# `SSL.Crypto.KeyExchange`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/crypto/key_exchange.ex#L1)

Fresh ephemeral key generation and shared-secret computation for TLS groups.

Runtime support is determined by the crypto provider linked to OTP.

# `error_reason`

```elixir
@type error_reason() ::
  {:unsupported_group, term()}
  | {:unsupported_capability, group()}
  | {:key_generation_failed, group()}
  | {:invalid_private_key, group()}
  | {:invalid_peer_public_key, group()}
  | {:key_pair_mismatch, group()}
  | :invalid_key_pair
```

# `group`

```elixir
@type group() :: SSL.Crypto.KeyExchange.KeyPair.group()
```

# `generate`

```elixir
@spec generate(term()) ::
  {:ok, SSL.Crypto.KeyExchange.KeyPair.t()} | {:error, error_reason()}
```

# `shared_secret`

```elixir
@spec shared_secret(SSL.Crypto.KeyExchange.KeyPair.t(), term()) ::
  {:ok, binary()} | {:error, error_reason()}
```

# `supported?`

```elixir
@spec supported?(term()) :: boolean()
```

# `validate_key_pair`

```elixir
@spec validate_key_pair(term()) :: :ok | {:error, error_reason()}
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
