mirror of
https://github.com/arendst/Tasmota.git
synced 2026-07-27 20:05:46 +00:00
TLS support for EC P-384 curve in server certificate (#24909)
This commit is contained in:
@@ -10,6 +10,7 @@ All notable changes to this project will be documented in this file.
|
||||
- Matter virtual IR HVAC thermostat support (#24821)
|
||||
- HASPmota and LVGL `stripes` widget (#24907)
|
||||
- MagicSwitch configurable masking window fixing problems with multiple false triggering (#24888)
|
||||
- TLS support for EC P-384 curve in server certificate
|
||||
|
||||
### Breaking Changed
|
||||
|
||||
|
||||
@@ -110,8 +110,21 @@ api_muladd(unsigned char *A, const unsigned char *B, size_t len,
|
||||
}
|
||||
|
||||
/* see bearssl_ec.h */
|
||||
/*
|
||||
* Tasmota: only advertise curves that fit in BR_MAX_EC_SIZE, since the
|
||||
* i15 big-integer buffers (ec_prime_i15, ecdsa_i15_*) are statically
|
||||
* sized from it. Advertising a larger curve would let the peer select
|
||||
* it and overflow those stack buffers.
|
||||
* Curve id bits: secp256r1=23, secp384r1=24, secp521r1=25, curve25519=29
|
||||
*/
|
||||
const br_ec_impl br_ec_all_m15 PROGMEM = {
|
||||
(uint32_t)0x23800000,
|
||||
#if BR_MAX_EC_SIZE >= 521
|
||||
(uint32_t)0x23800000, /* P-256, P-384, P-521, Curve25519 */
|
||||
#elif BR_MAX_EC_SIZE >= 384
|
||||
(uint32_t)0x21800000, /* P-256, P-384, Curve25519 */
|
||||
#else
|
||||
(uint32_t)0x20800000, /* P-256, Curve25519 */
|
||||
#endif
|
||||
&api_generator,
|
||||
&api_order,
|
||||
&api_xoff,
|
||||
|
||||
@@ -34,7 +34,7 @@
|
||||
#endif
|
||||
|
||||
#ifndef BR_MAX_EC_SIZE
|
||||
#define BR_MAX_EC_SIZE 256 // max 256 bits EC keys
|
||||
#define BR_MAX_EC_SIZE 384 // max 384 bits EC keys (required for P-384 certificates, ex: Letsencrypt ECDSA)
|
||||
#endif
|
||||
|
||||
#endif
|
||||
|
||||
@@ -920,8 +920,11 @@ extern "C" {
|
||||
br_ssl_engine_set_aes_ctr(&cc->eng, &br_aes_small_ctr_vtable);
|
||||
br_ssl_engine_set_ghash(&cc->eng, &br_ghash_ctmul32);
|
||||
|
||||
// we support only P256 EC curve for AWS IoT, no EC curve for Letsencrypt unless forced
|
||||
br_ssl_engine_set_ec(&cc->eng, &br_ec_p256_m15);
|
||||
// Use all supported EC curves (P-256, P-384, P-521, Curve25519) for ECDHE key exchange.
|
||||
// Some servers (e.g. with ECDSA P-384 certificates) refuse P-256 for key exchange
|
||||
// and abort the handshake with SSL3_ALERT_HANDSHAKE_FAILURE (error 296).
|
||||
// `br_ec_all_m15` is already linked for X509 ECDSA validation, so no flash size impact.
|
||||
br_ssl_engine_set_ec(&cc->eng, &br_ec_all_m15);
|
||||
#if defined(ESP32) || (defined(ESP8266) && defined(USE_MQTT_TLS_ECDSA))
|
||||
br_ssl_engine_set_ecdsa(&cc->eng, &br_ecdsa_i15_vrfy_asn1);
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user