Hi Ron,
i need your help, i try to fix the bug but i fail
please help me,thank!
according to your guidance, i generate server.crt and i set my DNS in subject name, but i still encounter the same question
PS I:\repository\esp32s3\esp32s3\hello_world> $env:IDF_PATH = ‘E:/Espressif/frameworks/esp-idf-v5.3.2/’;
PS I:\repository\esp32s3\esp32s3\hello_world> & ‘E:\Espressif\python_env\idf5.3_py3.11_env\Scripts\python.exe’ ‘E:\Espressif\frameworks\esp-idf-v5.3.2\tools\idf_monitor.py’ -p COM359 -b 115200 --toolchain-prefix xtensa-esp32s3-elf- --make ‘’‘E:\Espressif\python_env\idf5.3_py3.11_env\Scripts\python.exe’’ ‘‘E:\Espressif\frameworks\esp-idf-v5.3.2\tools\idf.py’’’ --target esp32s3 ‘i:\repository\esp32s3\esp32s3\hello_world\build\hello_world.elf’
— Warning: GDB cannot open serial ports accessed as COMx
— Using \.\COM359 instead…
— esp-idf-monitor 1.5.0 on \.\COM359 115200
— Quit: Ctrl+] | Menu: Ctrl+T | Help: Ctrl+T followed by Ctrl+H
ESP-ROM:esp32s3-20210327
Build:Mar 27 2021
rst:0x15 (USB_UART_CHIP_RESET),boot:0x8 (SPI_FAST_FLASH_BOOT)
Saved PC:0x4037bb0e
— 0x4037bb0e: esp_cpu_wait_for_intr at I:/repository/esp32s3/esp32s3/hello_world/components/esp_hw_support/cpu.c:64
SPIWP:0xee
mode:DIO, clock div:1
load:0x3fce2810,len:0x1870
load:0x403c8700,len:0x4
load:0x403c8704,len:0xce8
load:0x403cb700,len:0x2ed8
entry 0x403c8918
I (26) boot: ESP-IDF v5.3.2-dirty 2nd stage bootloader
I (27) boot: compile time Sep 11 2025 14:25:23
I (27) boot: Multicore bootloader
I (30) boot: chip revision: v0.2
I (34) boot: efuse block revision: v1.3
I (39) boot.esp32s3: Boot SPI Speed : 80MHz
I (43) boot.esp32s3: SPI Mode : DIO
I (48) boot.esp32s3: SPI Flash Size : 16MB
I (53) boot: Enabling RNG early entropy source…
I (58) boot: Partition Table:
I (62) boot: ## Label Usage Type ST Offset Length
I (69) boot: 0 nvs WiFi data 01 02 00009000 00004000
I (77) boot: 1 otadata OTA data 01 00 0000d000 00002000
I (84) boot: 2 phy_init RF data 01 01 0000f000 00001000
I (92) boot: 3 factory factory app 00 00 00010000 00200000
I (99) boot: 4 ota_0 OTA app 00 10 00210000 00500000
I (106) boot: 5 ota_1 OTA app 00 11 00710000 00500000
I (114) boot: 6 nvs_key NVS keys 01 04 00c10000 00001000
I (122) boot: 7 SPIFFS Unknown data 01 82 00c11000 00300000
I (129) boot: End of partition table
I (133) boot: Defaulting to factory image
I (138) esp_image: segment 0: paddr=00010020 vaddr=3c110020 size=43c4ch (277580) map
I (196) esp_image: segment 1: paddr=00053c74 vaddr=3fc9b500 size=050a4h ( 20644) load
I (200) esp_image: segment 2: paddr=00058d20 vaddr=40374000 size=072f8h ( 29432) load
I (208) esp_image: segment 3: paddr=00060020 vaddr=42000020 size=10333ch (1061692) map
I (397) esp_image: segment 4: paddr=00163364 vaddr=4037b2f8 size=10100h ( 65792) load
I (421) boot: Loaded app from partition at offset 0x10000
I (422) boot: Disabling RNG early entropy source…
I (434) octal_psram: vendor id : 0x0d (AP)
I (434) octal_psram: dev id : 0x02 (generation 3)
I (434) octal_psram: density : 0x03 (64 Mbit)
I (439) octal_psram: good-die : 0x01 (Pass)
I (444) octal_psram: Latency : 0x01 (Fixed)
I (449) octal_psram: VCC : 0x01 (3V)
I (454) octal_psram: SRF : 0x01 (Fast Refresh)
I (460) octal_psram: BurstType : 0x01 (Hybrid Wrap)
I (466) octal_psram: BurstLen : 0x01 (32 Byte)
I (472) octal_psram: Readlatency : 0x02 (10 cycles@Fixed)
I (478) octal_psram: DriveStrength: 0x00 (1/1)
I (484) MSPI Timing: PSRAM timing tuning index: 5
I (488) esp_psram: Found 8MB PSRAM device
I (493) esp_psram: Speed: 80MHz
I (497) cpu_start: Multicore app
I (924) esp_psram: SPI SRAM memory test OK
I (932) cpu_start: Pro cpu start user code
I (932) cpu_start: cpu freq: 240000000 Hz
I (933) app_init: Application information:
I (935) app_init: Project name: hello_world
I (941) app_init: App version: 1
I (945) app_init: Compile time: Sep 12 2025 11:02:15
I (951) app_init: ELF file SHA256: 19978d182…
I (956) app_init: ESP-IDF: v5.3.2-dirty
I (961) efuse_init: Min chip rev: v0.0
I (966) efuse_init: Max chip rev: v0.99
I (971) efuse_init: Chip rev: v0.2
I (976) heap_init: Initializing. RAM available for dynamic allocation:
I (983) heap_init: At 3FCB4B98 len 00034B78 (210 KiB): RAM
I (989) heap_init: At 3FCE9710 len 00005724 (21 KiB): RAM
I (995) heap_init: At 3FCF0000 len 00008000 (32 KiB): DRAM
I (1002) heap_init: At 600FE100 len 00001EE8 (7 KiB): RTCRAM
I (1008) esp_psram: Adding pool of 8192K of PSRAM memory to heap allocator
I (1016) spi_flash: detected chip: boya
I (1020) spi_flash: flash io: dio
I (1024) sleep: Configure to isolate all GPIO pins in sleep state
I (1031) sleep: Enable automatic switching of GPIO sleep configuration
I (1038) main_task: Started on CPU0
I (1048) esp_psram: Reserving pool of 32K of internal memory for DMA/internal allocations
I (1048) main_task: Calling app_main()
I (1068) pp: pp rom version: e7ae62f
I (1068) net80211: net80211 rom version: e7ae62f
I (1078) wifi:wifi driver task: 3fcc72a0, prio:23, stack:6656, core=0
I (1078) wifi:wifi firmware version: b0fd6006b
I (1078) wifi:wifi certification version: v7.0
I (1078) wifi:config NVS flash: enabled
I (1088) wifi:config nano formating: disabled
I (1088) wifi:Init data frame dynamic rx buffer num: 64
I (1098) wifi:Init static rx mgmt buffer num: 5
I (1098) wifi:Init management short buffer num: 32
I (1098) wifi:Init static tx buffer num: 16
I (1108) wifi:Init tx cache buffer num: 32
I (1108) wifi:Init static tx FG buffer num: 2
I (1118) wifi:Init static rx buffer size: 1600
I (1118) wifi:Init static rx buffer num: 16
I (1118) wifi:Init dynamic rx buffer num: 64
I (1128) wifi_init: rx ba win: 32
I (1128) wifi_init: accept mbox: 6
I (1138) wifi_init: tcpip mbox: 32
I (1138) wifi_init: udp mbox: 6
I (1138) wifi_init: tcp mbox: 6
I (1148) wifi_init: tcp tx win: 5760
I (1148) wifi_init: tcp rx win: 28800
I (1158) wifi_init: tcp mss: 1440
I (1158) wifi_init: WiFi/LWIP prefer SPIRAM
I (1168) wifi_init: WiFi IRAM OP enabled
I (1168) wifi_init: WiFi RX IRAM OP enabled
I (1178) phy_init: phy_version 680,a6008b2,Jun 4 2024,16:41:10
I (1218) wifi:mode : sta (9c:13:9e:92:67:e0)
I (1218) wifi:enable tsf
I (1218) WIFI_STA: wifi_init_sta finished.
I (1238) wifi:new:<1,0>, old:<1,0>, ap:<255,255>, sta:<1,0>, prof:1, snd_ch_cfg:0x0
I (1238) wifi:state: init → auth (0xb0)
I (1238) wifi:state: auth → assoc (0x0)
I (1248) wifi:state: assoc → run (0x10)
I (1288) wifi:connected with zxy1416, aid = 1, channel 1, BW20, bssid = 50:88:11:ae:79:48
I (1288) wifi:security: WPA2-PSK, phy: bgn, rssi: -36
I (1298) wifi:pm start, type: 1
I (1298) wifi:dp: 1, bi: 102400, li: 3, scale listen interval from 307200 us to 307200 us
I (1308) wifi:set rx beacon pti, rx_bcn_pti: 0, bcn_timeout: 25000, mt_pti: 0, mt_time: 10000
I (1328) wifi:idx:0 (ifx:0, 50:88:11:ae:79:48), tid:0, ssn:0, winSize:64
I (1368) wifi:AP’s beacon interval = 102400 us, DTIM period = 1
I (2318) esp_netif_handlers: sta ip: 192.168.31.213, mask: 255.255.255.0, gw: 192.168.31.1
I (2318) WIFI_STA: got ip:192.168.31.213
I (2318) WIFI_STA: connected to ap SSID:zxy1416 password:2x4@U!v6
I (2468) LVGL: Starting LVGL task
I (2538) HTTP_OTA: Starting Advanced OTA
ca_cert:-----BEGIN CERTIFICATE-----
MIIEDTCCAvWgAwIBAgIURSEYFFAa8LQbGbJ6xjdgufgpQPgwDQYJKoZIhvcNAQEL
BQAwajEQMA4GA1UEAwwHUm9vdCBDQTELMAkGA1UEBhMCQ04xEzARBgNVBAgMCkd1
YW5nIERvbmcxEjAQBgNVBAcMCVNoZW4gWmhlbjEPMA0GA1UECgwGU2VydmVyMQ8w
DQYDVQQLDAZTZXJ2ZXIwIBcNMjUwOTExMDQwOTI1WhgPMjEyNTA4MTgwNDA5MjVa
MHwxIjAgBgNVBAMMGXNlY3VyZS5maWxlb3NzLmxidG9vbC5uZXQxCzAJBgNVBAYT
AkNOMRMwEQYDVQQIDApHdWFuZyBEb25nMRIwEAYDVQQHDAlTaGVuIFpoZW4xDzAN
BgNVBAoMBlNlcnZlcjEPMA0GA1UECwwGU2VydmVyMIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAsK8F/NpH+hb3PorbYfFxGbct+zAwHLdYt0JBMB0TsIjI
o4/k2YmOxyJwqAyCJKyycmkrC36sG7/sc/eCsQwxIuUPYUIEOyiWW7Mk2BodbNmg
KiqZoSYqqG//jJoMHpCZ1WeA5f+yN5dvkGn5pJbvhLgYxcG2TDv7EIuAMjJu+SpS
Wx1QmnBX+REBLJ+hytCXPuAUmNVoMiVk3sB+l5rEp6mRbSBHCyPJXhtAj7aQnOru
7PQNdcgTjR/+frDlmTtDKxqoYvfVdb2oO6guOezoeFJ4kzZma2OT0oWvT2SgYJDJ
camLGkKODiX0RhCFJlVXLJgpRfoKrKZCWJsKdl77FwIDAQABo4GWMIGTMCQGA1Ud
EQQdMBuCGXNlY3VyZS5maWxlb3NzLmxidG9vbC5uZXQwCQYDVR0TBAIwADALBgNV
HQ8EBAMCBeAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwHQYDVR0OBBYEFDd23ulgKM5h
A1J6outXJ0/R2+9zMB8GA1UdIwQYMBaAFK9QebvliYXQrzI0N2ZWwHssHT8lMA0G
CSqGSIb3DQEBCwUAA4IBAQC97zwL9xytqqnPs8gCPn+DDqfVVVb8bZazTOF25ydQ
6jn9Rci/hgjRmZCiL2D65bJsH80EDr4aGOpcUYlxJ5Ay8Ge10hs6gvExpiP2rUNK
gBSgYFUPDBzal9wQ8Z5vw7jTNl6qegFFZt8IgqcUny9aVxE7pfKFTzuBOn7Nv4VC
c48DZ9NiBHjs7V0YKl4hElEutPeWSEXutXLhmSzg1bPm6gT+4hqT3gKrbleRFVLi
XYY3TE4b10G3cmZ2sXHPvXy4KKpQBkGoXV/8O+mfPX85GI4K+5vR+4aUQMtt93Ac
z96ua1EgLI+6Os8QaV53i7M9O9y8GqHoBshBWVG5Efi0
-----END CERTIFICATE-----
I (2668) HTTP_OTA: OTA started
I (2678) wifi:idx:1 (ifx:0, 50:88:11:ae:79:48), tid:6, ssn:2, winSize:64
I (2748) mbedtls: ssl_tls.c:4608 => handshake
I (2748) mbedtls: ssl_msg.c:2353 => flush output
I (2748) mbedtls: ssl_msg.c:2362 <= flush output
I (2758) mbedtls: ssl_tls.c:4525 client state: MBEDTLS_SSL_HELLO_REQUEST
I (2758) mbedtls: ssl_msg.c:2353 => flush output
I (2768) mbedtls: ssl_msg.c:2362 <= flush output
I (2768) mbedtls: ssl_tls.c:4525 client state: MBEDTLS_SSL_CLIENT_HELLO
I (2778) mbedtls: ssl_client.c:919 => write client hello
I (2788) mbedtls: ssl_msg.c:2783 => write handshake message
I (2788) mbedtls: ssl_msg.c:2943 => write record
I (2798) mbedtls: ssl_msg.c:3080 <= write record
I (2808) mbedtls: ssl_msg.c:2904 <= write handshake message
I (2808) mbedtls: ssl_client.c:1012 <= write client hello
I (2818) mbedtls: ssl_msg.c:2353 => flush output
I (2818) mbedtls: ssl_msg.c:2367 message length: 224, out_left: 224
I (2828) mbedtls: ssl_msg.c:2374 ssl->f_send() returned 224 (-0xffffff20)
I (2838) mbedtls: ssl_msg.c:2401 <= flush output
I (2838) mbedtls: ssl_tls.c:4525 client state: MBEDTLS_SSL_SERVER_HELLO
I (2848) mbedtls: ssl_tls12_client.c:1195 => parse server hello
I (2858) mbedtls: ssl_msg.c:4189 => read record
I (2858) mbedtls: ssl_msg.c:2155 => fetch input
I (2868) mbedtls: ssl_msg.c:2295 in_left: 0, nb_want: 5
I (2868) mbedtls: ssl_msg.c:2315 in_left: 0, nb_want: 5
I (2878) mbedtls: ssl_msg.c:2318 ssl->f_recv(_timeout)() returned 5 (-0xfffffffb)
I (2888) mbedtls: ssl_msg.c:2340 <= fetch input
I (2888) mbedtls: ssl_msg.c:2155 => fetch input
I (2898) mbedtls: ssl_msg.c:2295 in_left: 5, nb_want: 98
I (2908) mbedtls: ssl_msg.c:2315 in_left: 5, nb_want: 98
I (2908) mbedtls: ssl_msg.c:2318 ssl->f_recv(_timeout)() returned 93 (-0xffffffa3)
I (2918) mbedtls: ssl_msg.c:2340 <= fetch input
I (2928) mbedtls: ssl_msg.c:4261 <= read record
I (2928) mbedtls: ssl_tls12_client.c:1447 server hello, total extension length: 17
I (2938) mbedtls: ssl_tls12_client.c:1661 <= parse server hello
I (2948) mbedtls: ssl_msg.c:2353 => flush output
I (2948) mbedtls: ssl_msg.c:2362 <= flush output
I (2958) mbedtls: ssl_tls.c:4525 client state: MBEDTLS_SSL_SERVER_CERTIFICATE
I (2968) mbedtls: ssl_tls.c:7964 => parse certificate
I (2968) mbedtls: ssl_msg.c:4189 => read record
I (2978) mbedtls: ssl_msg.c:2155 => fetch input
I (2978) mbedtls: ssl_msg.c:2295 in_left: 0, nb_want: 5
I (2988) mbedtls: ssl_msg.c:2315 in_left: 0, nb_want: 5
I (2988) mbedtls: ssl_msg.c:2318 ssl->f_recv(_timeout)() returned 5 (-0xfffffffb)
I (2998) mbedtls: ssl_msg.c:2340 <= fetch input
I (3008) mbedtls: ssl_msg.c:2155 => fetch input
I (3008) mbedtls: ssl_msg.c:2295 in_left: 5, nb_want: 2776
I (3018) mbedtls: ssl_msg.c:2315 in_left: 5, nb_want: 2776
I (3028) mbedtls: ssl_msg.c:2318 ssl->f_recv(_timeout)() returned 2771 (-0xfffff52d)
I (3028) mbedtls: ssl_msg.c:2340 <= fetch input
I (3048) mbedtls: ssl_msg.c:4261 <= read record
Verifying certificate 1, flags:00000008
Verifying certificate 0, flags:00000000
W (3078) mbedtls: ssl_tls.c:9859 x509_verify_cert() returned -9984 (-0x2700)
I (3078) mbedtls: ssl_msg.c:5168 => send alert message
I (3088) mbedtls: ssl_msg.c:2943 => write record
I (3088) mbedtls: ssl_msg.c:2353 => flush output
I (3098) mbedtls: ssl_msg.c:2367 message length: 7, out_left: 7
I (3098) mbedtls: ssl_msg.c:2374 ssl->f_send() returned 7 (-0xfffffff9)
I (3108) mbedtls: ssl_msg.c:2401 <= flush output
I (3118) mbedtls: ssl_msg.c:3080 <= write record
I (3118) mbedtls: ssl_msg.c:5180 <= send alert message
I (3128) mbedtls: ssl_tls.c:4619 <= handshake
E (3128) esp-tls-mbedtls: mbedtls_ssl_handshake returned -0x2700
I (3138) esp-tls-mbedtls: Failed to verify peer certificate!
E (3148) esp-tls: Failed to open new connection
E (3148) transport_base: Failed to open a new connection
E (3158) HTTP_CLIENT: Connection failed, sock < 0
E (3158) esp_https_ota: ESP HTTP client perform failed: 28674
E (3168) HTTP_OTA: ESP HTTPS OTA Begin failed
my setting:
[req]
distinguished_name = dn
x509_extensions = v3_req
prompt = no
[dn]
CN = secure.fileoss.lbtool.net
C = CN
ST = Guang Dong
L = Shen Zhen
O = Server
OU = Server
[v3_req]
subjectAltName = DNS:secure.fileoss.lbtool.net
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth