You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue was authored by claude-opus-5-5[1m] on behalf of @JPHutchins. While surveying Zephyr main's SMP server transports for the #58 design, @JPHutchins asked for a tracking issue for each server transport smpclient lacks. See also #139 (SPI).
Zephyr's UDP SMP transport has a DTLS mode, added in zephyrproject-rtos/zephyr#97526 (merged 2025-10-17) to resolve zephyrproject-rtos/zephyr#91754, with sample documentation in zephyrproject-rtos/zephyr#102201 (CONFIG_MCUMGR_TRANSPORT_UDP_DTLS, Kconfig.udp). It uses DTLS 1.2 with the device as the DTLS server, and while it is enabled the device does not serve plain UDP. smpclient's SMPUDPTransport speaks plain UDP only, so it cannot reach such a device.
Python's stdlib ssl has no DTLS, so this needs a third-party library; which one is open.
With #58, the security mode would be a constructor option on SMPUDPTransport.connected(...), e.g. a Plain | DTLS(...) sum type. That is the per-transport options work (#90/#103).
The server's side (Zephyr main @ 70be2ff0)
Socket. Opens NET_IPPROTO_DTLS_1_2, sets TLS_SEC_TAG_LIST to CONFIG_MCUMGR_TRANSPORT_UDP_DTLS_TLS_TAG (default 1) and TLS_DTLS_ROLE to server (smp_udp.c). It sets no peer-verification option.
Credentials.smp_udp_open() refuses to start without a public certificate and private key under that tag (smp_udp.c). The transport does not start automatically at boot: UDP_AUTOMATIC_INIT depends on !UDP_DTLS.
Warning
LLM Disclosure
This issue was authored by
claude-opus-5-5[1m]on behalf of @JPHutchins. While surveying Zephyrmain's SMP server transports for the #58 design, @JPHutchins asked for a tracking issue for each server transport smpclient lacks. See also #139 (SPI).Zephyr's UDP SMP transport has a DTLS mode, added in zephyrproject-rtos/zephyr#97526 (merged 2025-10-17) to resolve zephyrproject-rtos/zephyr#91754, with sample documentation in zephyrproject-rtos/zephyr#102201 (
CONFIG_MCUMGR_TRANSPORT_UDP_DTLS, Kconfig.udp). It uses DTLS 1.2 with the device as the DTLS server, and while it is enabled the device does not serve plain UDP. smpclient'sSMPUDPTransportspeaks plain UDP only, so it cannot reach such a device.Python's stdlib
sslhas no DTLS, so this needs a third-party library; which one is open.With #58, the security mode would be a constructor option on
SMPUDPTransport.connected(...), e.g. aPlain | DTLS(...)sum type. That is the per-transport options work (#90/#103).The server's side (Zephyr
main@70be2ff0)NET_IPPROTO_DTLS_1_2, setsTLS_SEC_TAG_LISTtoCONFIG_MCUMGR_TRANSPORT_UDP_DTLS_TLS_TAG(default 1) andTLS_DTLS_ROLEto server (smp_udp.c). It sets no peer-verification option.smp_udp_open()refuses to start without a public certificate and private key under that tag (smp_udp.c). The transport does not start automatically at boot:UDP_AUTOMATIC_INITdepends on!UDP_DTLS.udp-dtls.conf, with DER certificates incertificates/):ECDHE-ECDSA-AES128-GCM-SHA256andECDHE-RSA-AES128-CBC-SHA256NET_SOCKETS_DTLS_MAX_FRAGMENT_LENGTH=2048NET_SOCKETS_DTLS_TIMEOUT=30000udp.pywould need to account for it. Not worked out.🤖 Generated with Claude Code