fix(libtls): enable SECP384R1 and raise default TLS content length fo… - #712
Merged
Merged
Conversation
…r US region US-region cloud chains (rtc-ai*.iot-wus.com -> DigiCert Global Root G3) carry an ECDSA P-384 root certificate. With only SECP256R1 compiled in, certificate parsing fails with MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE (-0x3a00) during the TLS handshake, so US-region AI connections never establish while CN region (RSA/P-256 chains) works fine. Also raise ENABLE_MBEDTLS_SSL_MAX_CONTENT_LEN default from 1024 to 4096: the US chain Certificate message is ~2.6KB (leaf 1187 + intermediate 844 + root 579), which exceeds 1024 unless the peer honors max_fragment_length.
shiliu-yang
approved these changes
Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…r US region
US-region cloud chains (rtc-ai*.iot-wus.com -> DigiCert Global Root G3) carry an ECDSA P-384 root certificate. With only SECP256R1 compiled in, certificate parsing fails with MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE (-0x3a00) during the TLS handshake, so US-region AI connections never establish while CN region (RSA/P-256 chains) works fine.
Also raise ENABLE_MBEDTLS_SSL_MAX_CONTENT_LEN default from 1024 to 4096: the US chain Certificate message is ~2.6KB (leaf 1187 + intermediate 844
PR 描述/PR description
[在此详细描述 PR 的内容]/[Describe the PR content in detail here]
代码质量/Code Quality:
在本次拉取请求中,我已考虑以下事项 As part of this pull request, I've considered the following: