DANE certificate verification for SMTP (RFC 6698, RFC 7671, RFC 7672).
A TLSA record is {usage, selector, matching_type, data}:
- usage
3(DANE-EE) - the server's own certificate or key. Its name, dates, and issuer are not checked (RFC 7672 §3.1.1). - usage
2(DANE-TA) - a CA certificate or key in the chain the server sends; the chain from it must be valid for the server's name. - usages
0and1(PKIX-TA, PKIX-EE) are not used for SMTP (RFC 7672 §3.1.3) and are ignored. - selector
0matches the whole certificate,1its public key. - matching type
0is the exact data,1SHA-256,2SHA-512.
Only records from a DNSSEC-authenticated answer may be used: see
Sovite.DNS.lookup_secure/3.
Summary
Functions
Returns :ssl client options that accept a server only if its
certificate chain matches one of records (already filtered with
usable/1). hostname is the name the chain must be valid for with
DANE-TA, normally the MX host name. tls is passed to
Sovite.TLS.client_options/1 (:min_version, :ciphers).
Returns whether the DER certificate cert matches record.
Keeps the records usable for SMTP: DANE-TA and DANE-EE, with a known selector and matching type, and data of the right length. If none is left, DANE does not apply and the client falls back to opportunistic TLS (RFC 7672 §2.2).
Types
Functions
@spec client_options([tlsa(), ...], String.t(), keyword()) :: [ :ssl.tls_client_option() ]
Returns :ssl client options that accept a server only if its
certificate chain matches one of records (already filtered with
usable/1). hostname is the name the chain must be valid for with
DANE-TA, normally the MX host name. tls is passed to
Sovite.TLS.client_options/1 (:min_version, :ciphers).
Returns whether the DER certificate cert matches record.
Keeps the records usable for SMTP: DANE-TA and DANE-EE, with a known selector and matching type, and data of the right length. If none is left, DANE does not apply and the client falls back to opportunistic TLS (RFC 7672 §2.2).