quic_cert (quic v2.0.2)
View SourceSummary
Functions
Read trust anchors from a PEM file as DER.
Turn a cacertfile option into the DER cacerts the rest of the library takes.
Validate a client's certificate chain (mutual TLS, RFC 8446 §4.4.2.4).
Validate a server's certificate chain and identity.
Functions
-spec cacerts_from_file(file:name_all()) -> {ok, [public_key:der_encoded()]} | {error, {cacertfile, file:name_all(), term()}}.
Read trust anchors from a PEM file as DER.
A bundle yields every certificate in it. A file that cannot be read, or that holds no certificate, is an error rather than an empty list: empty anchors mean trust nothing, which fails every later handshake with a reason that says nothing about the file.
Turn a cacertfile option into the DER cacerts the rest of the library takes.
Called once where a connection or server starts, so the file is read once and a bad path fails the call that named it. An explicit cacerts is what the caller already resolved, so it wins.
-spec validate_client(binary() | undefined, [binary()], [binary()] | undefined) -> ok | {error, term()}.
Validate a client's certificate chain (mutual TLS, RFC 8446 §4.4.2.4).
Same trust-anchor chain validation as validate_server/4, but with no identity/hostname check: a client certificate is not bound to a server name, and the peer's application identity is established separately (e.g. from the certificate subject plus an out-of-band token). Leaf is the client's end-entity certificate (DER), Intermediates the rest of the chain in wire (leaf-to-root) order, and CaCerts the trust anchors (DER list, or undefined for the OS trust store).
-spec validate_server(binary() | undefined, [binary()], [binary()] | undefined, binary() | undefined) -> ok | {error, term()}.
Validate a server's certificate chain and identity.
Leaf is the server's end-entity certificate (DER). Intermediates are the remaining certificates sent by the peer (DER), in the leaf-to-root order they arrive on the wire. CaCerts are the trust anchors as a DER list, or undefined to use the OS trust store. ServerName is the expected identity (binary hostname or IP literal), or undefined to skip the hostname check.