Caller-owned TLS 1.3 certificate handshake for QUIC CRYPTO streams.
Feed only new contiguous handshake bytes at the level reported by info/1.
Process returned actions in list order. Emitted bytes are committed to the
caller's reliable send queue; retransmission reuses them without another TLS
call. This API implements no sockets, records, QUIC packets or HANDSHAKE_DONE.
See docs/QUIC_TLS_INTERFACE.md for the ownership and authentication boundary.
Summary
Types
@type action() :: SSL.QUIC.Secret.t() | {:emit, level(), binary()} | {:peer_transport_parameters, binary(), :unverified | :authenticated} | {:peer_authenticated, :server} | {:negotiated_alpn, binary()} | :handshake_complete | {:error, SSL.QUIC.Error.t()}
@type level() :: :initial | :handshake | :application
@type result() :: {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t(), state(), [action()]}
@opaque state()
Functions
@spec new(:client | :server, keyword()) :: {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t()}