Validates wire profiles against explicit engine/runtime capabilities.
Validation is intentionally fail-closed. Raw extensions require a specific
extension ID in the optional :raw_extensions capability allowlist.
Summary
Types
Capabilities the current TLS engine can safely advertise.
Types
@type capabilities() :: %{ :versions => [SSL.ClientHello.WireProfile.version()], :ciphers => [SSL.ClientHello.WireProfile.cipher_suite()], :groups => [SSL.ClientHello.WireProfile.group()], optional(:raw_extensions) => [0..65535], optional(:record_modes) => [:default | :none], optional(:signature_algorithms) => [atom() | 0..65535], optional(:certificate_signature_algorithms) => [atom() | 0..65535], optional(:psk_key_exchange_modes) => [atom() | 0..255], optional(:key_share_sizes) => %{ optional(SSL.ClientHello.WireProfile.group()) => pos_integer() } }
Capabilities the current TLS engine can safely advertise.
Functions
@spec validate(SSL.ClientHello.WireProfile.t(), capabilities()) :: {:ok, SSL.ClientHello.WireProfile.t()} | {:error, term()}