SSL.Protocol.ServerFlight (ex_ssl v0.16.7)

Copy Markdown View Source

Bounded codecs for the encrypted TLS 1.3 server handshake flight.

Decoding accepts one complete handshake message and preserves its exact encoded bytes. Stream fragmentation remains the responsibility of SSL.Protocol.HandshakeFramer. Bounded NewSessionTicket and KeyUpdate codecs let the connection runtime apply post-handshake epoch transitions explicitly.

Summary

Types

decoded()

@type decoded() ::
  SSL.Protocol.ServerFlight.EncryptedExtensions.t()
  | SSL.Protocol.ServerFlight.Certificate.t()
  | SSL.Protocol.ServerFlight.CertificateVerify.t()
  | SSL.Protocol.ServerFlight.Finished.t()
  | SSL.Protocol.ServerFlight.CertificateRequest.t()
  | SSL.Protocol.ServerFlight.NewSessionTicket.t()
  | SSL.Protocol.ServerFlight.KeyUpdate.t()

Functions

decode(input, opts \\ [])

@spec decode(term(), keyword()) ::
  {:ok, decoded(), binary()} | {:more, pos_integer()} | {:error, term()}

encode_client_certificate(context, chain)

@spec encode_client_certificate(binary(), [binary()]) ::
  {:ok, binary()} | {:error, term()}

encode_client_certificate_verify(scheme, signature)

@spec encode_client_certificate_verify(non_neg_integer(), binary()) ::
  {:ok, binary()} | {:error, term()}

encode_empty_certificate(context)

@spec encode_empty_certificate(binary()) :: {:ok, binary()} | {:error, term()}

encode_finished(verify_data, opts \\ [])

@spec encode_finished(term(), keyword()) :: {:ok, binary()} | {:error, term()}

encode_key_update(request_update)

@spec encode_key_update(boolean()) :: {:ok, <<_::40>>}