# `SSL.PKIX`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/pkix/pkix.ex#L1)

Pure, bounded certificate decoding, trust normalization, and peer verification.

Certificate chains are accepted in TLS leaf-first order. Trust sources are
supplied in memory as a DER list or PEM bundle; this module performs no file,
network, or operating-system trust lookup.

# `error_reason`

```elixir
@type error_reason() ::
  :empty_certificate_chain
  | :empty_trust_anchors
  | :hostname_mismatch
  | :malformed_pem
  | {:invalid_input, :certificate_chain | :trust_source | :options}
  | {:invalid_identity, term()}
  | {:invalid_certificate, non_neg_integer()}
  | {:certificate_count_limit_exceeded, non_neg_integer(), pos_integer()}
  | {:certificate_der_limit_exceeded, non_neg_integer(), non_neg_integer(),
     pos_integer()}
  | {:certificate_total_der_limit_exceeded, non_neg_integer(), pos_integer()}
  | {:pem_limit_exceeded, non_neg_integer(), pos_integer()}
  | {:path_validation_failed, term()}
  | {:certificate_signature_scheme_not_allowed, [non_neg_integer()]}
```

# `identity`

```elixir
@type identity() :: {:dns_id, binary()} | {:ip, binary() | :inet.ip_address()}
```

# `option`

```elixir
@type option() ::
  {:max_certificates, pos_integer()}
  | {:max_trust_anchors, pos_integer()}
  | {:max_der_bytes, pos_integer()}
  | {:max_total_der_bytes, pos_integer()}
  | {:max_pem_bytes, pos_integer()}
  | {:depth, non_neg_integer()}
  | {:customize_hostname_check, keyword()}
  | {:certificate_signature_schemes, [non_neg_integer()] | nil}
```

# `decode_chain`

```elixir
@spec decode_chain(term(), [option()]) ::
  {:ok, [SSL.PKIX.Certificate.t()]} | {:error, error_reason()}
```

# `normalize_trust`

```elixir
@spec normalize_trust(term(), [option()]) ::
  {:ok, [SSL.PKIX.Certificate.t()]} | {:error, error_reason()}
```

# `verify`

```elixir
@spec verify(term(), term(), term(), [option()]) ::
  {:ok, SSL.PKIX.VerifiedPeer.t()} | {:error, error_reason()}
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
