Skip to content

change(esp-tls): Improve support for wolfssl (IDFGH-15505)#16145

Open
gojimmypi wants to merge 1 commit into
espressif:release/v5.5from
gojimmypi:pr-wolfssl-esp-tls-v55
Open

change(esp-tls): Improve support for wolfssl (IDFGH-15505)#16145
gojimmypi wants to merge 1 commit into
espressif:release/v5.5from
gojimmypi:pr-wolfssl-esp-tls-v55

Conversation

@gojimmypi

Copy link
Copy Markdown

Description

Improves support for wolfSSL in the ESP-IDF esp-tls component.

I realize that v5.5 is already in beta1 as of a few days ago. I'm hopeful that this update can be included.

Works best with wolfSSL v5.7.6 or later; v5.7.8 is better, more polish coming to master branch.

The wolfssl source code can also be set via WOLFSSL_ROOT via environment variable, cmake variable, or idf.py menuconfig.

See ESP Registry for wolfssl and other components in the wolfssl namespace.

For getting started, see:

Related

Recent esp-tls specific changes to wolfSSL:

Overview:

Also:

Testing

Tested with my slightly revised esp_http_client_example.

Note the problem references in:


Checklist

Before submitting a Pull Request, please ensure the following:

  • 🚨 This PR does not introduce breaking changes.
  • All CI checks (GH Actions) pass.
  • Documentation is updated as needed.
  • Tests are updated or added as necessary.
  • Code is well-commented, especially in complex areas.
  • Git history is clean — commits are squashed to the minimum necessary.

@github-actions

github-actions Bot commented Jun 17, 2025

Copy link
Copy Markdown
Warnings
⚠️
	The **target branch** for this Pull Request **must be the default branch** of the project (`master`).

	If you would like to add this feature to a different branch, please state this in the PR description and we will consider it.

👋 Hello gojimmypi, we appreciate your contribution to this project!


📘 Please review the project's Contributions Guide for key guidelines on code, documentation, testing, and more.

🖊️ Please also make sure you have read and signed the Contributor License Agreement for this project.

Click to see more instructions ...


This automated output is generated by the PR linter DangerJS, which checks if your Pull Request meets the project's requirements and helps you fix potential issues.

DangerJS is triggered with each push event to a Pull Request and modify the contents of this comment.

Please consider the following:
- Danger mainly focuses on the PR structure and formatting and can't understand the meaning behind your code or changes.
- Danger is not a substitute for human code reviews; it's still important to request a code review from your colleagues.
- Resolve all warnings (⚠️ ) before requesting a review from human reviewers - they will appreciate it.
- To manually retry these Danger checks, please navigate to the Actions tab and re-run last Danger workflow.

Review and merge process you can expect ...


We do welcome contributions in the form of bug reports, feature requests and pull requests via this public GitHub repository.

This GitHub project is public mirror of our internal git repository

1. An internal issue has been created for the PR, we assign it to the relevant engineer.
2. They review the PR and either approve it or ask you for changes or clarifications.
3. Once the GitHub PR is approved, we synchronize it into our internal git repository.
4. In the internal git repository we do the final review, collect approvals from core owners and make sure all the automated tests are passing.
- At this point we may do some adjustments to the proposed change, or extend it by adding tests or documentation.
5. If the change is approved and passes the tests it is merged into the default branch.
5. On next sync from the internal git repository merged change will appear in this public GitHub repository.

Generated by 🚫 dangerJS against 5697a4c

@gojimmypi gojimmypi changed the title Improve support for wolfssl in esp-tls change(esp-tls): Improve support for wolfssl Jun 17, 2025
@github-actions github-actions Bot changed the title change(esp-tls): Improve support for wolfssl change(esp-tls): Improve support for wolfssl (IDFGH-15505) Jun 17, 2025
@espressif-bot espressif-bot added the Status: Opened Issue is new label Jun 17, 2025
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


gojimmypi seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@hrushikesh430

hrushikesh430 commented Jun 30, 2026

Copy link
Copy Markdown
Collaborator

Hi @gojimmypi, just migrated this PR to esp-wolfssl (check this).

@gojimmypi

Copy link
Copy Markdown
Author

Hi @hrushikesh430 - yes, I see that there's now a submodule in the esp-wolfssl repo. That will likely pull in something like a half gig of mostly unrelated code, no?

It is unfortunate that serious security continues to be considered an add-on, rather than a critical built-in, with wolfSSL integrated security removed from the EDP-IDF v6. (not even mentioned as a breaking change in the press release nor releases)

Have you tested the esp-wolfssl with things like wolfSSH, wolfMQTT, wolfTPM, etc?

Can I assume there's no longer interest in the Espressif wolfSSL Managed Components?

I don't see how venturing off on customizations like that in espressif/esp-wolfssl#29 and the esp-wolfssl in general are helpful to serious industrial and commercial end users.

I appreciate you asking my input. I just don't think that is the right direction to go.

@hrushikesh430

Copy link
Copy Markdown
Collaborator

Hi @hrushikesh430 - yes, I see that there's now a submodule in the esp-wolfssl repo. That will likely pull in something like a half gig of mostly unrelated code, no?

It is unfortunate that serious security continues to be considered an add-on, rather than a critical built-in, with wolfSSL integrated security removed from the EDP-IDF v6. (not even mentioned as a breaking change in the press release nor releases)

Have you tested the esp-wolfssl with things like wolfSSH, wolfMQTT, wolfTPM, etc?

Can I assume there's no longer interest in the Espressif wolfSSL Managed Components?

I don't see how venturing off on customizations like that in espressif/esp-wolfssl#29 and the esp-wolfssl in general are helpful to serious industrial and commercial end users.

I appreciate you asking my input. I just don't think that is the right direction to go.

Could please take a look, sorry for previous misdirected comment.

@gojimmypi

Copy link
Copy Markdown
Author

No worries. See my follow-up: #17683 (comment) response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Status: Opened Issue is new

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants