# `SSL.ClientHello.Profile`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/client_hello/profile.ex#L1)

Validates wire profiles against explicit engine/runtime capabilities.

Validation is intentionally fail-closed. Raw extensions require a specific
extension ID in the optional `:raw_extensions` capability allowlist.

# `capabilities`

```elixir
@type capabilities() :: %{
  :versions =&gt; [SSL.ClientHello.WireProfile.version()],
  :ciphers =&gt; [SSL.ClientHello.WireProfile.cipher_suite()],
  :groups =&gt; [SSL.ClientHello.WireProfile.group()],
  optional(:raw_extensions) =&gt; [0..65535],
  optional(:record_modes) =&gt; [:default | :none],
  optional(:signature_algorithms) =&gt; [atom() | 0..65535],
  optional(:certificate_signature_algorithms) =&gt; [atom() | 0..65535],
  optional(:psk_key_exchange_modes) =&gt; [atom() | 0..255],
  optional(:key_share_sizes) =&gt; %{
    optional(SSL.ClientHello.WireProfile.group()) =&gt; pos_integer()
  }
}
```

Capabilities the current TLS engine can safely advertise.

# `validate`

```elixir
@spec validate(SSL.ClientHello.WireProfile.t(), capabilities()) ::
  {:ok, SSL.ClientHello.WireProfile.t()} | {:error, term()}
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
