Mbed TLS SDK integration¶
The application TLS guide gives the project steps. This reference describes the packaged sources, targets and transport adapters.
This SDK builds its TLS libraries from the complete, locally vendored mbedtls-symbian source port, which adapts the upstream Mbed TLS project for Symbian. Link the library only in applications that need it. A TLS session uses a certificate to authenticate its peer and needs a trusted entropy source for cryptographic randomness. The default guest entropy callback fails closed until a target-specific source is supplied.
The default SDK export builds the vendored
third_party/mbedtls-symbian port for ARMv5T and ARMv6. The repository
contains its CMake project, source files, public and private headers, tests,
and original license notices. No sibling checkout is required. The SDK
installs Mbed TLS 3.4.1 headers, the static mbedcrypto, mbedx509 and
mbedtls archives, architecture-specific CMake package targets, the
Apache-2.0 license, a complete inspectable source copy in
source/mbedtls-symbian. The SDK digest inventory covers installed payload
integrity.
Cloning an older installed SDK with symbian sdk install also fails with a
message to use --workspace for a fresh export; it cannot silently copy an
SDK without the default TLS package.
An application opts in through CMake:
find_package(MbedTLS 3.4.1 EXACT CONFIG REQUIRED)
target_link_libraries(my_app PRIVATE MbedTLS::mbedtls)
The SDK toolchain selects the architecture-matched package. The TLS target
brings in X.509 and crypto; applications needing only cryptography can link
MbedTLS::mbedcrypto. Headers are also available from the SDK's include/
root. No TLS archive is linked by ordinary application targets unless they
explicitly or transitively request it.
The packaged port compiles TLS 1.2 and TLS 1.3. These archives do not replace
Symbian's system ssl.dll. The port supplies a UTC adapter using the SDK's
clock and libc imports, with an invalid-clock failure path. Its guest behavior
requires compatible clock and libc services on the target. The port also
provides nonblocking OpenC socket BIO callbacks. For SDK HTTP and WebSockets,
use TlsStream over Symbian::Connectivity's native RSocket transport;
OpenC outbound socket I/O is unavailable in the RM-807 emulator profile.
The standard guest entropy callback fails closed. Supply a secure entropy source appropriate to the actual target. The RM-807 entropy adapter requires the matching patched emulator and is not a phone entropy implementation. Certificate trust policy belongs to the application; no CA roots are loaded implicitly.
The project CMake option SYMBIAN_CA_BUNDLE selects a PEM file inside that
project. Leave it empty to package no roots. For example, configure with
-DSYMBIAN_CA_BUNDLE:STRING=certs/private-ca.pem. CMake checks the path and
256 KiB limit, prints its SHA-256, and exposes
SYMBIAN_CA_BUNDLE_PACKAGED_PATH to the application. The symbian package
step validates every PEM certificate, rejects other PEM blocks, and installs
the exact bytes at \\resource\\apps\\<executable-stem>_ca.pem. The package
report records the source, target and SHA-256. A bundle requires an
[application] registration; it changes no SDK trust store or Mbed TLS
defaults. The TLS owner must explicitly load these roots and require peer
verification. Packaging reads the selection from the ELF build directory's
CMakeCache.txt and rejects a cache belonging to another project. Explicit
key pinning remains possible without a CA bundle.
Socket BIO API¶
symbian_mbedtls_socket_bio_attach takes an already connected OpenC socket
descriptor and requests O_NONBLOCK. The caller retains ownership of that
descriptor and must close it after the TLS owner has stopped using the BIO.
Pass the BIO to mbedtls_ssl_set_bio with
symbian_mbedtls_socket_bio_send and
symbian_mbedtls_socket_bio_recv; retry MBEDTLS_ERR_SSL_WANT_READ and
MBEDTLS_ERR_SSL_WANT_WRITE only when the socket becomes ready. Call
symbian_mbedtls_socket_bio_cancel to make later callback invocations return
MBEDTLS_ERR_NET_CONN_RESET. The cancel flag does not interrupt a callback
already inside OpenC. For native SDK TLS sessions, use TlsStream over the native Socket Server
transport instead.