Pure, bounded certificate decoding, trust normalization, and peer verification.
Certificate chains are accepted in TLS leaf-first order. Trust sources are supplied in memory as a DER list or PEM bundle; this module performs no file, network, or operating-system trust lookup.
Summary
Types
@type error_reason() :: :empty_certificate_chain | :empty_trust_anchors | :hostname_mismatch | :malformed_pem | {:invalid_input, :certificate_chain | :trust_source | :options} | {:invalid_identity, term()} | {:invalid_certificate, non_neg_integer()} | {:certificate_count_limit_exceeded, non_neg_integer(), pos_integer()} | {:certificate_der_limit_exceeded, non_neg_integer(), non_neg_integer(), pos_integer()} | {:certificate_total_der_limit_exceeded, non_neg_integer(), pos_integer()} | {:pem_limit_exceeded, non_neg_integer(), pos_integer()} | {:path_validation_failed, term()} | {:certificate_signature_scheme_not_allowed, [non_neg_integer()]}
@type identity() :: {:dns_id, binary()} | {:ip, binary() | :inet.ip_address()}
@type option() :: {:max_certificates, pos_integer()} | {:max_trust_anchors, pos_integer()} | {:max_der_bytes, pos_integer()} | {:max_total_der_bytes, pos_integer()} | {:max_pem_bytes, pos_integer()} | {:depth, non_neg_integer()} | {:customize_hostname_check, keyword()} | {:certificate_signature_schemes, [non_neg_integer()] | nil}
Functions
@spec decode_chain(term(), [option()]) :: {:ok, [SSL.PKIX.Certificate.t()]} | {:error, error_reason()}
@spec normalize_trust(term(), [option()]) :: {:ok, [SSL.PKIX.Certificate.t()]} | {:error, error_reason()}
@spec verify(term(), term(), term(), [option()]) :: {:ok, SSL.PKIX.VerifiedPeer.t()} | {:error, error_reason()}