Re-enable mbedtls secp384r1 on ESP32 (#11344)

Let's Encrypt Generation Y chains sign a P-256 leaf with the P-384
intermediate YE1 under ISRG Root YE. mqtt.meshtastic.org switched to
this chain on 2026-07-29. With CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=n
mbedtls cannot parse the peer chain and the TLS handshake aborts with
MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE, breaking MQTT over TLS on every
ESP32 target.

Costs about 4 kB of flash.

Fixes #11316
This commit is contained in:
Thomas Göttgens
2026-08-03 12:49:21 +00:00
committed by GitHub
parent ddb7bbf090
commit 58657d484a
+6 -1
View File
@@ -232,7 +232,12 @@ custom_sdkconfig =
CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=n
CONFIG_MBEDTLS_ECP_DP_SECP192R1_ENABLED=n
CONFIG_MBEDTLS_ECP_DP_SECP224R1_ENABLED=n
CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=n
; Required, do not disable. Let's Encrypt "Generation Y" chains (used by
; mqtt.meshtastic.org since 2026-07-29) sign a P-256 leaf with the P-384
; intermediate YE1 under ISRG Root YE. Without this curve mbedtls cannot
; parse the chain and every TLS handshake fails with
; MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE (-0x3A00). Costs ~4 kB flash. (#11316)
CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=y
CONFIG_MBEDTLS_ECP_DP_SECP521R1_ENABLED=n
CONFIG_MBEDTLS_ECP_DP_SECP192K1_ENABLED=n
CONFIG_MBEDTLS_ECP_DP_SECP224K1_ENABLED=n