Bounded codecs for the encrypted TLS 1.3 server handshake flight.
Decoding accepts one complete handshake message and preserves its exact
encoded bytes. Stream fragmentation remains the responsibility of
SSL.Protocol.HandshakeFramer. Bounded NewSessionTicket and KeyUpdate codecs
let the connection runtime apply post-handshake epoch transitions explicitly.
Summary
Types
@type decoded() ::
SSL.Protocol.ServerFlight.EncryptedExtensions.t()
| SSL.Protocol.ServerFlight.Certificate.t()
| SSL.Protocol.ServerFlight.CertificateVerify.t()
| SSL.Protocol.ServerFlight.Finished.t()
| SSL.Protocol.ServerFlight.CertificateRequest.t()
| SSL.Protocol.ServerFlight.NewSessionTicket.t()
| SSL.Protocol.ServerFlight.KeyUpdate.t()
Functions
@spec encode_client_certificate_verify(non_neg_integer(), binary()) :: {:ok, binary()} | {:error, term()}
@spec encode_key_update(boolean()) :: {:ok, <<_::40>>}