@@ -90,23 +90,29 @@ static void applyTlsPolicy(WiFiClientSecure& client) {
9090 }
9191}
9292
93+ // The ESP-IDF Mozilla root-CA bundle (esp_crt_bundle), embedded by the Arduino
94+ // framework when CONFIG_MBEDTLS_CERTIFICATE_BUNDLE is enabled (default). Linked
95+ // symbol; declared here so the GitHub update path can validate against the full
96+ // public trust store rather than one hand-pinned root.
97+ extern const uint8_t rootca_crt_bundle_start[] asm (" _binary_x509_crt_bundle_start" );
98+ extern const uint8_t rootca_crt_bundle_end[] asm (" _binary_x509_crt_bundle_end" );
99+
93100/* *
94101 * TLS trust policy for the GitHub auto-update path (ota.h).
95102 *
96- * Pins the GitHub root bundle (config.h / GITHUB_CA_ROOT_CERT) so the whole
97- * update path is authenticated: api.github.com (release metadata) and the
98- * *.githubusercontent.com asset hosts (manifest.json + the .bin downloads) chain
99- * to different roots, both in the bundle, and HTTPClient keeps this same client
100- * across the github.com -> githubusercontent.com asset redirect, so one policy
101- * validates every hop. Falls back to setInsecure() if the bundle was overridden
102- * to empty (the binary is MD5-verified regardless, see ota.h).
103+ * Validates against the full Mozilla root-CA bundle, NOT a single pinned root.
104+ * GitHub rotates its CA, and a single pin breaks the whole update path on the
105+ * next rotation with MBEDTLS_ERR_X509_CERT_VERIFY_FAILED (tls -0x2700) -- which
106+ * is exactly what bricked the auto-update in the field. The bundle covers
107+ * api.github.com (release metadata) and the *.githubusercontent.com asset hosts
108+ * (manifest.json + .bin downloads), across the github.com -> githubusercontent
109+ * redirect HTTPClient follows on one client, and survives future CA rotations.
110+ * Still REAL certificate validation (not setInsecure): the firmware-update path
111+ * needs it, because the .bin's trusted MD5 is read from the TLS-fetched manifest.
103112 */
104113static void applyTlsPolicyGitHub (WiFiClientSecure& client) {
105- if (kGithubCaRootCert != nullptr && kGithubCaRootCert [0 ] != ' \0 ' ) {
106- client.setCACert (kGithubCaRootCert );
107- } else {
108- client.setInsecure ();
109- }
114+ client.setCACertBundle (rootca_crt_bundle_start,
115+ (size_t )(rootca_crt_bundle_end - rootca_crt_bundle_start));
110116}
111117
112118/* *
0 commit comments