# `SSL.Protocol.ServerFlight`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/protocol/server_flight.ex#L1)

Bounded codecs for the encrypted TLS 1.3 server handshake flight.

Decoding accepts one complete handshake message and preserves its exact
encoded bytes. Stream fragmentation remains the responsibility of
`SSL.Protocol.HandshakeFramer`. Bounded NewSessionTicket and KeyUpdate codecs
let the connection runtime apply post-handshake epoch transitions explicitly.

# `decoded`

```elixir
@type decoded() ::
  SSL.Protocol.ServerFlight.EncryptedExtensions.t()
  | SSL.Protocol.ServerFlight.Certificate.t()
  | SSL.Protocol.ServerFlight.CertificateVerify.t()
  | SSL.Protocol.ServerFlight.Finished.t()
  | SSL.Protocol.ServerFlight.CertificateRequest.t()
  | SSL.Protocol.ServerFlight.NewSessionTicket.t()
  | SSL.Protocol.ServerFlight.KeyUpdate.t()
```

# `decode`

```elixir
@spec decode(term(), keyword()) ::
  {:ok, decoded(), binary()} | {:more, pos_integer()} | {:error, term()}
```

# `encode_client_certificate`

```elixir
@spec encode_client_certificate(binary(), [binary()]) ::
  {:ok, binary()} | {:error, term()}
```

# `encode_client_certificate_verify`

```elixir
@spec encode_client_certificate_verify(non_neg_integer(), binary()) ::
  {:ok, binary()} | {:error, term()}
```

# `encode_empty_certificate`

```elixir
@spec encode_empty_certificate(binary()) :: {:ok, binary()} | {:error, term()}
```

# `encode_finished`

```elixir
@spec encode_finished(term(), keyword()) :: {:ok, binary()} | {:error, term()}
```

# `encode_key_update`

```elixir
@spec encode_key_update(boolean()) :: {:ok, &lt;&lt;_::40&gt;&gt;}
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
