819 Commits
Author SHA1 Message Date
Ashish Sharma 28f3d0be4a fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:48 +08:00
Kapil Gupta e15821aca2 fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-22 09:00:45 +05:30
Kapil Gupta e8b60c7e2e fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-22 09:00:41 +05:30
harshal.patil 8a934fa932 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-06-12 16:54:33 +05:30
harshal.patilandAshish Sharma 483c51b3c8 fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down
Co-Authored-By: Ashish Sharma <ashish.sharma@espressif.com>
2026-06-12 16:54:33 +05:30
Ashish Sharma 99fc683322 fix(mbedtls): fixes build failure with clang21
Closes https://github.com/espressif/esp-idf/issues/18456
2026-06-05 16:49:29 +08:00
Aditya Patwardhan 6f79e8ed4a Merge branch 'feat/esp_tee_backports_v5.5' into 'release/v5.5'
feat(esp_tee): Feature/fixes backports to `release/v5.5`

See merge request espressif/esp-idf!48496
2026-05-28 11:00:10 +05:30
Aditya Patwardhan 9234e95e20 Merge branch 'feat/generic_key_mgr_key_types_v5.5' into 'release/v5.5'
Store key_len field in the key_config (v5.5)

See merge request espressif/esp-idf!48145
2026-05-28 10:42:25 +05:30
Laukik Hase 2c38c285cf feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-05-26 11:44:47 +05:30
Jiang Guang Ming 24d57e57b3 fix(mbedtls): fix ROM mbedTLS threading alt issues 2026-05-19 14:52:43 +08:00
harshal.patil 8b2e942e4e change(esp_key_mgr): Store key_len field in the key_info
- Update the Key Manager key types to be generic
- Define a new enum to determine the length of the keys
- Refactor the Key Manager driver support generic key types and key lengths
- Also store key deployment mode in the key recovery info
2026-05-15 00:13:34 +05:30
Ashish Sharma 71eb2dbe6a fix(protocomm): fixes potential issues that can lead to crash during device provisioning 2026-04-29 16:22:14 +08:00
Mahavir Jain d302230c2f Merge branch 'change/exclude_cve-2025-66442_5.5' into 'release/v5.5'
change(mbedtls): adds CVE-2025-66442 to exclude list.

See merge request espressif/esp-idf!47422
2026-04-27 10:37:35 +05:30
wanckl 5d37003c47 ci(p4): p4 eco5 enable parts of special tests 2026-04-24 15:09:56 +08:00
Ashish Sharma d4b067dc25 change(mbedtls): adds CVE-2025-66442 to exclude list.
The CVE is applicable with Clang using LLVM's select-optimize feature. ESP-IDF uses GCC as default compiler and sets -Os as the default optimisation flag
2026-04-22 15:42:51 +08:00
harshal.patil 9c86e8bdc1 fix(esp_security): Enable Key Manager clocks even for efuse key operations
The Key Manager holds a key usage register, thus, the Key Manager peripheral
clock must be enabled even for efuses-based key operations to route the
crypto operations to correctly to the efuses (default is Key Manager)
2026-04-06 18:36:17 +05:30
harshal.patil 8dafc3b75f feat(esp32p4): Support newer Key Manager key sources for ESP32-P4 V3 2026-04-06 18:11:43 +05:30
Ashish Sharma 6293b28504 feat(mbedtls): update to version 3.6.6 2026-04-02 11:34:22 +08:00
Laukik Hase f2b640df49 feat(esp_tee): Enable GDMA burst mode for AES/SHA operations
- Co-authored-by: Harshal Patil <harshal.patil@espressif.com>
2026-03-31 11:09:35 +05:30
Ashish Sharma cca227e022 feat(esp-tls): adds per ssl context state management 2026-03-30 13:45:28 +08:00
Ashish Sharma 9681ec0f9c fix: fixes failing dynamic buffer tests 2026-03-30 13:45:28 +08:00
nilesh.kale afdb9e957d fix(mbedtls): software fallback for ECDSA verification for P4 version < 3.0 2026-02-24 11:56:30 +05:30
nilesh.kale 6584b5adad feat: enabled ECDSA peripheral support for ESSP32-P4 2026-02-09 20:05:46 +08:00
harshal.patil 0742f3fce3 fix(mbedtls/aes): Cache invalidate the output buffer before the AES-DMA operation
Instead of performing the cache-to-memory (C2M) operation on the output buffer,
even a cache invalidate (M2C) is sufficient to ensure that no write-back occurs
during the DMA write operation
2026-01-16 11:07:00 +05:30
harshal.patil 525ef3a2ea fix(mbedlts/aes): Ensure cache coherency when DMA writes to cacheable PSRAM buffers 2026-01-16 11:06:46 +05:30
Mahavir Jain 3378c690c4 Merge branch 'feat/add_mbedtls_testcases_for_ecc_p_384_v5.5' into 'release/v5.5'
feat(mbedtls): add ECC P-384 mbedtls support and test_cases (v5.5)

See merge request espressif/esp-idf!43980
2025-12-26 09:56:00 +05:30
harshal.patil 11c8f6aa94 fix(mbedtls/aes): Reallocate buffers only if in external RAM 2025-12-12 13:00:40 +05:30
nilesh.kale 3e4bed2e4d feat(mbedtls): add ECC P-384 mbedtls support and test_cases 2025-12-04 12:48:32 +05:30
harshal.patil 76436b3418 fix(mbedtls/port): Use internal buffers to perform chunkwise operations
when the external input and output buffers are unaligned.
This also fixes as a recursion loop that occurs when the size of the input
buffer is not aligned to dcache_line_size but is aligned to AES_BLOCK_BYTES
2025-12-01 18:15:25 +05:30
armando 304ba1655b fix check test scripts build issue 2025-11-20 11:33:36 +08:00
armando cdff2570c7 ci(p4): disable p4 rev3 invalid tests temporarily 2025-11-20 11:33:36 +08:00
Jiang Jiang Jian 86bd3d30c6 Merge branch 'fix/axi_dma_ext_mem_alignment_c5_v5.5' into 'release/v5.5'
Align AES and SHA buffers to 16 when SPIRAM encryption is enabled (v5.5)

See merge request espressif/esp-idf!43261
2025-11-12 17:45:43 +08:00
harshal.patil 317a6f074d fix(mbedtls/port): Align AES and SHA DMA buffers to 16 when SPIRAM encryption is enabled
- Targets that support GDMA and MSPI encryption module need data and addresses aligned to 16
2025-11-11 17:45:11 +05:30
Ashish Sharma 30f93c0516 feat(mbedtls): update to version 3.6.5 2025-11-11 16:47:45 +08:00
Kapil Gupta bdd1b0ca20 fix(mbedtls): Addressed comments on PR15679 2025-10-27 15:41:21 +08:00
Deomid rojer Ryabkov 73a9949161 feat(mbedtls): Add mbedtls_esp_random()
Suitable for passing as f_rng to various Mbed-TLS APIs that require it
2025-10-27 15:41:21 +08:00
Aditya Patwardhan 647e7de668 fix(ecdsa): Fixed ECDSA efuse purpose check condition 2025-10-16 14:48:13 +08:00
nilesh.kale 364adc79c3 feat: added config member to store block number for high part of ecdsa key 2025-10-16 14:48:13 +08:00
nilesh.kale 851602ed8e feat: add ecdsa-p384 testcases and relative support for ESP32C5 ECO2
This commit adds testcases in crypto/hal and mbedtls testapps.
2025-10-16 14:48:13 +08:00
Laukik Hase 73d0dadd6b fix(esp_tee): Correct flash operation bound checks to handle all overlap cases
- Ensure bound checks correctly handle all scenarios, including
  when a requested operation's (SPI0/1) range fully contains the
  TEE-protected region.
- Disable delegation of INTWDT timeout and Cache error interrupts as they reset
  the device after the panic handler
2025-10-14 10:12:28 +05:30
Laukik Hase 78737a757a feat(esp_tee): Added support for PBKDF2-based (HMAC) ECDSA signing 2025-10-14 10:12:13 +05:30
Laukik Hase 508a659001 feat(esp_tee): Support for ESP32-C5 - the rest of the components 2025-10-14 10:12:11 +05:30
harshal.patil f6f15bf91a change(mbedtls/ecdsa): The ECDSA module of ESP32-H2 ECO5 does not use MPI module 2025-08-13 18:53:19 +05:30
harshal.patil 61b0b072f9 fix(mbedtls/gcm): Allow enabling GCM fallback only if software GCM is available 2025-07-25 08:48:00 +05:30
Mahavir Jain b458016805 Merge branch 'feat/adding_different_strategy_to_perform_tls_using_dynamic_feature_v5.5' into 'release/v5.5'
Add configuration to control dynamic buffer strategy in mbedtls (v5.5)

See merge request espressif/esp-idf!39919
2025-07-22 14:48:44 +05:30
Mahavir Jain 570ecdc1cc Merge branch 'feature/support_ds_peripheral_rsa_decryption_v5.5' into 'release/v5.5'
feat(mbedtls): Add support for RSA decryption with DS peripheral (v5.5)

See merge request espressif/esp-idf!40449
2025-07-22 11:57:15 +05:30
Mahavir Jain 5c02c6fc1e Merge branch 'feat/update_mbedtls_3.6.4_v5.5' into 'release/v5.5'
feat(mbedtls): update to version 3.6.4 (v5.5)

See merge request espressif/esp-idf!40375
2025-07-22 11:52:29 +05:30
Jiang Jiang Jian 3c39b32195 Chip/support esp32c61 v5.5 2025-07-22 12:21:36 +08:00
Ashish Sharma 163db6a8a5 feat(mbedtls): adds support for RSA decryption with DS peripheral 2025-07-21 09:27:06 +08:00
Ashish Sharma a3af8972ae feat(mbedtls): update to version 3.6.4 2025-07-04 17:34:00 +08:00