Skip to main content

MbedTLS

MbedTLS is the TLS library that secures network connections on Zephyr-based devices. It provides the encryption behind HTTPS, secure email and SNMPv3.

You normally never enable MbedTLS by hand. It is added to the project automatically when a feature or block needs it:

Added byWhen
HTTP Request blockThe URL starts with https, or comes from a variable.
HTTP ServerTLS/HTTPS is enabled.
SMTP ClientConnection Security is STARTTLS or SSL/TLS.
SNMP AgentSNMPv3 is enabled.
Availability

MbedTLS is available on Zephyr-based devices.

Configuration​

  • Enabled: turns TLS support on. Configurations is disabled while it is off.

  • Configurations: extra Zephyr Kconfig options appended to the project configuration, one per line. The defaults are:

    CONFIG_MBEDTLS_HEAP_SIZE=16384
    CONFIG_MBEDTLS_SSL_MAX_CONTENT_LEN=4096

The feature builds MbedTLS with TLS 1.2, PEM certificate support and Server Name Indication (SNI).

Memory Tuning​

TLS is memory-hungry, and most TLS problems on small devices are memory problems.

  • CONFIG_MBEDTLS_HEAP_SIZE: memory reserved for TLS sessions. Increase it if handshakes fail with allocation errors.
  • CONFIG_MBEDTLS_SSL_MAX_CONTENT_LEN: the largest TLS record the device can receive. Some servers send records up to 16 KB; if a handshake fails right after connecting, try 16384, provided the heap is large enough.

Some features request their own values for these options; for example, the SMTP Client asks for a heap of at least 30000. Lines in Configurations are added to prj.conf as written, and when an option is assigned more than once the last assignment wins. If you change an option here, check the generated prj.conf to confirm the value you expect is the one in effect.

See Also​