_v5.4' into 'release/v5.4'
Validate ECDSA signature range and harden ECC memory power-down (v5.4)

See merge request espressif/esp-idf!49444
2026-06-23 11:29:49 +05:30
harshal.patil 551fad393d test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-06-22 11:17:50 +05:30
harshal.patilandAshish Sharma abcbe87e2d fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down
Co-Authored-By: Ashish Sharma <ashish.sharma@espressif.com>
2026-06-22 11:17:50 +05:30
Kapil Gupta 9ce6228b0f fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-22 09:01:18 +05:30
Kapil Gupta e9586fa03a fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-22 09:01:18 +05:30
Ashish Sharma 385c1f5d8e fix(mbedtls): fixes build failure with clang21
Closes https://github.com/espressif/esp-idf/issues/18456
2026-06-09 14:04:22 +08:00
Jiang Guang Ming 1c9d738fde fix(mbedtls): fix ROM mbedTLS threading alt issues 2026-05-19 15:51:19 +08:00
Ashish Sharma f5d24a7e91 fix(protocomm): fixes potential issues that can lead to crash during device provisioning 2026-04-29 16:22:24 +08:00
Ashish Sharma 832fbe67e8 change(mbedtls): adds CVE-2025-66442 to exclude list.
The CVE is applicable with Clang using LLVM's select-optimize feature. ESP-IDF uses GCC as default compiler and sets -Os as the default optimisation flag
2026-04-27 14:11:34 +08:00
Ashish Sharma 6449eaeeab feat(mbedtls): update to version 3.6.6 2026-04-07 10:31:58 +08:00
Evgeny Torbin f7395255da test: format all test scripts 2026-03-11 07:34:34 +01:00
harshal.patil dff987476b fix(mbedlts/aes): Ensure cache coherency when DMA writes to cacheable PSRAM buffers 2026-01-14 11:22:20 +05:30
Mahavir Jain a0e8f64199 Merge branch 'feat/update_mbedtls_3.6.5_v5.4' into 'release/v5.4'
feat(mbedtls): update to version 3.6.5 (v5.4)

See merge request espressif/esp-idf!43245
2025-11-18 09:41:14 +05:30
Ashish Sharma 0f639a9c8b feat(mbedtls): update to version 3.6.5 2025-11-11 16:48:46 +08:00
Kapil Gupta 3cf1f74776 fix(mbedtls): Addressed comments on PR15679 2025-10-06 11:27:16 +05:30
Deomid rojer Ryabkov f04b08af12 feat(mbedtls): Add mbedtls_esp_random()
Suitable for passing as f_rng to various Mbed-TLS APIs that require it
2025-10-06 11:27:15 +05:30
harshal.patil 93473a0558 change(mbedtls/ecdsa): The ECDSA module of ESP32-H2 ECO5 does not use MPI module 2025-08-13 20:38:12 +05:30
harshal.patil e761d83cf8 fix(mbedtls/gcm): Allow enabling GCM fallback only if software GCM is available 2025-07-25 08:48:16 +05:30
Mahavir Jain a1b7cc9f65 Merge branch 'feature/support_ds_peripheral_rsa_decryption_v5.4' into 'release/v5.4'
feat(mbedtls): Add support for RSA decryption with DS peripheral (v5.4)

See merge request espressif/esp-idf!40450
2025-07-22 10:36:14 +05:30
Jiang Jiang Jian e839ed589c Merge branch 'feature/enable_support_for_deterministic_mode_and_ecdsa_192_v5.4' into 'release/v5.4'
enable support for deterministic mode and ecdsa 192 in ESP32H2 (v5.4)

See merge request espressif/esp-idf!39541
2025-07-11 13:47:39 +08:00
Ashish Sharma 89fa1559d9 feat(mbedtls): adds support for RSA decryption with DS peripheral 2025-07-10 11:29:44 +08:00
nilesh.kale cebbedbac2 feat: enable support for deterministic mode for esp32h2 2025-07-09 13:05:56 +08:00
nilesh.kale 497fc7ed18 feat: enabled ECDSA-P192 support for ESP32H2 2025-07-09 13:05:56 +08:00
Ashish Sharma 98fa9a3829 feat(mbedtls): update to version 3.6.4 2025-07-04 17:36:08 +08:00
Mahavir Jain 858a988d6e Merge branch 'feat/adding_different_strategy_to_perform_tls_using_dynamic_feature_v5.4' into 'release/v5.4'
Add configuration to control dynamic buffer strategy in mbedtls (v5.4)

See merge request espressif/esp-idf!39920
2025-06-27 10:42:24 +05:30
Mahavir Jain 72775cd61c Merge branch 'fix/suppress_cert_bundle_serial_number_warning_v5.4' into 'release/v5.4'
fix(mbedtls/esp_crt_bundle): Suppress non-negative serial number warning (v5.4)

See merge request espressif/esp-idf!39402
2025-06-26 13:39:08 +05:30
hrushikesh.bhosale d7b3e3b978 feat(mbedtls): Add configuration to control dynamic buffer strategy in mbedtls
Problem:
1. In low-memory scenarios, the dynamic buffer feature can fail due to memory fragmentation.
2. It requires a contiguous 16KB heap chunk, but continuous allocation and deallocation of
the RX buffer can lead to fragmentation.
3. If another component allocates memory between these operations, it can break up the
available 16KB block, causing allocation failure.

Solution:
1. Introduce configurable strategy for using dynamic buffers in TLS connections.
2. For example, convert RX buffers to static after the TLS handshake.
3. Allow users to select the strategy via a new field in the esp_http_client_cfg_t structure.
4. The strategy can be controlled independently for each TLS session.
2025-06-26 12:22:44 +05:30
wanckl ea03622621 ci(esp32c61): remove c61 support from readme on 5.4 2025-06-17 15:09:40 +08:00
harshal.patilandMahavir Jain f81c69eabc fix(mbedtls/esp_crt_bundle): Suppress non-negative serial number warning
Co-authored-by: Mahavir Jain <mahavir.jain@espressif.com>
2025-05-26 13:34:38 +05:30
Jiang Jiang Jian 45d95b1bd8 Merge branch 'fix/fix_esp32p4_retention_cost_v5.4' into 'release/v5.4'
fix(esp_hw_support): optimize retention cost and update sleep time compensation (v5.4)

See merge request espressif/esp-idf!38744
2025-05-06 14:18:49 +08:00
harshal.patil 05353d8d8f fix(mbedtls): Fix config dependencies when ROM mbedtls is used 2025-04-29 10:53:06 +05:30
wuzhenghui 33aca83c63 change(ci): remove esp32c5 from readme since esp32c5 skipped CI build 2025-04-25 17:13:27 +08:00
Ashish Sharma 605206b69f feat(mbedtls): new config to allow weak cert verification 2025-04-16 09:50:24 +08:00
Ashish Sharma 7578913742 feat(mbedtls): update to version 3.6.3 2025-04-16 09:50:24 +08:00
harshal.patil 96f48cd1cf feat(mbedtls): Make mbedtls SHA1 support configurable 2025-04-01 12:40:55 +05:30
Ashish Sharma a83a0ab02b fix(component/mbedtls): Adds github root cert to cmn_crt_authorities.csv 2025-03-18 14:36:18 +08:00
Aditya Patwardhan b301e03f57 feat(docs): Update minimizing binary size
The ESP32-H2 software countermeasure may not be necessary
        for ESP32-H2 v1.2 and above, this commit updates
        the relevant documentation
2025-02-20 21:03:10 +08:00
Aditya Patwardhan 2ff128ebf4 fix(soc): Fixed ECDSA register compatibility 2025-02-20 21:03:10 +08:00
Aditya Patwardhan 3bcafe77d8 fix(hal): Make the ECDSA countermeasure dynamically applicable
This commit makes the ECDSA countermeasure dynamically applicable
    across different revisions of the ESP32H2 SoC.
2025-02-20 21:03:10 +08:00
Mahavir Jain 748d29b5ad feat(ecc): enable ECC constant time mode for ESP32-H2 ECO5 2025-02-20 21:03:10 +08:00
harshal.patil 7d803e661e feat(hal/aes): Enable pseudo rounds function during AES operations 2025-01-21 12:28:23 +05:30
harshal.patil e0312feddb fix(mbedtls/aes): Fix external memory corruption caused due to unaligned length cache sync
Fixes the memory corruption issue that arises due to external memory cache sync of unaligned
length bytes when L2 cache line size is greater than the L1 cache line size
2024-11-21 12:15:57 +05:30
Harshal Patil 27f11f87f5 Merge branch 'feat/mbedtls_size_optimization' into 'master'
Fix the increase in build size of mbedtls while upgrading to v3.x

See merge request espressif/esp-idf!34179
2024-10-26 01:20:40 +08:00
harshal.patil 4cdfdac18c fix(mbedtls): Fix the increase in build size of mbedtls when upgrading to v3.x 2024-10-24 14:45:57 +05:30
harshal.patil c2b71a3855 ci(mbedtls): Fix component dependencies for security-related test apps 2024-10-24 14:45:56 +05:30
nilesh.kale 854101959d feat: enable security related testcases for c5 and c61 2024-10-21 14:24:36 +05:30
nilesh.kale dacb9a57cb feat(mbedtls): update mbedtls version to 3.6.2 2024-10-18 11:59:31 +05:30
harshal.patilandHanno 3957e59f1a feat(mbedtls/esp_crt_bundle): Move dummy cert to .rodata to save 408B from dram
Co-authored-by: Hanno <h.binder@web.de>
2024-10-16 16:21:28 +05:30