Sovite.TLS.Certificate (sovite v0.2.0)

Copy Markdown View Source

A certificate chain and its private key, loaded from PEM files.

The certificate file holds the server certificate first, then any intermediate certificates, as most CAs (and ACME clients) write it. The key file holds one unencrypted private key: RSA, EC, or PKCS #8.

The key is checked against the certificate, so a mismatched pair is rejected at load time instead of failing every handshake.

Summary

Types

Why a certificate could not be loaded

t()

Functions

Returns the certificate as an :ssl certs_keys entry.

Decodes a certificate chain and key from PEM data.

Loads a certificate chain and key from PEM files.

Returns whether the certificate is valid for hostname. A wildcard name matches exactly one label (*.example.com matches mx.example.com, not example.com or a.b.example.com).

Types

error()

@type error() ::
  {:cert_file | :key_file, File.posix()}
  | :no_certificate
  | :no_key
  | :encrypted_key
  | :invalid_certificate
  | :invalid_key
  | :key_mismatch

Why a certificate could not be loaded:

  • {:cert_file | :key_file, File.posix()} - the file cannot be read.

  • :no_certificate / :no_key - the PEM data has none.
  • :encrypted_key - the key is protected by a passphrase.
  • :invalid_certificate / :invalid_key - the data does not decode.
  • :key_mismatch - the key does not belong to the certificate.

t()

@type t() :: %Sovite.TLS.Certificate{
  cert_file: Path.t() | nil,
  chain: [binary(), ...],
  key: {atom(), binary()},
  key_file: Path.t() | nil,
  names: [String.t()],
  not_after: DateTime.t()
}

Functions

certs_keys(certificate)

@spec certs_keys(t()) :: map()

Returns the certificate as an :ssl certs_keys entry.

decode(cert_pem, key_pem)

@spec decode(binary(), binary()) :: {:ok, t()} | {:error, error()}

Decodes a certificate chain and key from PEM data.

load(cert_file, key_file)

@spec load(Path.t(), Path.t()) :: {:ok, t()} | {:error, error()}

Loads a certificate chain and key from PEM files.

matches?(certificate, hostname)

@spec matches?(t(), String.t()) :: boolean()

Returns whether the certificate is valid for hostname. A wildcard name matches exactly one label (*.example.com matches mx.example.com, not example.com or a.b.example.com).