MbedTLS
MbedTLS is the TLS library that secures network connections on Zephyr-based devices. It provides the encryption behind HTTPS, secure email and SNMPv3.
You normally never enable MbedTLS by hand. It is added to the project automatically when a feature or block needs it:
| Added by | When |
|---|---|
| HTTP Request block | The URL starts with https, or comes from a variable. |
| HTTP Server | TLS/HTTPS is enabled. |
| SMTP Client | Connection Security is STARTTLS or SSL/TLS. |
| SNMP Agent | SNMPv3 is enabled. |
MbedTLS is available on Zephyr-based devices.
Configuration
Enabled: turns TLS support on. Configurations is disabled while it is off.
Configurations: extra Zephyr Kconfig options appended to the project configuration, one per line. The defaults are:
CONFIG_MBEDTLS_HEAP_SIZE=16384
CONFIG_MBEDTLS_SSL_MAX_CONTENT_LEN=4096
The feature builds MbedTLS with TLS 1.2, PEM certificate support and Server Name Indication (SNI).
Memory Tuning
TLS is memory-hungry, and most TLS problems on small devices are memory problems.
CONFIG_MBEDTLS_HEAP_SIZE: memory reserved for TLS sessions. Increase it if handshakes fail with allocation errors.CONFIG_MBEDTLS_SSL_MAX_CONTENT_LEN: the largest TLS record the device can receive. Some servers send records up to 16 KB; if a handshake fails right after connecting, try16384, provided the heap is large enough.
Some features request their own values for these options; for example, the SMTP Client asks for a heap of at least 30000. Lines in Configurations are added to prj.conf as written, and when an option is assigned more than once the last assignment wins. If you change an option here, check the generated prj.conf to confirm the value you expect is the one in effect.