Added USE_MQTT_TLS_DROP_OLD_FINGERPRINT
compile time option to drop old (less secure) TLS fingerprint
#10584
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description:
Add a compile time option to drop the old algorithm for TLS Fingerprint.
All fingerprints are automatically updated to the new algo at first connection, however if the check fails, it will check against the old algo as well.
This new option disables the fallback to the old algo, so it should be enabled ONLY if you know that your fingerprint was updated. Not enabled by default.
See https://threadreaderapp.com/thread/1339101572832382981.html for details about the fingerprint vulnerability.
Related issue (if applicable): fixes #10571
Checklist:
NOTE: The code change must pass CI tests. Your PR cannot be merged unless tests pass