Commit Graph
100 Commits
Author SHA1 Message Date
Aditya Patwardhan 70531b1a59 Merge branch 'update/version_6_0_2' into 'release/v6.0'
Update version to 6.0.2

See merge request espressif/esp-idf!49823
2026-06-25 07:36:34 +05:30
Aditya Patwardhan 7101770dc6 change(version): Update version to 6.0.2 2026-06-19 12:18:37 +05:50
Aditya Patwardhan f82a0593e0 Merge branch 'fix/secure_boot_bootloader_ecdsa_range_gate_v6.0' into 'release/v6.0'
Add ECDSA signature bounds check in bootloader before Secure Boot verify (v6.0)

See merge request espressif/esp-idf!49633
2026-06-19 11:51:09 +05:30
Aditya Patwardhan 839352f836 Merge branch 'fix/disable_secure_boot_v2_ecdsa_v6.0' into 'release/v6.0'
Fix/disable secure boot v2 ecdsa (v6.0)

See merge request espressif/esp-idf!49470
2026-06-11 07:48:52 +05:30
Aditya Patwardhan 94be07050f change(secure_boot): mark ECDSA based Secure Boot V2 as insecure on affected SoCs
ECDSA based Secure Boot V2 is not functional for certain input vectors on
ESP32-C5/C61/H2/P4 and on the preview targets ESP32-H4/H21. RSA based Secure
Boot V2 is the recommended scheme where the SoC supports it. This issue will be
fixed in a future hardware ECO revision; more details will be shared through the
hardware errata document.

A new hidden Kconfig option SECURE_BOOT_V2_ECDSA_INSECURE marks the affected
mass-production SoCs (ESP32-C5/C61/H2/P4). On these SoCs, when hardware Secure
Boot V2 is enabled, the ECDSA (V2) signing scheme is no longer offered by
default; it must be turned on explicitly via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
under "Allow potentially insecure options" (CONFIG_SECURE_BOOT_INSECURE). App
signing without hardware Secure Boot is not affected. Note that ESP32-C61 has no
RSA based Secure Boot V2, so it has no Secure Boot scheme enabled by default.

The preview targets ESP32-H4 and ESP32-H21 mark ECDSA Secure Boot V2 as not
supported in their SoC capabilities instead of using the option above. As
ESP32-H4 has no other Secure Boot V2 scheme, Secure Boot is disabled entirely on
it; ESP32-H21 retains RSA based Secure Boot V2.

The security documentation keeps the ECDSA Secure Boot V2 content visible and
adds a warning describing the limitation (including that ECDSA Secure Boot V2 on
ESP32-C61 is not recommended for production). CI apps that exercise ECDSA Secure
Boot V2 on the affected SoCs set CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
accordingly.
2026-06-10 18:06:48 +05:30
Aditya Patwardhan a66f301ca2 Merge branch 'fix/ecdsa_ecc_hw_input_validation_v6.0' into 'release/v6.0'
Validate ECDSA signature range and harden ECC memory power-down (v6.0)

See merge request espressif/esp-idf!49428
2026-06-10 18:06:25 +05:30
Aditya Patwardhan cb519ffe87 fix(esp_http_client): require https->https for cross-scheme redirects
esp_http_client_set_redirection() now rejects any redirect target whose
scheme is not https:// when the origin is HTTPS. This catches http, ftp,
ws and any other scheme before client state is mutated. Same-host /
https-to-https redirects are unaffected. Apps that intentionally want
mixed-scheme redirects can set disable_auto_redirect=true and handle
HTTP_EVENT_REDIRECT.
2026-05-30 23:15:48 +05:30
Aditya Patwardhan f77a7d16ec fix(mbedtls): use constant-time compare and zeroize key material
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.

Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-30 23:15:44 +05:30
Aditya Patwardhan 4fb4dbda90 fix(mbedtls): correct inverted NULL check in esp_hmac_abort_opaque
esp_hmac_abort_opaque() had an inverted guard that called
mbedtls_platform_zeroize() on the context only when the context pointer
was NULL, dereferencing NULL and skipping cleanup of valid contexts.

Effect:
* Calling the abort path with a NULL pointer crashes (NULL write)
  instead of being a safe no-op.
* The valid (non-NULL) HMAC opaque operation context is never zeroized
  on abort, leaving sensitive intermediate HMAC state and key handle
  references in operation memory until the buffer is overwritten or
  freed.

Fix: invert the check so zeroization runs only when the context pointer
is non-NULL.
2026-05-30 23:15:42 +05:30
Aditya Patwardhan 0004544536 fix(esp-tls): clarify skip_common_name and warn when SNI is disabled
The skip_common_name flag was named for the legacy CN field but actually
suppresses the entire mbedtls_ssl_set_hostname() call -- disabling
hostname matching against CN/SAN AND Server Name Indication. Update the
doxygen to describe the real effect, and emit a per-call WARN inside the
SNI-disable branch so debug-only use does not slip into production
unnoticed.
2026-05-26 19:12:27 +05:30
Aditya Patwardhan 15ac4697f3 fix(esp-tls): close CA-verification bypass during session resumption
The session-resumption else-if in set_client_config() short-circuited
the CA verification chain when only client_session was supplied. Remove
the branch so session-only configs fall through to the normal error /
skip-verify path; resumption no longer silently disables CA validation.
2026-05-26 19:12:27 +05:30
Aditya Patwardhan f7399e0069 fix(protocomm): pass current session id when closing existing session
sec1_new_session()/sec2_new_session() were calling sec*_close_session()
with the *new* session_id parameter instead of the existing
cur_session->id. The close handler validates `cur_session->id ==
session_id` before performing teardown, so the call always failed with
ESP_ERR_INVALID_STATE.

Effect: when a peer started a new provisioning session while another was
already active, the previous session's PSA keys, AES context, SRP handle
and username buffer were leaked instead of being destroyed. The cleared
session struct was overwritten by the new session, leaking the previous
key handles inside PSA Crypto and (for security2) leaking heap memory
for the username and SRP context.

Fix: pass cur_session->id so the close path actually executes the
teardown (psa_destroy_key/psa_cipher_abort/esp_srp_free/free) before the
new session takes over.
2026-05-20 12:37:18 +05:30
Aditya Patwardhan 58ae4daa56 Merge branch 'fix/pmp_drom_mask_read_only_v6.0' into 'release/v6.0'
fix(cpu_region_protect): set DROM mask PMP entry to read-only (v6.0)

See merge request espressif/esp-idf!47575
2026-05-12 16:15:49 +05:30
Aditya Patwardhan b723799c4e Merge branch 'fix/http_server_async_handler_connection_retry_v6.0' into 'release/v6.0'
fix(http_server/async_handler): Fix http_server async handler tests (backport v6.0)

See merge request espressif/esp-idf!47723
2026-05-08 13:33:34 +05:30
Aditya Patwardhan e1aa234ce4 Merge branch 'fix/ws_echo_server_uri_registration_race_v6.0' into 'release/v6.0'
fix(http_server/ws_echo_server): Fix ws_echo_server test URI registration race condition (backport v6.0)

See merge request espressif/esp-idf!47725
2026-05-08 13:32:47 +05:30
Aditya Patwardhan effe8923bc Merge branch 'fix/flipped_key_mgr_key_info_flash_position_v6.0' into 'release/v6.0'
Fix the flipped key info slot when deploying a Key Manager-based key (v6.0)

See merge request espressif/esp-idf!48159
2026-05-04 18:05:05 +05:30
Aditya Patwardhan 0e1e1e79aa fix(esp_tee): prevent validation clobbering and deref-before-check
TEE secure-service handlers had two bugs letting REE bypass
pointer-region validation:

1. valid_addr = instead of valid_addr &= in AEAD encrypt/decrypt
   and DS sign handlers, clobbering prior failed checks.
   Impact: REE writes to TEE DRAM via DS signature output, or reads
   TEE DRAM via AEAD output.

2. data->rsa_length dereferenced before data is validated in DS sign
   and DS start_sign handlers.

Fix: use &= for subsequent checks, add early return after initial
data pointer check in DS handlers.
2026-04-30 10:17:53 +05:30
Aditya Patwardhan 931888f3c3 Merge branch 'fix/fix_dynamic_buffer_with_tls1_3_v6.0' into 'release/v6.0'
fix: fixes failing dynamic buffer tests (v6.0)

See merge request espressif/esp-idf!46430
2026-03-19 20:21:58 +05:30
Aditya Patwardhan c8a92d52c3 Merge branch 'fix/add_ecdsa_curve_validation_during_secure_boot_v6.0' into 'release/v6.0'
fix(bootloader_support): added ecdsa curve validation during secure boot (v6.0)

See merge request espressif/esp-idf!46297
2026-03-19 19:46:00 +05:30
Aditya Patwardhan 4051f597ea Merge branch 'fix/fix_psa_sha_driver_macro_checks_v6.0' into 'release/v6.0'
fix(mbedtls): Gate PSA SHA driver on ACCEL flags instead of raw SOC caps (v6.0)

See merge request espressif/esp-idf!46739
2026-03-19 19:45:34 +05:30
Aditya Patwardhan 891ddca56e Merge branch 'feat/introduce_esp_rsa_ds_opaque_key_context_v6.0' into 'release/v6.0'
Extend opaque driver context to add Key recovery info (v6.0)

See merge request espressif/esp-idf!46074
2026-03-19 19:45:02 +05:30
Aditya Patwardhan 305b04da81 Merge branch 'feat/adds_option_to_save_response_headers_v6.0' into 'release/v6.0'
feat(esp_http_client): adds support to save response headers (v6.0)

See merge request espressif/esp-idf!45509
2026-03-19 19:44:27 +05:30
Aditya Patwardhan e7d948b0e7 Merge branch 'docs/add_psa_drivers_guide_v6.0' into 'release/v6.0'
doc: adds RSA DS docs for PSA Migration (v6.0)

See merge request espressif/esp-idf!46678
2026-03-19 19:44:10 +05:30
Aditya Patwardhan 662a3be354 change(version): Update version to 6.0.0 2026-03-18 15:18:48 +05:50
Aditya Patwardhan 9df5d023bc Merge branch 'ci/backport-master-6.0-2026-02-11' into 'release/v6.0'
ci: backport master changes to 6.0

See merge request espressif/esp-idf!45829
2026-03-10 15:58:56 +05:30
Aditya Patwardhan 5ecafbffc1 Merge branch 'update/version_6_0_0' into 'release/v6.0'
Update version to 6.0.0

See merge request espressif/esp-idf!46355
2026-03-09 13:45:19 +05:30
Aditya Patwardhan 504c09dca9 change(version): Update version to 6.0.0 2026-03-06 15:27:38 +05:50
Aditya Patwardhan 2235fd841a fix(bt): Keep older error code for backward comatibility 2026-03-02 14:35:43 +08:00
Aditya Patwardhan 8d4dd1bc99 feat(esp-tls): Add crypto callbacks to custom TLS stack interface
Added crypto_sha1 and crypto_base64_encode callbacks to esp_tls_stack_ops_t
to allow custom TLS stacks to provide implementations for esp_crypto_* APIs.
2026-02-06 11:47:00 +05:30
Aditya Patwardhan a4eeacab06 feat(esp-tls): Added build test for the custom stack registration 2026-02-06 11:47:00 +05:30
Aditya Patwardhan 742f2e2c3c feat(docs): Added migration guide 2026-02-06 11:46:59 +05:30
Aditya Patwardhan b0844ddfdd feat(esp-tls): Added support to register custom tls stack
* Removed the esp_tls_wolfssl layer from esp-tls
    * Migrated Error codes
2026-02-06 11:46:55 +05:30
Aditya Patwardhan 5918295328 Merge branch 'fix/dead_code_and_uninitialised_scalar_v6.0' into 'release/v6.0'
fix(examples/tee): Remove dead code and fix unintialised scalar usage (v6.0)

See merge request espressif/esp-idf!45578
2026-02-02 13:04:55 +05:30
Aditya Patwardhan db2f4d1660 fix(esp_hal_security): Fix pre-commit hook changes 2026-01-30 17:12:56 +05:30
Aditya Patwardhan 9dbe3975e4 fix(bootloader_support): Use ROM SHA types to avoid esp_hal_security dependency 2026-01-30 17:12:56 +05:30
Aditya Patwardhan 1146a98c65 fix(bootloader_support): Add esp_hal_security dependency for TEE builds 2026-01-30 17:12:55 +05:30
Aditya Patwardhan 85e70bc138 fix(hal): Add brownout_hal for TEE builds 2026-01-30 17:12:55 +05:30
Aditya Patwardhan e26b33cc3a fix(esp_tee): Update linker scripts for apm_hal move to esp_hal_security 2026-01-30 17:12:55 +05:30
Aditya Patwardhan 69179d566e fix(hal/huk): Add missing break statements in switch cases for ESP32-C5 2026-01-30 17:12:55 +05:30
Aditya Patwardhan 8c7b5de2f3 fix(docs): Fix docs after esp_hal_security update 2026-01-30 17:12:54 +05:30
Aditya Patwardhan 4d3cfefc2e refactor(esp_hal_security): Updated esp_hal_security build and includes 2026-01-30 17:12:54 +05:30
Aditya Patwardhan 6c2716cd27 refactor(hal): Created esp_hal_security for security code 2026-01-30 17:12:49 +05:30
Aditya Patwardhan f6fbbd94df Merge branch 'feat/enable_ecdsa_support_for_esp32p4_eco5_v6.0' into 'release/v6.0'
feat(esp32p4_eco5): enabled ECDSA peripheral support for ESP32P4 ECO5 (v6.0)

See merge request espressif/esp-idf!45350
2026-01-30 07:47:55 +05:30
Aditya Patwardhan 7a337412b1 Merge branch 'bugfix/http_digest_arg_validation_v6.0' into 'release/v6.0'
fix(esp_http_client): prevent out-of-bounds read in Digest auth (v6.0)

See merge request espressif/esp-idf!43900
2025-12-21 13:09:31 +05:30
Aditya Patwardhan 084d1f03f6 Merge branch 'bugfix/protocomm_sec1_validation_v6.0' into 'release/v6.0'
fix(protocomm): add validation for Security1 client verifier data (v6.0)

See merge request espressif/esp-idf!43776
2025-12-21 13:08:04 +05:30
Aditya Patwardhan 77d2a9e627 feat(protocomm): Migrate to PSA api interface 2025-12-18 21:18:58 +08:00
Aditya Patwardhan 574a60289d feat(protocomm): Migrate to PSA api interface 2025-12-18 21:18:58 +08:00
Aditya Patwardhan 72a2f0b9aa feat(coredump): Migrated coredump sha256 implementation to PSA
Added test case to test the sha256 implementation of coredump
2025-12-18 21:18:58 +08:00
Aditya Patwardhan eb5e92063f feat(mbedtls): Update the protocol components with PSA APis 2025-12-18 21:18:58 +08:00
Aditya Patwardhan 6985915481 feat(esp-tls): mbedtls PSA migration 2025-12-18 21:18:58 +08:00
Aditya Patwardhan c39347c00c feat(bootloader_support): Migrated mbedTLS crypto APIs to PSA 2025-12-18 21:18:55 +08:00
Aditya Patwardhan e2b9c01b7a Merge branch 'fix/cert_bundle_stress_test_failure_v6.0' into 'release/v6.0'
Fix cert bundle stress test (v6.0)

See merge request espressif/esp-idf!43360
2025-11-14 14:48:28 +05:30
Aditya Patwardhan 41b37f813b feat(docs): Added svg file for the RNG 2025-09-21 18:37:20 +05:30
Aditya Patwardhan d2cd0e72ef fix(docs): Improved RNG documentation
Updated the RNG documentation to add more details
about the High speed ADC as a noise source
and its limitations.

Closes https://github.com/espressif/esp-idf/issues/14665
2025-09-21 18:37:13 +05:30
Aditya Patwardhan b0cdc82996 fix(ecdsa): Fixed ECDSA efuse purpose check condition 2025-09-18 15:29:25 +05:30
Aditya Patwardhan 0cd73dfb43 fix(esp_hw_support): Fixed entropy mixing of RTC timer with RNG
Previously the RTC timer entropy was being mixed with the RNG timer
    in a wrong way. Which led to the overwriting of the LSB with rtc
    timer value.
    This change fixes that behaviour
2025-09-11 09:41:25 +05:30
Aditya Patwardhan cc37708f98 Merge branch 'feature/remove_ds_and_rsa_support_for_esp32h4' into 'master'
feat: remove ds and mpi support for esp32h4

Closes IDF-12443, IDF-12444, and IDF-12970

See merge request espressif/esp-idf!41339
2025-08-26 11:49:15 +05:30
Aditya Patwardhan 646377c622 Merge branch 'fix/http_client_coverity_warnings' into 'master'
fix(esp_http_client): address coverity generated warnings

Closes IDF-13867, IDF-13881, and IDF-13886

See merge request espressif/esp-idf!41411
2025-08-25 17:02:07 +05:30
Aditya Patwardhan 4371348039 Merge branch 'contrib/github_pr_17464' into 'master'
Update the QEMU instructions for the security_features_app example (GitHub PR)

Closes IDFGH-16318 and IDFGH-16311

See merge request espressif/esp-idf!41438
2025-08-25 10:04:07 +05:30
Aditya Patwardhan 286f7fe082 Merge branch 'change/ecdsa_does_not_use_mpi_esp32h2_eco5' into 'master'
The ECDSA module of ESP32-H2 ECO5 does not use the MPI module

See merge request espressif/esp-idf!41156
2025-08-13 23:22:51 +05:30
Aditya Patwardhan b72e532598 Merge branch 'feature/move_partial_download_code_under_config' into 'master'
feat(esp_http_client): move partial download related code under config

Closes IDF-13464

See merge request espressif/esp-idf!40270
2025-08-11 11:09:49 +05:30
Aditya Patwardhan 4a69fcbdfd Merge branch 'fix/regression_issue_in_digest_auth' into 'master'
fix(esp_http_client): fixed regression issue during enabling digest auth in client

Closes IDFGH-16189

See merge request espressif/esp-idf!41069
2025-08-07 10:53:39 +05:30
Aditya Patwardhan a783974d00 Merge branch 'feat/support_authentication_feature_for_ws' into 'master'
Added pre handshake callback for websocket

Closes IDF-13605

See merge request espressif/esp-idf!40706
2025-07-31 15:04:07 +05:30
Aditya Patwardhan 9cd759c3bc Merge branch 'feature/support_rng_sampling' into 'master'
Feature/support rng sampling

See merge request espressif/esp-idf!40433
2025-07-24 09:42:39 +05:30
Aditya Patwardhan 96170ea10b refactor(hal): Move CONFIG options used in ecdsa_hal.c under config.h 2025-07-23 15:34:05 +05:30
Aditya Patwardhan 03ffe90f95 feat(soc): Added soc capabilities related to RNG for ESP32C5 2025-07-23 14:22:09 +05:30
Aditya Patwardhan 5cc1e8c0d5 fix(mqtt): Increased partition size to fix build failure 2025-07-23 11:33:15 +05:30
Aditya Patwardhan f8ebe0c936 Merge branch 'feat/enable_memory_region_protection_for_h21' into 'master'
feat(esp_hw_support): Enabled support for memory region protection for H21

Closes IDF-11917

See merge request espressif/esp-idf!39312
2025-07-10 17:13:36 +05:30
Aditya Patwardhan bfc5e1b234 Merge branch 'feature/store_respnse_status_code_before_header_complete' into 'master'
feat(esp_http_client): Add HTTP_EVENT_ON_STATUS_CODE to notify early status code acquisition

Closes IDF-13452

See merge request espressif/esp-idf!40244
2025-07-10 12:35:10 +05:30
Aditya Patwardhan 9820fd1d9f Merge branch 'fix/esp_key_mgr_incorrect_overlapping_comparisons' into 'master'
Fix incorrect overlapping comparisons in key manager driver

See merge request espressif/esp-idf!40344
2025-07-04 08:27:07 +05:30
Aditya Patwardhan 9f5c9c7ef6 Merge branch 'feat/adding_hidden_config_for_dynamic_buffer_control_configuration' into 'master'
feat(esp_tls): Added hidden config in esp-tls for dynamic buffer strategy configuration

See merge request espressif/esp-idf!40172
2025-06-30 16:26:03 +05:30
Aditya Patwardhan 662d793f37 feat(esp_security): Added support for key manager for esp32c5 2025-06-27 15:15:26 +05:30
Aditya Patwardhan b971cf5bf9 Merge branch 'docs/fix_secure_download_mode_unsupported_esp32' into 'master'
fix(bootloader): Fix documentation as ESP32 does not support secure download mode

See merge request espressif/esp-idf!40005
2025-06-20 22:08:20 +05:30
Aditya Patwardhan 68b583f30c Merge branch 'docs/update_http_server_uri_fun_doc_regarding_thread_safe' into 'master'
Updated the http_server doc regarding thread safety

Closes IDFGH-15207

See merge request espressif/esp-idf!39587
2025-06-20 13:57:41 +05:30
Aditya Patwardhan f4e8813d45 Merge branch 'contrib/github_pr_15972' into 'master'
feat(esp_http_client): Event to signal last header downloaded (GitHub PR)

See merge request espressif/esp-idf!39309
2025-06-10 13:08:10 +05:30
Aditya Patwardhan 8d0527d7bf Merge branch 'feat/support_sha512_for_esp32c5' into 'master'
Support SHA 512 for ESP32-C5

See merge request espressif/esp-idf!39421
2025-06-09 09:42:37 +05:30
Aditya Patwardhan d835854c8f Merge branch 'bugfix/fix_tls1_3_dynamic_buffer_build' into 'master'
fix(mbedtls): Fix failing build with TLS1.3 only and dynamic buffer enabled

Closes IDF-13140

See merge request espressif/esp-idf!39319
2025-06-06 16:09:25 +05:30
Aditya Patwardhan ec659cbe93 Merge branch 'docs/update_cn_translation_for_secure_boot' into 'master'
docs: Update CN translation for Secure Boot

Closes DOC-10935

See merge request espressif/esp-idf!38862
2025-05-08 17:24:08 +08:00
Aditya Patwardhan d3e3790fc9 Merge branch 'fix/refactor_source_code_and_comments' into 'master'
fix(hal): updated API description and added comments

Closes IDF-12618

See merge request espressif/esp-idf!38415
2025-04-30 18:26:57 +08:00
Aditya Patwardhan 852466ea0e Merge branch 'fix/cache_support_duing_pure_ram_app' into 'master'
fix(esp_mm): Move cache-related sources out of pure RAM app check

See merge request espressif/esp-idf!38717
2025-04-30 11:28:01 +08:00
Aditya Patwardhan f7398c5bc2 Merge branch 'bugfix/esp32_c6_rev0_ecdsa_build' into 'master'
fix: Secure boot (ECDSA) build failure for C6 rev0 target

Closes IDFGH-15184

See merge request espressif/esp-idf!38810
2025-04-29 17:57:55 +08:00
Aditya Patwardhan cb9ffd9cf6 fix(http_server): Fixed CI build test rules for the example 2025-04-24 15:57:12 +05:30
Aditya Patwardhan f6a7bcb54e fix(esp-tls): Fixed build issue in esp-tls related to IPV6 only config 2025-04-24 15:14:35 +05:30
Aditya Patwardhan fd4f74a559 Merge branch 'fix/esp_tls_correct_struct_size' into 'master'
fix(esp_tls): use correct sockaddr struct size when calling connect()

Closes IDFGH-15135

See merge request espressif/esp-idf!38636
2025-04-24 13:10:12 +08:00
Aditya Patwardhan bb9f73a786 Merge branch 'contrib/github_pr_15821' into 'master'
fix(esp_http_server): Fix incorrect spelling in the comments (GitHub PR)

Closes IDFGH-15144

See merge request espressif/esp-idf!38569
2025-04-23 20:42:03 +08:00
Aditya Patwardhan 2e2f39b9a0 Merge branch 'fix/add_dependency_for_esp_https_ota_component' into 'master'
fix(esp_https_ota): add component dependencies for esp_https_ota component

Closes IDFGH-14981

See merge request espressif/esp-idf!38304
2025-04-09 18:08:31 +08:00
Aditya Patwardhan 61f992a061 Merge branch 'contrib/github_pr_15291' into 'master'
fix(esp_http_client): Fix invalid content length header (GitHub PR)

Closes IDFGH-14528

See merge request espressif/esp-idf!37036
2025-02-25 13:03:12 +08:00
Aditya Patwardhan 877057db3d Merge branch 'fix/fix_timeout_issue_in_https_server' into 'master'
fix(esp-tls): Fixed the server session create API

Closes IDFGH-14201

See merge request espressif/esp-idf!36519
2025-02-23 19:07:00 +08:00
Aditya Patwardhan 43a7248501 Merge branch 'contrib/github_pr_14785' into 'master'
Removed dependency on esp32 to use secure element (GitHub PR)

Closes IDFGH-13955 and IDFGH-13922

See merge request espressif/esp-idf!36935
2025-02-21 00:52:38 +08:00
Aditya Patwardhan 786dcacd8b fix(security): Fixed README for security features app 2025-02-20 22:05:48 +05:30
Aditya Patwardhan d31654da96 fix(esp-tls): Fixed the server session create API
Added the option to define tls_handshake_timeout value
    for the esp_tls_server_session_create API.
    At the moment, the API gets stuck infinitely if
    the handshake is blocked on recieving more data
    and the peer connection has closed due to some issue.

    Closes https://github.com/espressif/esp-idf/issues/14999
2025-02-18 14:46:33 +05:30
Aditya Patwardhan 05af3a87c7 Merge branch 'feature/esp32h2_eco5_ecc' into 'master'
feat(ecc): enable ECC constant time mode for ESP32-H2 ECO5

Closes IDF-11051, IDF-11399, and DOC-10127

See merge request espressif/esp-idf!34364
2025-01-24 14:12:06 +08:00
Aditya Patwardhan 839c18c762 feat(docs): Update minimizing binary size
The ESP32-H2 software countermeasure may not be necessary
        for ESP32-H2 v1.2 and above, this commit updates
        the relevant documentation
2025-01-24 11:50:17 +08:00
Aditya Patwardhan d8d9ba3dc2 fix(soc): Fixed ECDSA register compatibility 2025-01-24 11:50:17 +08:00
Aditya Patwardhan bef2a72ecb fix(hal): Make the ECDSA countermeasure dynamically applicable
This commit makes the ECDSA countermeasure dynamically applicable
    across different revisions of the ESP32H2 SoC.
2025-01-24 11:50:17 +08:00
Aditya Patwardhan bc63628fe6 Merge branch 'contrib/github_pr_15059' into 'master'
feat(https): Get TLS errors from http client (GitHub PR)

Closes IDFGH-14265

See merge request espressif/esp-idf!35833
2025-01-21 14:01:12 +08:00
Aditya Patwardhan 79e78a8fd5 Merge branch 'docs/update_cn_secure_boot_v2' into 'master'
docs: Update CN translation for secure-boot-v2.rst

Closes DOC-9811

See merge request espressif/esp-idf!35758
2024-12-23 10:57:39 +08:00
Aditya Patwardhan 05f3a6be80 Merge branch 'bugfix/fix_efuse_block_numbers_in_hal_crypto_testapps' into 'master'
fix(hal/test_apps): update efuse block numbers for ECDSA key burning

Closes IDF-11445

See merge request espressif/esp-idf!35457
2024-12-20 18:46:12 +08:00
Aditya Patwardhan f9d64d4db8 feat(esp-tls): Update support for asynchronous server session create
Closes https://github.com/espressif/esp-idf/pull/14493
2024-11-29 17:04:31 +05:30
Aditya Patwardhan 308bad9bf4 Merge branch 'bug/wifi_provisioning_failure_even_after_connecting' into 'master'
fix(esp_wifi_prov): Provisioning App failure on first failed attempt

Closes IDF-11451

See merge request espressif/esp-idf!34411
2024-11-29 17:46:26 +08:00