Holds server certificates, picks one per connection by SNI (RFC 6066), and reloads them when their files change.
children = [
{Sovite.TLS.CertStore,
name: MyApp.Certs,
certificates: [
%{cert_file: "/etc/tls/mx.example.com.pem", key_file: "/etc/tls/mx.example.com.key"},
%{cert_file: "/etc/tls/mail.example.org.pem", key_file: "/etc/tls/mail.example.org.key"}
]}
]
ssl_opts = Sovite.TLS.CertStore.server_options(MyApp.Certs)A client asking for a name gets every certificate valid for it (for
example both an RSA and an ECDSA one; :ssl picks what the client
supports). Clients without SNI, or asking for an unknown name, get the
default: the first certificate, with any others for exactly the same
names.
Files are checked every :reload_interval and reloaded when their
size, modification time, or inode changes. A file that fails to load
keeps its previous certificate, so a half-written renewal does not
take TLS down. reload/1 forces a check.
Options
:certificates- a list of%{cert_file, key_file}maps, seeSovite.TLS.Certificate.load/2. Addoptional: trueto skip a pair whose files do not exist yet, such as one an ACME client will write. Required.:tls- options forSovite.TLS.server_options/1, such as:min_versionand:ciphers.:reload_interval- milliseconds, ornilto never check. Defaults to 60 seconds.:name- registered name.
Starting fails if a required certificate cannot be loaded.
Telemetry
[:sovite, :tls, :certificate, :loaded]-%{},%{cert_file, names, not_after}[:sovite, :tls, :certificate, :error]-%{},%{cert_file, reason}(aSovite.TLS.Certificate.error())
Summary
Functions
Returns the loaded certificates, default first.
Checks the files now and reloads what changed.
Returns :ssl server options for the current certificates, or nil
when none is loaded. Call it per connection, so reloaded certificates
apply to new connections.
Starts the store.
Functions
@spec certificates(GenServer.server()) :: [Sovite.TLS.Certificate.t()]
Returns the loaded certificates, default first.
@spec reload(GenServer.server()) :: :ok
Checks the files now and reloads what changed.
@spec server_options(GenServer.server()) :: [:ssl.tls_server_option()] | nil
Returns :ssl server options for the current certificates, or nil
when none is loaded. Call it per connection, so reloaded certificates
apply to new connections.
@spec start_link(keyword()) :: GenServer.on_start()
Starts the store.