Pure TLS 1.3 key-schedule derivations.
Callers supply exact transcript hashes at each protocol checkpoint. Derived traffic states start at sequence zero for a new traffic epoch.
Summary
Types
@type error_reason() :: :unsupported_hash | {:unsupported_cipher_suite, term()} | {:invalid_input, :psk | :shared_secret | :ticket_nonce | :transcript_hash} | {:invalid_secret_length, atom(), pos_integer()} | {:invalid_input, :empty_shared_secret} | {:invalid_transcript_hash_length, pos_integer()} | {:ticket_nonce_too_long, 255}
@type hash() :: :sha256 | :sha384
Functions
@spec client_application_traffic_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec client_handshake_traffic_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec derived_secret(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec early_secret(hash(), binary() | nil) :: {:ok, binary()} | {:error, error_reason()}
@spec exporter_master_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec handshake_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec master_secret(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec resumption_master_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec resumption_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec server_application_traffic_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec server_handshake_traffic_secret(hash(), binary(), binary()) :: {:ok, binary()} | {:error, error_reason()}
@spec traffic_state(SSL.Crypto.TrafficState.cipher_suite(), binary()) :: {:ok, SSL.Crypto.TrafficState.t()} | {:error, error_reason()}
@spec traffic_update(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}