<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/87567/can-we-use-latest-mbed-tls-2-28-0-or-3-1-0-with-latest-nordic-sdk-for-nrf52832</link><description>Hi, 
 
 I see that the latest Nordic SDK ( v17.1.0) supports mbed TLS version of 2.16.10 only. However, we have received a End of life notification for the same ( Mbed TLS 1.3, 1.4, 2.0 ≤ 2.7, 2.14 ≤ 2.18 - End of Life Notification (EOL)). Please let</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 05 May 2022 13:20:57 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/87567/can-we-use-latest-mbed-tls-2-28-0-or-3-1-0-with-latest-nordic-sdk-for-nrf52832" /><item><title>RE: Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/thread/366484?ContentTypeID=1</link><pubDate>Thu, 05 May 2022 13:20:57 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:da114ada-5f0a-4170-a026-ba994728b5c2</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Thank you for explaining the background, that is good to know. Generally I suspect that in a situation like you describe we might also issue a notice about the issue and how it can be fixed by for instance updating a specific&amp;nbsp;component (like mbed TLS) or provide a patch. That is hypothetical, though. (Also note that mbed TLS is not much used in the SDK and it is an external&amp;nbsp;component that we do not maintain). Other than that, you should ask your regional Nordic sales representative about details&amp;nbsp;about&amp;nbsp; (potential) future releases.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/thread/366472?ContentTypeID=1</link><pubDate>Thu, 05 May 2022 13:01:10 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5a8be1d5-56ae-49f8-8662-b61aaf7f74f1</guid><dc:creator>Engineer01</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Thank you for the inputs. It is not required to update as of now since there are no vulnerabilities. But&amp;nbsp;its a general requirement here to keep the cryptographic libraries to latest version due to security implications. I am assuming that latest versions might be more robust against vulnerabilities. Is it possible that Nordic will release new SDK with updated mbed TLS libraries in future if serious vulnerabilities are identified in 2.16.10?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/thread/366465?ContentTypeID=1</link><pubDate>Thu, 05 May 2022 12:48:10 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:642e40ae-b4b0-4047-b4c5-8f5263d6f338</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I did not get a chanse to test this myself today. However, even though there should not be API changes there are quite a lot of changes, added functionality, etc between mbed TLS 2.16.10 and 2.28, so I expect you will need to work a bit on updating (at least adjust build configuration, mbedTLS configuration script (), etc.). This will typically be the same if you replace any library.&lt;/p&gt;
[quote user="Engineer01"]Also, i w2ould like to know if there are any risks of using mbed tls which has not gone through official release testing from nordic?[/quote]
&lt;p&gt;I do not see any particular risk with updating to a newer mbed TLS version of the same major version. However, we only test what is in the SDK, and and cannot make any guarantees for&amp;nbsp;anything else.&amp;nbsp;This is up to you and your choice.&lt;/p&gt;
[quote user="Engineer01"]Are there any plans to upgrade the nordic SDK with mbed tls v2.28.0 in the near future?[/quote]
&lt;p&gt;I generally cannot comment on roadmap questions here, but as you see in the&amp;nbsp;nRF Connect SDK and nRF5 SDK statement, the nRF5 SDK is in maintenance mode and you should not expect many updated going forward.&lt;/p&gt;
&lt;p&gt;One thing though, why do you need to update mbed TLS at this point? What this means is that EOL&amp;#39;ed versions will not get updates, but&amp;nbsp;that does not mean that it is suddenly bad or more vulnerable than it was before. When there are new security issues found in mbed TLS you may want to update, but that could just as well be an issue introduced in a later version, (and then you would have to do this exercise again at that point).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/thread/366240?ContentTypeID=1</link><pubDate>Wed, 04 May 2022 12:43:18 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:0f0856ea-422f-4d02-9a77-f18c47016e97</guid><dc:creator>Engineer01</dc:creator><description>&lt;p&gt;Thank you for the information. I cloned v2.28.0 from&amp;nbsp;&lt;a href="https://github.com/Mbed-TLS/mbedtls/blob/v2.28.0/BRANCHES.md"&gt;https://github.com/Mbed-TLS/mbedtls/blob/v2.28.0/BRANCHES.md&lt;/a&gt;&amp;nbsp;and added it to my project. However, i&amp;nbsp;got the following error&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp;Fatal Error[Pe035]: #error directive: &amp;quot;MBEDTLS_CERTS_C defined, but not all prerequisites &amp;quot;source\modules\external\mbedtls\include\mbedtls\check_config.h 828&lt;/p&gt;
&lt;p&gt;I then replaced the contents of &amp;quot;check_config.h&amp;quot; as per the contents of &amp;quot;check_config.h&amp;quot; in mbed tls v2.4.2. This resolved the error. However, i have following&amp;nbsp;linker errors&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Linking &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_platform_zeroize&amp;quot; [referenced from application\pca10040\s132\iar\_build\ctr_drbg.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chachapoly_update&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chachapoly_free&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chachapoly_init&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chachapoly_setkey&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chacha20_free&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chacha20_init&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chacha20_setkey&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error[Li005]: no definition for &amp;quot;mbedtls_chacha20_update&amp;quot; [referenced from application\pca10040\s132\iar\_build\cipher_wrap.o] &lt;br /&gt;Error while running Linker &lt;br /&gt; &lt;br /&gt;Total number of errors: 9&lt;/p&gt;
&lt;p&gt;Please help. Also, i w2ould like to know if there are any risks of using mbed tls which has not gone through official release testing from nordic? Are there any plans to upgrade the nordic SDK with mbed tls v2.28.0 in the near future?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Can we use latest MBED tls 2.28.0 or 3.1.0 with latest Nordic SDK for nrf52832</title><link>https://devzone.nordicsemi.com/thread/366214?ContentTypeID=1</link><pubDate>Wed, 04 May 2022 11:51:21 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1bb524cc-3cdd-4ba5-8f9e-351a7ccb4ae8</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;We have only done release testing with the mbed TLS version that is part of the SDK release (this is the same with all external SDK components). That said, &lt;a href="https://github.com/Mbed-TLS/mbedtls/blob/development/BRANCHES.md#backwards-compatibility"&gt;mbed TLS releases of the same minor versions should be API compatible&lt;/a&gt;, so I expect you should not have much problems replacing only mbed TLS.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>