Commit Graph
159 Commits
Author SHA1 Message Date
Aditya Patwardhan 9c1dcca1af fix(esp-tls): address MR review comments for SE PSA driver
- esp_tls_mbedtls: require cert when PSA-backed server/client key is set
- esp_tls_mbedtls: drop redundant pk_init/x509_crt_init (calloc handles it)
- psa SE driver: copy callbacks/opaque_key by value (no lifetime coupling)
- psa SE driver: replace atomic CAS with simple null check on register
- psa SE driver: use sig_len from sign callback with bounds validation
- psa SE driver: validate pubkey_len returned by export_pubkey callback
- psa SE driver: check hash sub-alg in RSA PKCS1V15 branch of validate_request
- psa SE driver: align secure_element_register_callbacks doc with value-copy impl
- esp_https_server: initialize server_key in HTTPD_SSL_CONFIG_DEFAULT
- mbedtls: move SECURE_ELEMENT_DRIVER_ENABLED to esp_config.h for parity
  with ESP_ECDSA_DRIVER_ENABLED; drop target_compile_definitions
- docs: fix esp_tls_cfg_t -> esp_http_client_config_t cross-reference
- docs: check psa_import_key() status in ESP-TLS PSA example
- hints/error_output: point at CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED

(cherry picked from commit 08b567ef3b)
2026-07-09 11:17:02 +05:30
Aditya Patwardhan e889a304c5 feat(mbedtls): Add PSA Crypto driver for external secure elements
Add generic secure element PSA driver with runtime callback registration.
Consolidate Kconfig into single MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED option.

Closes https://github.com/espressif/esp-idf/issues/18388

(cherry picked from commit 1c20f525b4)
2026-07-09 11:14:15 +05:30
Ashish Sharma 9ad041cc8c fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:38 +08:00
harshal.patil 3c4586abff feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-07-03 10:25:48 +05:30
Jiang Guang Ming dd28e303d5 fix(mbedtls): support ROM mbedTLS crypto in bootloader 2026-05-25 10:08:25 +08:00
Jiang Guang Ming 6eb7f181a2 feat(mbedtls): enable ROM mbedTLS pytest with esp32c2 rev2.0 2026-05-25 10:07:47 +08:00
Jiang Guang Ming 6ae3fa39f4 feat(mbedtls): enable ESP32-C2(Rev2.0) ROM crypto for PSA 2026-05-25 10:04:10 +08:00
Jiang Jiang Jian 6d6aa6cccd Merge branch 'fix/fix_https_server_linux_build_v6.0' into 'release/v6.0'
fix(https_server): fixes failing example build for linux target (v6.0)

See merge request espressif/esp-idf!48205
2026-05-12 18:07:17 +08:00
Ashish Sharma 1d0cdd5602 fix(https_server): fixes failing example build for linux target 2026-05-10 19:29:25 +08:00
Ashish Sharma b86a1231fb feat(mbedtls): update to version 4.1.1 2026-05-10 19:16:12 +08:00
Guillaume Souchere ed9eefd94b fix(mbedtls): compile esp_mem.c in IDF component lib instead of builtin target
esp_mem.c in the builtin target via
target_sources(builtin PRIVATE ...) called from the parent CMakeLists.
This cross-directory source injection causes CMake's Ninja generator on
Windows to produce unstable TARGET_PDB/RSP_FILE paths across
reconfigures, changing the ninja command hash and forcing a re-archive
of libmbed-builtin.a on every cmake run — even when no source changed.
This broke test_rebuild_source_files.

Fix by adding esp_mem.c to the IDF mbedtls component library
(mbedtls_srcs) instead. The final ELF link uses --start-group, so
builtin's platform.o resolves esp_mbedtls_mem_calloc/free from the
component library regardless of archive order. esp_mem.c is IDF-specific
code (heap_caps_calloc, sdkconfig.h) and belongs in the port layer, not
in any submodule target.
2026-05-04 09:02:53 +02:00
Mahavir Jain 63be46ed3d Merge branch 'fix/mbedtls_disable_default_configs_v6.0' into 'release/v6.0'
change(mbedTLS): update mbedTLS default configs (v6.0)

See merge request espressif/esp-idf!45699
2026-02-12 11:34:33 +05:30
Ashish Sharma 397c689548 fix: make the PSA compile definitions public 2026-02-11 18:04:56 +08:00
Ashish Sharma 0aef47a07e change(mbedtls): rename builtin to mbed-builtin 2026-02-11 18:04:56 +08:00
Ashish Sharma 7418a91d3e feat: adds DS Sign capabilities for ESP32S2 2026-02-06 16:09:41 +08:00
Ashish Sharma b1f14d19d0 feat: adds new Kconfig variable for DS peripheral 2026-02-06 16:09:41 +08:00
Ashish Sharma 93349d05b2 feat: adds PSA DS driver support 2026-02-06 16:09:41 +08:00
harshal.patil de7f8c88b2 fix(mbedtls): Make the driver define macros public to allow application access
- Also, use the PSA HMAC opaque key interface for HMAC-PBKDF2
2026-02-02 10:51:31 +05:30
harshal.patil 3163ed4167 feat(mbedtls): Introduce ESP-HMAC PSA opaque driver 2026-02-02 10:51:30 +05:30
harshal.patil 4d2e7fb4d3 fix(mbedtls): Enable h/w accel for CMAC and HMAC operations
- Refactor ESP-MAC drivers
2026-02-02 10:51:30 +05:30
harshal.patil 5c55790f54 feat(mbedtls/ecdsa): Introduce PSA ECDSA driver 2026-01-31 10:59:11 +05:30
Mahavir Jain ee2da28726 Merge branch 'feat/esp_tee_backports_v6.0' into 'release/v6.0'
feat(esp_tee): Feature/fixes backports to `release/v6.0`

See merge request espressif/esp-idf!45095
2026-01-31 10:27:34 +05:30
morris db750dc1a0 feat(dma): graduate the dma driver from esp_hw_support to esp_driver_dma 2026-01-29 14:41:14 +08:00
Laukik Hase 1752290f02 feat(esp_tee): Migrate TEE attestation to the PSA interface 2026-01-29 11:49:15 +05:30
Ferdinand Bachmann f4efb00ecd fix(cmake): Set CACHE variables correctly
The syntax for setting cache variables is actually
set(<variable> <value> CACHE <type> <docstring>) and not
set(<variable> CACHE <type> <value>).

The previous code silently set the variables to the empty string.
2026-01-23 11:40:16 +05:30
Ashish Sharma 933dd7e02f feat: adds PSA MD5 driver support 2026-01-09 13:56:03 +05:30
harshal.patil 3c4dadff0b fix(mbedtls): Support partial hardware AES-GCM and s/w fallback for non-AES ciphers
- Support software-fallback for unsupported hardware AES lengths
2026-01-09 13:55:51 +05:30
Mahavir Jain 1f0ce0524c fix(mbedtls): misc updates post PSA crypto migration 2026-01-05 14:54:33 +05:30
Ashish Sharma b02538834c fix: resolves MR comments 2025-12-20 23:02:25 +08:00
Ashish Sharma 5d5ba9d008 fix: migrate PSA SHA driver to be similar to parallel engine port 2025-12-19 11:06:41 +08:00
Ashish Sharma 76287081ea feat: code cleanup 2025-12-19 07:29:43 +08:00
Ashish Sharma c2c31ba9d2 fix(wpa_supplicant): revert changes to dpp_crypto 2025-12-19 07:29:08 +08:00
Ashish SharmaandMahavir Jain 06d03e1a12 feat: add NVS based secure storage layer for PSA
(cherry picked from commit 31c7bad7f74ce8e54ea0563b670df37a58215600)

Co-authored-by: Mahavir Jain <mahavir@espressif.com>
2025-12-19 07:29:00 +08:00
Ashish Sharma f306dbea84 feat(mbedtls): migrates ESP-TEE with PSA APIs 2025-12-19 07:28:33 +08:00
Ashish Sharma c47caf4f0a feat(mbedtls): adds mbedtls alt drivers with PSA 2025-12-19 07:28:33 +08:00
Ashish Sharma b8a738e0c4 feat(mbedtls): adds SHA drivers with PSA 2025-12-19 07:28:32 +08:00
Ashish Sharma 7d17e8a024 feat(mbedtls): adds AES drivers with PSA 2025-12-19 07:28:28 +08:00
Ashish Sharma e629ab299c feat(mbedtls): adds SHA drivers with PSA 2025-12-19 07:27:59 +08:00
Ashish Sharma bf46351fb0 feat(mbedtls): fix build errors with PSA migration 2025-12-19 07:27:54 +08:00
Ashish Sharma a088d2ccdc feat(mbedtls): fix build errors with PSA migration 2025-12-18 21:18:58 +08:00
Ashish Sharma b0da66f7e1 feat(bt): migrate mbedtls to PSA APIs 2025-12-18 21:18:58 +08:00
Ashish Sharma b4fea9cccc feat(lwip): migrate to to PSA API interface 2025-12-18 21:18:58 +08:00
harshal.patil 10cefdd975 fix(mbedtls/port): Align AES and SHA DMA buffers to 16 when SPIRAM encryption is enabled
- Targets that support GDMA and MSPI encryption module need data and addresses aligned to 16
2025-11-11 17:39:39 +05:30
Frantisek Hrbata a82016927f fix(mbedtls/cmake): handle lwip dependency in cmakev2
Currently, the lwip is linked to mbedtls if CONFIG_LWIP_ENABLE is set.
This approach works in cmakev1 because only the configuration for
BUILD_COMPONENTS is available during component evaluation. However, this
is not the case in cmakev2, where the configuration for all components
is available. This means that even if CONFIG_LWIP_ENABLE is set, it does
not guarantee that the lwip component is included in the build. For
cmakev2, modify the check to use a generator expression to ensure that
lwip is linked to mbedtls only if lwip is actually included in the
build.

Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>
2025-11-04 07:48:14 +01:00
harshal.patil 8992f08bef feat(mbedtls/aes): Add config to support AES block and DMA modes during runtime
- Dynamically switch the AES operation modes based on the buffer operating length
- Shorter AES and SHA operations can now run faster and concurrently as well

Closes https://github.com/espressif/esp-idf/issues/15914
2025-09-20 10:55:07 +05:30
Laukik Hase c152663408 feat(esp_tee): Added support for PBKDF2-based (HMAC) ECDSA signing 2025-09-19 12:06:02 +05:30
harshal.patil 55e0730a8d change(esp_hw_support): Move security-related modules to the esp_security component
- Also adds support to whitelist target specific expected dependency violations
in check_dependencies.py
2025-08-04 11:43:01 +05:30
Mahavir Jain 8096a2a295 Merge branch 'feat/mbedtls_no_buffer_alloc_on_session_reset' into 'master'
feat(mbedtls): disable unnecessary buffer allocation in dynamic buffer session reset

See merge request espressif/esp-idf!40126
2025-07-31 17:53:50 +05:30
Ashish Sharma d9c431268a feat(mbedtls): restructure mbedtls configuration page 2025-07-30 17:47:54 +08:00
Ashish Sharma 6259505f18 feat(mbedtls): disable unnecessary buffer allocation in dynamic buffer session reset 2025-07-30 17:45:16 +08:00