Skip to content

SSL: Add peer certificate verification - #2390

Open
petermm wants to merge 1 commit into
atomvm:release-0.7from
petermm:feature/esp32-ssl
Open

SSL: Add peer certificate verification#2390
petermm wants to merge 1 commit into
atomvm:release-0.7from
petermm:feature/esp32-ssl

Conversation

@petermm

@petermm petermm commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

good old secops - obviously good for general use, and things like https://github.com/nerves-hub/nerves_hub_link_atomvm_esp32 so they dont need a custom nif for websocket..

Support verify_peer with caller-provided CA certificates or CA files, and use the ESP32 IDF certificate bundle when requested.

Require a verification name for peer verification, return stable CA option errors, and close sockets on every failed TLS setup path.

Map TLS close and socket reset failures to stable SSL errors, and add coverage for CA verification, option errors, and ESP32 HTTPS connections.

These changes are made under both the "Apache 2.0" and the "GNU Lesser General
Public License 2.1 or later" license terms (dual license).

SPDX-License-Identifier: Apache-2.0 OR LGPL-2.1-or-later

Support verify_peer with caller-provided CA certificates or CA files,
and use the ESP32 IDF certificate bundle when requested.

Require a verification name for peer verification, return stable CA option
errors, and close sockets on every failed TLS setup path.

Map TLS close and socket reset failures to stable SSL errors, and add
coverage for CA verification, option errors, and ESP32 HTTPS connections.

Signed-off-by: Peter M <petermm@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant