# ex_ssl v0.16.7 - Table of Contents > An independent Elixir/OTP TLS stack with programmable ClientHello wire profiles ## Modules - [SSL](SSL.md): OTP `:ssl`-compatible client facade for the implemented `ex_ssl` feature subset. - [SSL.ClientHello.AST](SSL.ClientHello.AST.md): Public, fully materialized ClientHello fields in exact wire order. - [SSL.ClientHello.Extension](SSL.ClientHello.Extension.md): Encodes fully materialized ClientHello extensions. - [SSL.ClientHello.GreasePolicy](SSL.ClientHello.GreasePolicy.md): Declares GREASE behavior for a ClientHello wire profile. - [SSL.ClientHello.Materializer](SSL.ClientHello.Materializer.md): Resolves a reusable wire profile into per-connection ClientHello material. - [SSL.ClientHello.Materializer.Materialized](SSL.ClientHello.Materializer.Materialized.md): A public ClientHello AST and its separately retained ephemeral key pairs. - [SSL.ClientHello.Profile](SSL.ClientHello.Profile.md): Validates wire profiles against explicit engine/runtime capabilities. - [SSL.ClientHello.RecordPolicy](SSL.ClientHello.RecordPolicy.md): Declares record handling for a ClientHello wire profile. - [SSL.ClientHello.Serializer](SSL.ClientHello.Serializer.md): Encodes a fully materialized ClientHello AST as an exact handshake message. - [SSL.ClientHello.WireProfile](SSL.ClientHello.WireProfile.md): Ordered, declarative configuration for a TLS ClientHello. - [SSL.Crypto.AEAD](SSL.Crypto.AEAD.md): Pure TLS 1.3 AEAD encryption and authenticated decryption. - [SSL.Crypto.Finished](SSL.Crypto.Finished.md): TLS 1.3 Finished verify-data calculation and constant-time verification. - [SSL.Crypto.HKDF](SSL.Crypto.HKDF.md): HKDF and TLS 1.3 labeled key derivation. - [SSL.Crypto.KeyExchange](SSL.Crypto.KeyExchange.md): Fresh ephemeral key generation and shared-secret computation for TLS groups. - [SSL.Crypto.KeyExchange.KeyPair](SSL.Crypto.KeyExchange.KeyPair.md): Ephemeral key material for one key exchange. - [SSL.Crypto.KeySchedule](SSL.Crypto.KeySchedule.md): Pure TLS 1.3 key-schedule derivations. - [SSL.Crypto.Signature](SSL.Crypto.Signature.md): TLS 1.3 CertificateVerify and raw TLS 1.2 handshake signatures. - [SSL.Crypto.TLS12KeySchedule](SSL.Crypto.TLS12KeySchedule.md): Pure TLS 1.2 PRF and Extended Master Secret derivation for the bounded ECDHE-GCM subset. - [SSL.Crypto.TrafficState](SSL.Crypto.TrafficState.md): Immutable key material and record sequence state for one TLS traffic epoch. - [SSL.Fingerprint](SSL.Fingerprint.md): JA3 and JA4 observation of exact, naked ClientHello handshake bytes. - [SSL.PKIX](SSL.PKIX.md): Pure, bounded certificate decoding, trust normalization, and peer verification. - [SSL.PKIX.Certificate](SSL.PKIX.Certificate.md): A bounded X.509 certificate retaining both its exact DER and decoded OTP form. - [SSL.PKIX.VerifiedPeer](SSL.PKIX.VerifiedPeer.md): The authenticated leaf material needed by later handshake verification. - [SSL.Protocol.ClientHandshake](SSL.Protocol.ClientHandshake.md): Shared record-free ClientHello and HelloRetryRequest orchestration. - [SSL.Protocol.ClientOffer](SSL.Protocol.ClientOffer.md): Bounded extraction of negotiation inputs from one exact ClientHello message. - [SSL.Protocol.HandshakeCore](SSL.Protocol.HandshakeCore.md): Shared TLS 1.3 authentication and secret derivation over exact handshake bytes. - [SSL.Protocol.HandshakeFramer](SSL.Protocol.HandshakeFramer.md): Frames complete TLS handshake messages from an arbitrarily chunked byte stream. - [SSL.Protocol.HandshakeMachine](SSL.Protocol.HandshakeMachine.md): Pure TLS client coordinator consuming one complete record at a time. - [SSL.Protocol.InnerPlaintext](SSL.Protocol.InnerPlaintext.md): Bounded TLS 1.3 inner plaintext encoding and decoding. - [SSL.Protocol.Record](SSL.Protocol.Record.md): Pure TLS 1.3 encrypted record protection for one complete framed record. - [SSL.Protocol.RecordFramer](SSL.Protocol.RecordFramer.md): Frames complete TLS records from an arbitrarily chunked byte stream. - [SSL.Protocol.Resumption](SSL.Protocol.Resumption.md): Pure TLS 1.3 resumption ticket binder construction over exact ClientHello bytes. - [SSL.Protocol.ServerFlight](SSL.Protocol.ServerFlight.md): Bounded codecs for the encrypted TLS 1.3 server handshake flight. - [SSL.Protocol.ServerFlightVerifier](SSL.Protocol.ServerFlightVerifier.md): TLS record adapter for the shared record-free handshake core. - [SSL.Protocol.ServerFlightVerifier.Input](SSL.Protocol.ServerFlightVerifier.Input.md): Exact public handshake inputs and fresh per-connection client key material. - [SSL.Protocol.ServerFlightVerifier.Result](SSL.Protocol.ServerFlightVerifier.Result.md): Verified peer and traffic epochs ready for later connection orchestration. - [SSL.Protocol.ServerHandshake](SSL.Protocol.ServerHandshake.md): Record-free TLS 1.3 full-certificate server handshake operations. - [SSL.Protocol.ServerHello](SSL.Protocol.ServerHello.md): Pure, bounded decoder for TLS 1.3 ServerHello and HelloRetryRequest messages. - [SSL.Protocol.TLS12](SSL.Protocol.TLS12.md): Pure, bounded TLS 1.2 ECDHE/EMS client protocol engine. - [SSL.Protocol.TLS12Codec](SSL.Protocol.TLS12Codec.md): Bounded codecs for complete TLS 1.2 handshake messages. - [SSL.Protocol.TLS12Record](SSL.Protocol.TLS12Record.md): Pure TLS 1.2 AES-GCM record protection for one directional traffic epoch. - [SSL.Protocol.Transcript](SSL.Protocol.Transcript.md): Immutable storage and hashing for exact encoded TLS handshake messages. - [SSL.QUIC](SSL.QUIC.md): Caller-owned TLS 1.3 certificate handshake for QUIC CRYPTO streams. - [SSL.QUIC.Error](SSL.QUIC.Error.md): Redacted TLS, QUIC integration, or local API error. - [SSL.QUIC.Secret](SSL.QUIC.Secret.md): A directional TLS traffic secret. Inspection never reveals its bytes. - [SSL.SessionTicket](SSL.SessionTicket.md): Bounded, authenticated TLS 1.3 ticket material retained in memory only. - [SSL.Socket](SSL.Socket.md): An opaque handle to one ex_ssl connection. Contains no TLS key material. - [SSL.TicketCache](SSL.TicketCache.md): Bounded, one-use, in-memory TLS 1.3 ticket cache.