ODIN-W2开发板mbedOS环境下HTTPS握手失败问题求助
Hey there, let's work through this TLS handshake issue you're hitting on your ODIN-W2 with mbedOS. That -0x2700 error (MBEDTLS_ERR_X509_CERT_VERIFY_FAILED) paired with the MBEDTLS_X509_BADCERT_BAD_PK flag means mbedTLS is rejecting the server's certificate because its public key algorithm doesn't meet the configured security requirements. Here's how to troubleshoot and fix it:
1. First, verify the server's certificate details
Start by checking what public key algorithm and key length os.mbed.com is using. Run this command on your desktop to inspect the certificate:
openssl s_client -connect os.mbed.com:443 | openssl x509 -text -noout
Look for the Public Key Algorithm section. For example, if it's RSA, check the key size (e.g., 2048-bit vs 1024-bit). If it's ECDSA, note the curve used (e.g., secp256r1). This will tell you exactly what mbedTLS is rejecting.
2. Adjust mbedTLS security profiles via mbed_app.json
mbedOS uses mbed_app.json to configure mbedTLS behavior. You'll need to tweak settings here to match the server's certificate:
- If the server uses a smaller RSA key (e.g., 1024-bit):
The default mbedTLS configuration requires a minimum 2048-bit RSA key. To lower this limit, add to yourmbed_app.json:"target_overrides": { "*": { "mbedtls.x509_min_rsa_key_size": 1024 } } - If the server uses an unsupported ECDSA curve:
Some less common ECDSA curves might be disabled by default. Enable all curves with this setting:"target_overrides": { "*": { "mbedtls.ecp_all_curves": true } }
After modifying the file, rebuild your project to apply the changes.
3. Ensure you have the correct root CA certificate
Even if the key algorithm is valid, a missing or outdated root CA certificate can trigger this error. Make sure your project includes the root CA that signed os.mbed.com's certificate:
- Export the root CA from your browser (visit os.mbed.com, view the certificate chain, save the root CA as a PEM file).
- Add the PEM content as a
const chararray in your code (e.g., in a header file), then load it into the mbedTLS SSL context during initialization.
4. Debug with disabled certificate validation (only for testing!)
To confirm the issue is purely certificate-related, temporarily disable certificate verification in your code (never do this in production):
mbedtls_ssl_conf_authmode(&ssl_conf, MBEDTLS_SSL_VERIFY_NONE);
If the handshake succeeds after this, you know the problem is definitely in the certificate validation logic—go back to steps 1-3 to fix it properly.
5. Update mbedOS/mbedTLS to the latest version
Older versions of mbedTLS might have stricter or outdated algorithm support. Upgrading to the latest stable mbedOS release can resolve compatibility issues with modern server certificates.
内容的提问来源于stack exchange,提问作者Дмитро Медвідь

