mirror of
https://github.com/alexhopeoconnor/firmware.git
synced 2026-10-04 03:18:10 +10:00
Re-enable mbedtls secp384r1 on ESP32 (#11344)
Let's Encrypt Generation Y chains sign a P-256 leaf with the P-384 intermediate YE1 under ISRG Root YE. mqtt.meshtastic.org switched to this chain on 2026-07-29. With CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=n mbedtls cannot parse the peer chain and the TLS handshake aborts with MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE, breaking MQTT over TLS on every ESP32 target. Costs about 4 kB of flash. Fixes #11316
This commit is contained in:
@@ -232,7 +232,12 @@ custom_sdkconfig =
|
||||
CONFIG_MBEDTLS_KEY_EXCHANGE_ECJPAKE=n
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP192R1_ENABLED=n
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP224R1_ENABLED=n
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=n
|
||||
; Required, do not disable. Let's Encrypt "Generation Y" chains (used by
|
||||
; mqtt.meshtastic.org since 2026-07-29) sign a P-256 leaf with the P-384
|
||||
; intermediate YE1 under ISRG Root YE. Without this curve mbedtls cannot
|
||||
; parse the chain and every TLS handshake fails with
|
||||
; MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE (-0x3A00). Costs ~4 kB flash. (#11316)
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP384R1_ENABLED=y
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP521R1_ENABLED=n
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP192K1_ENABLED=n
|
||||
CONFIG_MBEDTLS_ECP_DP_SECP224K1_ENABLED=n
|
||||
|
||||
Reference in New Issue
Block a user