SSL (ex_ssl v0.16.7)

Copy Markdown View Source

OTP :ssl-compatible client facade for the implemented ex_ssl feature subset.

This experimental client supports TLS 1.3 and explicit bounded TLS 1.2, binary raw sockets, passive and active-once delivery, application ownership transfer, authenticated ALPN, bounded streaming writes, and mandatory peer verification. These restricted defaults differ from OTP. Unsupported options return explicit {:error, {:options, reason}} errors.

STARTTLS callers must own a passive binary/raw TCP socket, fully consume and validate the application's upgrade response, and reject any buffered plaintext. Supply server_name_indication as the certificate reference DNS name. Once upgrade is attempted, an owned socket is closed on failure; plaintext must never resume. A socket belonging to another process is left untouched.

Summary

Functions

Closes the connection. Closing an already closed handle succeeds.

Returns the supported non-secret connection metadata.

Transfers application ownership while the TLS process retains the TCP socket.

Returns the authenticated ALPN selection, if the server negotiated one.

Returns the authenticated server leaf certificate as DER.

Returns the live TCP peer address and port.

Receives available bytes for length 0, or exactly length bytes. Timeout retains buffered data.

Writes iodata as one ordered logical write. Concurrent writes return :busy.

Changes supported delivery, send, and mutable TCP options after validation.

Returns the live local TCP address and port.

Functions

close(socket)

@spec close(SSL.Socket.t()) :: :ok | {:error, term()}

Closes the connection. Closing an already closed handle succeeds.

connect(tcp_socket, options)

@spec connect(:gen_tcp.socket(), list()) :: {:ok, SSL.Socket.t()} | {:error, term()}

connect(host, port, options)

@spec connect(term(), term(), term()) :: {:ok, SSL.Socket.t()} | {:error, term()}

connect(host, port, options, timeout)

@spec connect(term(), :inet.port_number(), list(), timeout()) ::
  {:ok, SSL.Socket.t()} | {:error, term()}

connection_information(socket)

@spec connection_information(SSL.Socket.t()) :: {:ok, keyword()} | {:error, term()}

Returns the supported non-secret connection metadata.

connection_information(socket, keys)

@spec connection_information(SSL.Socket.t(), term()) ::
  {:ok, keyword()} | {:error, term()}

controlling_process(socket, owner)

@spec controlling_process(SSL.Socket.t(), pid()) :: :ok | {:error, term()}

Transfers application ownership while the TLS process retains the TCP socket.

negotiated_protocol(socket)

@spec negotiated_protocol(SSL.Socket.t()) :: {:ok, binary()} | {:error, term()}

Returns the authenticated ALPN selection, if the server negotiated one.

peercert(socket)

@spec peercert(SSL.Socket.t()) :: {:ok, binary()} | {:error, term()}

Returns the authenticated server leaf certificate as DER.

peername(socket)

@spec peername(SSL.Socket.t()) ::
  {:ok, {:inet.ip_address(), :inet.port_number()}} | {:error, term()}

Returns the live TCP peer address and port.

recv(socket, length, timeout \\ :infinity)

@spec recv(SSL.Socket.t(), non_neg_integer(), timeout()) ::
  {:ok, binary()} | {:error, term()}

Receives available bytes for length 0, or exactly length bytes. Timeout retains buffered data.

send(socket, data)

@spec send(SSL.Socket.t(), iodata()) :: :ok | {:error, term()}

Writes iodata as one ordered logical write. Concurrent writes return :busy.

setopts(socket, options)

@spec setopts(SSL.Socket.t(), list()) :: :ok | {:error, term()}

Changes supported delivery, send, and mutable TCP options after validation.

sockname(socket)

@spec sockname(SSL.Socket.t()) ::
  {:ok, {:inet.ip_address(), :inet.port_number()}} | {:error, term()}

Returns the live local TCP address and port.