Skip to content

SSL: Add peer certificate verification - #2390

Open
petermm wants to merge 3 commits into
atomvm:release-0.7from
petermm:feature/esp32-ssl
Open

SSL: Add peer certificate verification#2390
petermm wants to merge 3 commits into
atomvm:release-0.7from
petermm:feature/esp32-ssl

Conversation

@petermm

@petermm petermm commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

good old secops - obviously good for general use, and things like https://github.com/nerves-hub/nerves_hub_link_atomvm_esp32 so they dont need a custom nif for websocket..

Support verify_peer with caller-provided CA certificates or CA files, and use the ESP32 IDF certificate bundle when requested.

Require a verification name for peer verification, return stable CA option errors, and close sockets on every failed TLS setup path.

Map TLS close and socket reset failures to stable SSL errors, and add coverage for CA verification, option errors, and ESP32 HTTPS connections.

These changes are made under both the "Apache 2.0" and the "GNU Lesser General
Public License 2.1 or later" license terms (dual license).

SPDX-License-Identifier: Apache-2.0 OR LGPL-2.1-or-later

Support verify_peer with caller-provided CA certificates or CA files,
and use the ESP32 IDF certificate bundle when requested.

Require a verification name for peer verification, return stable CA option
errors, and close sockets on every failed TLS setup path.

Map TLS close and socket reset failures to stable SSL errors, and add
coverage for CA verification, option errors, and ESP32 HTTPS connections.

Signed-off-by: Peter M <petermm@gmail.com>
Signed-off-by: Peter M <petermm@gmail.com>
@petermm
petermm force-pushed the feature/esp32-ssl branch 4 times, most recently from 6cfbe40 to 2d16d62 Compare August 31, 2026 08:04
Exercise CYW43 WiFi, DHCP, SNTP, certificate time checks, and verified HTTPS on Pico W in Wokwi. Add a combined UF2 target, token-gated CI workflow, and local build instructions.

Run the Wokwi-only network case last and retain its final VM context because the RP2 network port does not yet support full teardown.

Signed-off-by: Peter M <petermm@gmail.com>
@petermm
petermm force-pushed the feature/esp32-ssl branch from 2d16d62 to 4603168 Compare August 31, 2026 09:27
@petermm

petermm commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

upon further review it turns out we should default to CONFIG_MBEDTLS_HAVE_TIME_DATE=y - as to default validate that cert is within it's valid period. Requires a decent time set - building with CONFIG_MBEDTLS_HAVE_TIME_DATE=n, disables the time validation, for those scenarios.

we should also kinda not suggest people to use verify_none.

the rp2 simtest CI is there for good measure, I suggest moving that to other PR before merge and then a squash, but good to validate it rp2 while we iterate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant