SSL.Crypto.Signature (ex_ssl v0.16.7)

Copy Markdown View Source

TLS 1.3 CertificateVerify and raw TLS 1.2 handshake signatures.

This module verifies handshake signatures only. Certificate path and service identity validation remain separate PKIX responsibilities.

Summary

Types

error_reason()

@type error_reason() ::
  :unsupported_hash
  | :invalid_certificate_verify
  | :signature_verification_failed
  | :empty_signature
  | :invalid_public_key
  | {:unsupported_signature_scheme, term()}
  | {:invalid_input, :transcript_hash | :signature}
  | {:invalid_transcript_hash_length, pos_integer()}
  | {:key_type_mismatch, :ecdsa | :rsa | :rsa_pss | :eddsa}
  | {:unsupported_ec_curve, atom() | tuple()}
  | :invalid_ecdsa_signature_encoding
  | :invalid_rsa_pss_parameters

signature_scheme()

@type signature_scheme() :: 1027 | 1283 | 2052..2055 | 2057..2059

Functions

client_signed_content(hash, transcript_hash)

@spec client_signed_content(atom(), term()) ::
  {:error,
   :unsupported_hash
   | {:invalid_input, :transcript_hash}
   | {:invalid_transcript_hash_length, 32 | 48 | 64}}
  | {:ok, <<_::64, _::_*8>>}

server_signed_content(hash, transcript_hash)

@spec server_signed_content(atom(), term()) ::
  {:error,
   :unsupported_hash
   | {:invalid_input, :transcript_hash}
   | {:invalid_transcript_hash_length, 32 | 48 | 64}}
  | {:ok, <<_::64, _::_*8>>}

sign_client(signature_scheme, private_key, transcript_hash_algorithm, transcript_digest)

@spec sign_client(term(), term(), atom(), term()) ::
  {:ok, binary()} | {:error, error_reason()}

sign_message(signature_scheme, private_key, data)

@spec sign_message(term(), term(), term()) ::
  {:error,
   :invalid_rsa_pss_parameters
   | :signature_verification_failed
   | {:invalid_input, :message}
   | {:key_type_mismatch, term()}
   | {:unsupported_signature_scheme, term()}}
  | {:ok, binary()}

Signs exact TLS 1.2 handshake bytes without a TLS 1.3 CertificateVerify context.

sign_server(scheme, key, hash, digest)

@spec sign_server(term(), term(), atom(), term()) ::
  {:ok, binary()} | {:error, error_reason()}

signed_content(role, hash, transcript_hash)

@spec signed_content(:server | :client, atom(), term()) ::
  {:ok, binary()} | {:error, error_reason()}

verify_client(signature_scheme, public_key, transcript_hash_algorithm, transcript_digest, signature)

@spec verify_client(term(), term(), atom(), term(), term()) ::
  :ok | {:error, error_reason()}

verify_message(signature_scheme, public_key, data, signature)

@spec verify_message(term(), term(), term(), term()) ::
  :ok
  | {:error,
     :empty_signature
     | :invalid_certificate_verify
     | :invalid_ecdsa_signature_encoding
     | :invalid_public_key
     | :invalid_rsa_pss_parameters
     | :signature_verification_failed
     | {:invalid_input, :message | :signature}
     | {:key_type_mismatch, :ecdsa | :eddsa | :rsa | :rsa_pss}
     | {:unsupported_ec_curve, term()}
     | {:unsupported_signature_scheme, term()}}

Verifies exact TLS 1.2 handshake bytes without a TLS 1.3 CertificateVerify context.

verify_server(signature_scheme, public_key, transcript_hash_algorithm, transcript_digest, signature)

@spec verify_server(term(), term(), atom(), term(), term()) ::
  :ok | {:error, error_reason()}