SSL.ClientHello.Profile (ex_ssl v0.16.7)

Copy Markdown View Source

Validates wire profiles against explicit engine/runtime capabilities.

Validation is intentionally fail-closed. Raw extensions require a specific extension ID in the optional :raw_extensions capability allowlist.

Summary

Types

Capabilities the current TLS engine can safely advertise.

Types

capabilities()

@type capabilities() :: %{
  :versions => [SSL.ClientHello.WireProfile.version()],
  :ciphers => [SSL.ClientHello.WireProfile.cipher_suite()],
  :groups => [SSL.ClientHello.WireProfile.group()],
  optional(:raw_extensions) => [0..65535],
  optional(:record_modes) => [:default | :none],
  optional(:signature_algorithms) => [atom() | 0..65535],
  optional(:certificate_signature_algorithms) => [atom() | 0..65535],
  optional(:psk_key_exchange_modes) => [atom() | 0..255],
  optional(:key_share_sizes) => %{
    optional(SSL.ClientHello.WireProfile.group()) => pos_integer()
  }
}

Capabilities the current TLS engine can safely advertise.

Functions

validate(profile, capabilities)

@spec validate(SSL.ClientHello.WireProfile.t(), capabilities()) ::
  {:ok, SSL.ClientHello.WireProfile.t()} | {:error, term()}