A TLS Context keep tls specific state, parameters and backend information.
Moduletls-2.1.6Haskell2010
Network.TLS
Native Haskell TLS protocol implementation for servers and clients.
This provides a high-level implementation of a sensitive security protocol, eliminating a common set of security issues through the use of the advanced type system, high level constructions and common Haskell features.
Currently implement the TLS1.2 and TLS 1.3 protocol, and support RSA and Ephemeral (Elliptic curve and regular) Diffie Hellman key exchanges, and many extensions.
The tipical usage is:
socket <- ...
ctx <- contextNew socket <params>
handshake ctx
... (using recvData and sendData)
bye- 61 types
- 3 classes
- 135 values
- Packagetls-2.1.6
- Exports277
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceTLS.hs
Basic APIs
6 declarationscontextNew :: (MonadIO m, HasBackend backend, TLSParams params)=> backendBackend abstraction with specific method to interact with the connection type.
-> paramsParameters of the context.
-> m Context
create a new context using the backend and parameters specified.
Handshake for a new TLS connection
This is to be called at the beginning of a connection, and during renegotiation.
Don't use this function as the acquire resource of bracket.
sendData sends a bunch of data. It will automatically chunk data to acceptable packet size
Get data out of Data packet, and automatically renegotiate if a Handshake ClientHello is received. An empty result means EOF.
Notify the context that this side wants to close connection. This is important that it is called before closing the handle, otherwise the session might not be resumable (for version < TLS1.2). This doesn't actually close the handle.
Proper usage is as follows:
ctx <- contextNew <backend> <params>
handshake ctx
...
byeThe following code ensures nothing but is no harm.
bracket (contextNew <backend> <params>) bye $ \ctx -> do
handshake ctx
...Exceptions
0 declarationsSince 1.8.0, this library only throws exceptions of type TLSException.
In the common case where the chosen backend is socket, IOException
may be thrown as well. This happens because the backend for sockets,
opaque to most modules in the tls library, throws those exceptions.
Backend abstraction
2 declarationsMethods
initializeBackend :: a -> IO ()getBackend :: a -> Backend
Instances3HasBackend
HasBackend HandleDefined in tls-2.1.6 · Network.TLS.BackendHasBackend SocketDefined in tls-2.1.6 · Network.TLS.BackendHasBackend BackendDefined in tls-2.1.6 · Network.TLS.Backend
Connection IO backend
Constructors
BackendbackendFlush :: IO ()Flush the connection sending buffer, if any.
backendClose :: IO ()Close the connection.
backendSend :: ByteString -> IO ()Send a bytestring through the connection.
backendRecv :: Int -> IO ByteStringReceive specified number of bytes from the connection.
Instances1HasBackend
HasBackend BackendDefined in tls-2.1.6 · Network.TLS.Backend
Parameters
1 declarationInstances2TLSParams
TLSParams ClientParamsDefined in tls-2.1.6 · Network.TLS.ContextTLSParams ServerParamsDefined in tls-2.1.6 · Network.TLS.Context
Client parameters
Instances2Show, TLSParams
Show ClientParamsDefined in tls-2.1.6 · Network.TLS.ParametersTLSParams ClientParamsDefined in tls-2.1.6 · Network.TLS.Context
Default: Nothing
Define the name of the server, along with an extra service identification blob. this is important that the hostname part is properly filled for security reason, as it allow to properly associate the remote side with the given certificate during a handshake.
The extra blob is useful to differentiate services running on the same host, but that might have different certificates given. It's only used as part of the X509 validation infrastructure.
This value is typically set by defaultParamsClient.
Allow the use of the Server Name Indication TLS extension during handshake, which allow the client to specify which host name, it's trying to access. This is useful to distinguish CNAME aliasing (e.g. web virtual host).
Default: True
try to establish a connection using this session for TLS 1.2/TLS 1.3.
This can be used for TLS 1.3 but for backward compatibility purpose only.
Use clientWantSessionResume13 instead for TLS 1.3.
Default: Nothing
try to establish a connection using one of this sessions especially for TLS 1.3. This take precedence over clientWantSessionResume. For convenience, this can be specified for TLS 1.2 but only the first entry is used.
Default: '[]'
See the default value of ClientHooks.
In this element, you'll need to override the default empty value of of supportedCiphers with a suitable cipherlist.
See the default value of Supported.
See the default value of DebugParams.
Client tries to send early data in TLS 1.3
via sendData if possible.
If not accepted by the server, the early data
is automatically re-sent.
Default: False
Server parameters
Instances3Show, Default, TLSParams
Show ServerParamsDefined in tls-2.1.6 · Network.TLS.ParametersDefault ServerParamsDefined in tls-2.1.6 · Network.TLS.ParametersTLSParams ServerParamsDefined in tls-2.1.6 · Network.TLS.Context
Request a certificate from client.
Default: False
This is a list of certificates from which the disinguished names are sent in certificate request messages. For TLS1.0, it should not be empty.
Default: '[]'
Server Optional Diffie Hellman parameters. Setting parameters is necessary for FFDHE key exchange when clients are not compatible with RFC 7919.
Value can be one of the standardized groups from module Network.TLS.Extra.FFDHE or custom parameters generated with generateParams.
Default: Nothing
See the default value of ServerHooks.
See the default value of Supported.
See the default value of DebugParams.
Server accepts this size of early data in TLS 1.3. 0 (or lower) means that the server does not accept early data.
Default: 0
Lifetime in seconds for session tickets generated by the server. Acceptable value range is 0 to 604800 (7 days).
Default: 7200 (2 hours)
Shared
Client hooks
A set of callbacks run by the clients for various corners of TLS establishment
Instances2Show, Default
Show ClientHooksDefined in tls-2.1.6 · Network.TLS.ParametersDefault ClientHooksDefined in tls-2.1.6 · Network.TLS.Parameters
type OnCertificateRequest = ([CertificateType], Maybe [HashAndSignatureAlgorithm], [DistinguishedName]) -> IO (Maybe (CertificateChain, PrivKey))Type for onCertificateRequest. This type synonym is to make document readable.
This action is called when the a certificate request is received from the server. The callback argument is the information from the request. The server, at its discretion, may be willing to continue the handshake without a client certificate. Therefore, the callback is free to return Nothing to indicate that no client certificate should be sent, despite the server's request. In some cases it may be appropriate to get user consent before sending the certificate; the content of the user's certificate may be sensitive and intended only for specific servers.
The action should select a certificate chain of one of the given certificate types and one of the certificates in the chain should (if possible) be signed by one of the given distinguished names. Some servers, that don't have a narrow set of preferred issuer CAs, will send an empty DistinguishedName list, rather than send all the names from their trusted CA bundle. If the client does not have a certificate chaining to a matching CA, it may choose a default certificate instead.
Each certificate except the last should be signed by the following one. The returned private key must be for the first certificates in the chain. This key will be used to signing the certificate verify message.
The public key in the first certificate, and the matching returned private key must be compatible with one of the list of HashAndSignatureAlgorithm value when provided. TLS 1.3 changes the meaning of the list elements, adding explicit code points for each supported pair of hash and signature (public key) algorithms, rather than combining separate codes for the hash and key. For details see RFC 8446 section 4.2.3. When no compatible certificate chain is available, return Nothing if it is OK to continue without a client certificate. Returning a non-matching certificate should result in a handshake failure.
While the TLS version is not provided to the callback,
the content of the signature_algorithms list provides
a strong hint, since TLS 1.3 servers will generally list
RSA pairs with a hash component of Intrinsic (0x08).
Note that is is the responsibility of this action to select a certificate matching one of the requested certificate types (public key algorithms). Returning a non-matching one will lead to handshake failure later.
Default: returns Nothing anyway.
type OnServerCertificate = CertificateStore -> ValidationCache -> ServiceID -> CertificateChain -> IO [FailedReason]Type for onServerCertificate. This type synonym is to make document readable.
Used by the client to validate the server certificate. The default implementation calls validateDefault which validates according to the default hooks and checks provided by Data.X509.Validation. This can be replaced with a custom validation function using different settings.
The function is not expected to verify the key-usage extension of the end-entity certificate, as this depends on the dynamically-selected cipher and this part should not be cached. Key-usage verification is performed by the library internally.
Default: validateDefault
This action is called when the client sends ClientHello to determine ALPN values such as '["h2", "http/1.1"]'.
Default: returns Nothing
This action is called to validate DHE parameters when the server selected a finite-field group not part of the "Supported Groups Registry" or not part of supportedGroups list.
With TLS 1.3 custom groups have been removed from the protocol, so this callback is only used when the version negotiated is 1.2 or below.
The default behavior with (dh_p, dh_g, dh_size) and pub as follows:
rejecting if dh_p is even
rejecting unless 1 < dh_g && dh_g < dh_p - 1
rejecting unless 1 < dh_p && pub < dh_p - 1
rejecting if dh_size < 1024 (to prevent Logjam attack)
See RFC 7919 section 3.1 for recommandations.
When a handshake is done, this hook can check Information.
Server hooks
A set of callbacks run by the server for various corners of the TLS establishment
Instances2Show, Default
Show ServerHooksDefined in tls-2.1.6 · Network.TLS.ParametersDefault ServerHooksDefined in tls-2.1.6 · Network.TLS.Parameters
This action is called when a client certificate chain is received from the client. When it returns a CertificateUsageReject value, the handshake is aborted.
The function is not expected to verify the key-usage extension of the certificate. This verification is performed by the library internally.
Default: returns the followings:
CertificateUsageReject (CertificateRejectOther "no client certificates expected")
Allow the server to choose the cipher relative to the the client version and the client list of ciphers.
This could be useful with old clients and as a workaround to the BEAST (where RC4 is sometimes prefered with TLS < 1.1)
The client cipher list cannot be empty.
Default: taking the head of ciphers.
Allow the server to indicate additional credentials to be used depending on the host name indicated by the client.
This is most useful for transparent proxies where credentials must be generated on the fly according to the host the client is trying to connect to.
Returned credentials may be ignored if a client does not support the signature algorithms used in the certificate chain.
Default: returns mempty
At each new handshake, we call this hook to see if we allow handshake to happens.
Default: returns True
Allow the server to choose an application layer protocol suggested from the client through the ALPN (Application Layer Protocol Negotiation) extensions. If the server supports no protocols that the client advertises an empty ByteString should be returned.
Default: Nothing
Allow to modify extensions to be sent in EncryptedExtensions of TLS 1.3.
Default: return
record some data about this connection.
Instances2Eq, Show
Eq MeasurementDefined in tls-2.1.6 · Network.TLS.MeasurementShow MeasurementDefined in tls-2.1.6 · Network.TLS.Measurement
number of handshakes on this context
bytes received since last handshake
bytes sent since last handshake
Supported
List all the supported algorithms, versions, ciphers, etc supported.
Supported versions by this context. On the client side, the highest version will be used to establish the connection. On the server side, the highest version that is less or equal than the client version will be chosen.
Versions should be listed in preference order, i.e. higher versions first.
Default: [TLS13,TLS12]
Supported cipher methods. The default is empty, specify a suitable cipher list. ciphersuite_default is often a good choice.
Default: []
Supported compressions methods. By default only the "null" compression is supported, which means no compression will be performed. Allowing other compression method is not advised as it causes a connection failure when TLS 1.3 is negotiated.
Default: [nullCompression]
All supported hash/signature algorithms pair for client certificate verification and server signature in (EC)DHE, ordered by decreasing priority.
This list is sent to the peer as part of the "signature_algorithms" extension. It is used to restrict accepted signatures received from the peer at TLS level (not in X.509 certificates), but only when the TLS version is 1.2 or above. In order to disable SHA-1 one must then also disable earlier protocol versions in supportedVersions.
The list also impacts the selection of possible algorithms when generating signatures.
Note: with TLS 1.3 some algorithms have been deprecated and will not be used even when listed in the parameter: MD5, SHA-1, SHA-224, RSA PKCS#1, DSA.
Default:
[ (HashIntrinsic, SignatureEd448)
, (HashIntrinsic, SignatureEd25519)
, (Struct.HashSHA256, SignatureECDSA)
, (Struct.HashSHA384, SignatureECDSA)
, (Struct.HashSHA512, SignatureECDSA)
, (HashIntrinsic, SignatureRSApssRSAeSHA512)
, (HashIntrinsic, SignatureRSApssRSAeSHA384)
, (HashIntrinsic, SignatureRSApssRSAeSHA256)
, (Struct.HashSHA512, SignatureRSA)
, (Struct.HashSHA384, SignatureRSA)
, (Struct.HashSHA256, SignatureRSA)
, (Struct.HashSHA1, SignatureRSA)
, (Struct.HashSHA1, SignatureDSA)
]
The mode regarding extended main secret. Enabling this extension provides better security for TLS versions 1.2. TLS 1.3 provides the security properties natively and does not need the extension.
By default the extension is RequireEMS. So, the handshake will fail when the peer does not support the extension.
Default: RequireEMS
Set if we support session.
Default: True
In ver <= TLS1.0, block ciphers using CBC are using CBC residue as IV, which can be guessed by an attacker. Hence, an empty packet is normally sent before a normal data packet, to prevent guessability. Some Microsoft TLS-based protocol implementations, however, consider these empty packets as a protocol violation and disconnect. If this parameter is False, empty packets will never be added, which is less secure, but might help in rare cases.
Default: True
A list of supported elliptic curves and finite-field groups in the preferred order.
The list is sent to the server as part of the "supported_groups" extension. It is used in both clients and servers to restrict accepted groups in DH key exchange. Up until TLS v1.2, it is also used by a client to restrict accepted elliptic curves in ECDSA signatures.
The default value includes all groups with security strength of 128 bits or more.
Default: [X25519,X448,P256,FFDHE2048,FFDHE3072,FFDHE4096,P384,FFDHE6144,FFDHE8192,P521]
Debug parameters
All settings should not be used in production
Instances2Show, Default
Show DebugParamsDefined in tls-2.1.6 · Network.TLS.ParametersDefault DebugParamsDefined in tls-2.1.6 · Network.TLS.Parameters
Disable the true randomness in favor of deterministic seed that will produce a deterministic random from. This is useful for tests and debugging purpose. Do not use in production
Default: Nothing
Add a way to print the seed that was randomly generated. re-using the same seed will reproduce the same randomness with debugSeed
Default: no printing
Force to choose this version in the server side.
Default: Nothing
Printing main keys.
Default: no printing
Shared parameters
0 declarationsCredentials
Constructors
Instances3Show, Semigroup, Monoid
Show CredentialsDefined in tls-2.1.6 · Network.TLS.CredentialsSemigroup CredentialsDefined in tls-2.1.6 · Network.TLS.CredentialsMonoid CredentialsDefined in tls-2.1.6 · Network.TLS.Credentials
credentialLoadX509 try to create a new credential object from a public certificate and the associated private key that are stored on the filesystem in PEM format.
similar to credentialLoadX509 but take the certificate and private key from memory instead of from the filesystem.
similar to credentialLoadX509 but also allow specifying chain certificates.
similar to credentialLoadX509FromMemory but also allow specifying chain certificates.
Session manager
A session manager. In the server side, all fields are used. In the client side, only sessionEstablish is used.
The session manager to do nothing.
Used on TLS 1.2/1.3 servers to lookup SessionData with SessionID or to decrypt Ticket to get SessionData.
Used for 0RTT on TLS 1.3 servers to lookup SessionData with SessionID or to decrypt Ticket to get SessionData.
Used on TLS 1.2/1.3 servers to store SessionData with SessionID or to encrypt SessionData to get Ticket ignoring SessionID. Used on TLS 1.2/1.3 clients to store SessionData with SessionIDorTicket and then return Nothing. For clients, only this field should be set with noSessionManager.
Used TLS 1.2 servers to delete SessionData with SessionID on errors.
A session ID
Identity
Encrypted session ticket (encrypt(encode SessionData)).
Session data
Session data to resume
Instances5Eq, Show, Generic, Serialise, Rep
Eq SessionDataDefined in tls-2.1.6 · Network.TLS.Types.SessionShow SessionDataDefined in tls-2.1.6 · Network.TLS.Types.SessionGeneric SessionDataDefined in tls-2.1.6 · Network.TLS.Types.SessionSerialise SessionDataDefined in tls-2.1.6 · Network.TLS.Types.Sessiontype Rep SessionData = D1 ('MetaDataDefined in tls-2.1.6 · Network.TLS.Types.Session"SessionData"
"Network.TLS.Types.Session"
"tls-2.1.6-3TrFPbgFIalLKNEHCldmNu"
'False) (C1 ('MetaCons"SessionData"
'PrefixI 'True) (((S1 ('MetaSel ('Just"sessionVersion"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 Version) :*: S1 ('MetaSel ('Just"sessionCipher"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 CipherID)) :*: (S1 ('MetaSel ('Just"sessionCompression"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 CompressionID) :*: (S1 ('MetaSel ('Just"sessionClientSNI"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe HostName)) :*: S1 ('MetaSel ('Just"sessionSecret"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 ByteString)))) :*: ((S1 ('MetaSel ('Just"sessionGroup"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe Group)) :*: S1 ('MetaSel ('Just"sessionTicketInfo"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe TLS13TicketInfo))) :*: (S1 ('MetaSel ('Just"sessionALPN"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe ByteString)) :*: (S1 ('MetaSel ('Just"sessionMaxEarlyDataSize"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 Int) :*: S1 ('MetaSel ('Just"sessionFlags"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 [SessionFlag]))))))
Some session flags
Constructors
SessionEMSSession created with Extended Main Secret
Instances6Enum, Eq, Show, Generic, Serialise, Rep
Enum SessionFlagDefined in tls-2.1.6 · Network.TLS.Types.SessionEq SessionFlagDefined in tls-2.1.6 · Network.TLS.Types.SessionShow SessionFlagDefined in tls-2.1.6 · Network.TLS.Types.SessionGeneric SessionFlagDefined in tls-2.1.6 · Network.TLS.Types.SessionSerialise SessionFlagDefined in tls-2.1.6 · Network.TLS.Types.Sessiontype Rep SessionFlag = D1 ('MetaDataDefined in tls-2.1.6 · Network.TLS.Types.Session"SessionFlag"
"Network.TLS.Types.Session"
"tls-2.1.6-3TrFPbgFIalLKNEHCldmNu"
'False) (C1 ('MetaCons"SessionEMS"
'PrefixI 'False) U1)
Instances5Eq, Show, Generic, Serialise, Rep
Eq TLS13TicketInfoDefined in tls-2.1.6 · Network.TLS.Types.SessionShow TLS13TicketInfoDefined in tls-2.1.6 · Network.TLS.Types.SessionGeneric TLS13TicketInfoDefined in tls-2.1.6 · Network.TLS.Types.SessionSerialise TLS13TicketInfoDefined in tls-2.1.6 · Network.TLS.Types.Sessiontype Rep TLS13TicketInfo = D1 ('MetaDataDefined in tls-2.1.6 · Network.TLS.Types.Session"TLS13TicketInfo"
"Network.TLS.Types.Session"
"tls-2.1.6-3TrFPbgFIalLKNEHCldmNu"
'False) (C1 ('MetaCons"TLS13TicketInfo"
'PrefixI 'True) ((S1 ('MetaSel ('Just"lifetime"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 Second) :*: S1 ('MetaSel ('Just"ageAdd"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 Second)) :*: (S1 ('MetaSel ('Just"txrxTime"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedUnpack) (Rec0 Millisecond) :*: S1 ('MetaSel ('Just"estimatedRTT"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 (Maybe Millisecond)))))
Validation Cache
All the callbacks needed for querying and adding to the cache.
Constructors
ValidationCachecacheQuery :: ValidationCacheQueryCallbackcache querying callback
cacheAdd :: ValidationCacheAddCallbackcache adding callback
Instances1Default
Default ValidationCacheDefined in crypton-x509-validation-1.6.14 · Data.X509.Validation.Cache
type ValidationCacheQueryCallback = ServiceID -> Fingerprint -> Certificate -> IO ValidationCacheResultValidation cache query callback type
Validation cache callback type
The result of a cache query
Constructors
ValidationCachePasscache allow this fingerprint to go through
ValidationCacheDenied Stringcache denied this fingerprint for further validation
ValidationCacheUnknownunknown fingerprint in cache
Instances2Eq, Show
Eq ValidationCacheResultDefined in crypton-x509-validation-1.6.14 · Data.X509.Validation.CacheShow ValidationCacheResultDefined in crypton-x509-validation-1.6.14 · Data.X509.Validation.Cache
create a simple constant cache that list exceptions to the certification validation. Typically this is use to allow self-signed certificates for specific use, with out-of-bounds user checks.
No fingerprints will be added after the instance is created.
The underlying structure for the check is kept as a list, as usually the exception list will be short, but when the list go above a dozen exceptions it's recommended to use another cache mechanism with a faster lookup mechanism (hashtable, map, etc).
Note that only one fingerprint is allowed per ServiceID, for other use, another cache mechanism need to be use.
Types
0 declarationsFor Supported
Instances6Eq, Ord, Show, Generic, Serialise, Rep
Eq VersionDefined in tls-2.1.6 · Network.TLS.Types.VersionOrd VersionDefined in tls-2.1.6 · Network.TLS.Types.VersionShow VersionDefined in tls-2.1.6 · Network.TLS.Types.VersionGeneric VersionDefined in tls-2.1.6 · Network.TLS.Types.VersionSerialise VersionDefined in tls-2.1.6 · Network.TLS.Types.Versiontype Rep Version = D1 ('MetaDataDefined in tls-2.1.6 · Network.TLS.Types.Version"Version"
"Network.TLS.Types.Version"
"tls-2.1.6-3TrFPbgFIalLKNEHCldmNu"
'True) (C1 ('MetaCons"Version"
'PrefixI 'False) (S1 ('MetaSel 'Nothing 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 Word16)))
every compression need to be wrapped in this, to fit in structure
Constructors
forall a. CompressionC a => Compression a
Instances2Eq, Show
Eq CompressionDefined in tls-2.1.6 · Network.TLS.CompressionShow CompressionDefined in tls-2.1.6 · Network.TLS.Compression
default null compression
Constructors
Instances2Eq, Show
Eq HashAlgorithmDefined in tls-2.1.6 · Network.TLS.HashAndSignatureShow HashAlgorithmDefined in tls-2.1.6 · Network.TLS.HashAndSignature
Constructors
Instances2Eq, Show
Eq SignatureAlgorithmDefined in tls-2.1.6 · Network.TLS.HashAndSignatureShow SignatureAlgorithmDefined in tls-2.1.6 · Network.TLS.HashAndSignature
Instances5Eq, Show, Generic, Serialise, Rep
Eq GroupDefined in tls-2.1.6 · Network.TLS.Crypto.TypesShow GroupDefined in tls-2.1.6 · Network.TLS.Crypto.TypesGeneric GroupDefined in tls-2.1.6 · Network.TLS.Crypto.TypesSerialise GroupDefined in tls-2.1.6 · Network.TLS.Crypto.Typestype Rep Group = D1 ('MetaDataDefined in tls-2.1.6 · Network.TLS.Crypto.Types"Group"
"Network.TLS.Crypto.Types"
"tls-2.1.6-3TrFPbgFIalLKNEHCldmNu"
'True) (C1 ('MetaCons"Group"
'PrefixI 'False) (S1 ('MetaSel 'Nothing 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 Word16)))
Client or server policy regarding Extended Main Secret
Constructors
NoEMSExtended Main Secret is not used
AllowEMSExtended Main Secret is allowed
RequireEMSExtended Main Secret is required
For parameters and hooks
Group usage callback possible return values.
Constructors
GroupUsageValidusage of group accepted
GroupUsageInsecureusage of group provides insufficient security
GroupUsageUnsupported Stringusage of group rejected for other reason (specified as string)
GroupUsageInvalidPublicusage of group with an invalid public value
Instances2Eq, Show
Eq GroupUsageDefined in tls-2.1.6 · Network.TLS.ParametersShow GroupUsageDefined in tls-2.1.6 · Network.TLS.Parameters
Certificate Usage callback possible returns values.
Constructors
CertificateUsageAcceptusage of certificate accepted
CertificateUsageReject CertificateRejectReasonusage of certificate rejected
Instances2Eq, Show
Eq CertificateUsageDefined in tls-2.1.6 · Network.TLS.X509Show CertificateUsageDefined in tls-2.1.6 · Network.TLS.X509
Certificate and Chain rejection reason
Instances2Eq, Show
Eq CertificateRejectReasonDefined in tls-2.1.6 · Network.TLS.X509Show CertificateRejectReasonDefined in tls-2.1.6 · Network.TLS.X509
Some of the IANA registered code points for CertificateType are not currently supported by the library. Nor should they be, they're are either unwise, obsolete or both. There's no point in conveying these to the user in the client certificate request callback. The request callback will be filtered to exclude unsupported values. If the user cannot find a certificate for a supported code point, we'll go ahead without a client certificate and hope for the best, unless the user's callback decides to throw an exception.
Constructors
Instances3Eq, Ord, Show
Eq CertificateTypeDefined in tls-2.1.6 · Network.TLS.StructOrd CertificateTypeDefined in tls-2.1.6 · Network.TLS.StructShow CertificateTypeDefined in tls-2.1.6 · Network.TLS.Struct
TLS10 and up, RFC5246
TLS10 and up, RFC5246
TLS10 and up, RFC8422
Either a host name e.g., "haskell.org" or a numeric host
address string consisting of a dotted decimal IPv4 address or an
IPv6 address e.g., "192.168.0.1".
Instances2Eq, Show
Eq MaxFragmentEnumDefined in tls-2.1.6 · Network.TLS.ExtensionShow MaxFragmentEnumDefined in tls-2.1.6 · Network.TLS.Extension
Advanced APIs
0 declarationsBackend
return the backend object associated with this context
A shortcut for 'backendFlush . ctxBackend'.
A shortcut for 'backendClose . ctxBackend'.
Information gathering
Information related to a running context, e.g. current cipher
Instances2Eq, Show
Eq InformationDefined in tls-2.1.6 · Network.TLS.ParametersShow InformationDefined in tls-2.1.6 · Network.TLS.Parameters
Information about the current context
Instances2Eq, Show
Eq ClientRandomDefined in tls-2.1.6 · Network.TLS.StructShow ClientRandomDefined in tls-2.1.6 · Network.TLS.Struct
Instances2Eq, Show
Eq ServerRandomDefined in tls-2.1.6 · Network.TLS.StructShow ServerRandomDefined in tls-2.1.6 · Network.TLS.Struct
Type to show which handshake mode is used in TLS 1.3.
Constructors
FullHandshakeFull handshake is used.
HelloRetryRequestFull handshake is used with hello retry request.
RTT0Server authentication is skipped and early data is sent.
Instances2Eq, Show
Eq HandshakeMode13Defined in tls-2.1.6 · Network.TLS.Handshake.StateShow HandshakeMode13Defined in tls-2.1.6 · Network.TLS.Handshake.State
Getting certificates from a client, if any. Note that the certificates are not sent by a client on resumption even if client authentication is required. So, this API would be replaced by the one which can treat both cases of full-negotiation and resumption.
Negotiated
If the ALPN extensions have been used, this will return get the protocol agreed upon.
If the Server Name Indication extension has been used, return the hostname specified by the client.
Post-handshake actions
How to update keys in TLS 1.3
Instances2Eq, Show
Eq KeyUpdateRequestDefined in tls-2.1.6 · Network.TLS.CoreShow KeyUpdateRequestDefined in tls-2.1.6 · Network.TLS.Core
Post-handshake certificate request with TLS 1.3. Returns True if the request was possible, i.e. if TLS 1.3 is used and the remote client supports post-handshake authentication.
Getting the "tls-unique" channel binding for TLS 1.2 (RFC5929). For TLS 1.3, Nothing is returned. supportedExtendedMainSecret must be RequireEMS But in general, it is highly recommended to upgrade to TLS 1.3 and use the "tls-exporter" channel binding via getTLSExporter.
Getting the "tls-exporter" channel binding for TLS 1.3 (RFC9266). For TLS 1.2, Nothing is returned.
Getting the "tls-server-end-point" channel binding for TLS 1.2 (RFC5929). For 1.3, there is no specifications for how to create it. In this implementation, a certificate chain without extensions is hashed like TLS 1.2.
Deprecated. Use getTLSUnique instead
Getting TLS Finished sent to peer.
Deprecated. Use getTLSUnique instead
Getting TLS Finished received from peer.
Modifying hooks in context
A collection of hooks actions.
called at each handshake message received
called at each handshake message received for TLS 1.3
called at each certificate chain message received
hooks on IO and packets, receiving and sending.
Instances2Eq, Show
Eq Handshake13Defined in tls-2.1.6 · Network.TLS.Struct13Show Handshake13Defined in tls-2.1.6 · Network.TLS.Struct13
Hooks for logging
This is called when sending and receiving packets and IO
Constructors
Constructors
Instances2Eq, Show
Eq ProtocolTypeDefined in tls-2.1.6 · Network.TLS.StructShow ProtocolTypeDefined in tls-2.1.6 · Network.TLS.Struct
Errors and exceptions
0 declarationsErrors
TLSError that might be returned through the TLS stack.
Prior to version 1.8.0, this type had an Exception instance.
In version 1.8.0, this instance was removed, and functions in
this library now only throw TLSException.
Constructors
Error_Misc Stringmainly for instance of Error
Error_Protocol String AlertDescriptionA fatal error condition was encountered at a low level. The elements of the tuple give (freeform text description, structured error description).
Error_Protocol_Warning String AlertDescriptionA non-fatal error condition was encountered at a low level at a low level. The elements of the tuple give (freeform text description, structured error description).
Error_Certificate StringError_HandshakePolicy Stringhandshake policy failed.
Error_EOFError_Packet StringError_Packet_unexpected String StringError_Packet_Parsing StringError_TCP_Terminate
Instances4Eq, Show, MonadError
Eq TLSErrorDefined in tls-2.1.6 · Network.TLS.ErrorShow TLSErrorDefined in tls-2.1.6 · Network.TLS.ErrorMonadError TLSError RecordMDefined in tls-2.1.6 · Network.TLS.Record.StateMonadError TLSError TLSStDefined in tls-2.1.6 · Network.TLS.State
Constructors
Constructors
Instances2Eq, Show
Eq AlertDescriptionDefined in tls-2.1.6 · Network.TLS.ErrorShow AlertDescriptionDefined in tls-2.1.6 · Network.TLS.Error
Exceptions
TLS Exceptions. Some of the data constructors indicate incorrect use of the library, and the documentation for those data constructors calls this out. The others wrap TLSError with some kind of context to explain when the exception occurred.
Constructors
Terminated Bool String TLSErrorEarly termination exception with the reason and the error associated
HandshakeFailed TLSErrorHandshake failed for the reason attached.
PostHandshake TLSErrorFailure occurred while sending or receiving data after the TLS handshake succeeded.
Uncontextualized TLSErrorLifts a TLSError into TLSException without provided any context around when the error happened.
ConnectionNotEstablishedUsage error when the connection has not been established and the user is trying to send or receive data. Indicates that this library has been used incorrectly.
MissingHandshakeExpected that a TLS handshake had already taken place, but no TLS handshake had occurred. Indicates that this library has been used incorrectly.
Instances3Eq, Show, Exception
Eq TLSExceptionDefined in tls-2.1.6 · Network.TLS.ErrorShow TLSExceptionDefined in tls-2.1.6 · Network.TLS.ErrorException TLSExceptionDefined in tls-2.1.6 · Network.TLS.Error
Raw types
0 declarationsCompressions class
supported compression algorithms need to be part of this class
Methods
compressionCID :: a -> CompressionIDcompressionCDeflate :: a -> ByteString -> (a, ByteString)compressionCInflate :: a -> ByteString -> (a, ByteString)
Instances1CompressionC
CompressionC NullCompressionDefined in tls-2.1.6 · Network.TLS.Compression
Compression identification
Crypto Key
Public key types known and used in X.509
Constructors
PubKeyRSA PublicKeyRSA public key
PubKeyDSA PublicKeyDSA public key
PubKeyDH (Integer, Integer, Integer, Maybe Integer, ([Word8], Integer))DH format with (p,g,q,j,(seed,pgenCounter))
PubKeyEC PubKeyECEC public key
PubKeyX25519 PublicKeyX25519 public key
PubKeyX448 PublicKeyX448 public key
PubKeyEd25519 PublicKeyEd25519 public key
PubKeyEd448 PublicKeyEd448 public key
PubKeyUnknown OID ByteStringunrecognized format
Private key types known and used in X.509
Constructors
PrivKeyRSA PrivateKeyRSA private key
PrivKeyDSA PrivateKeyDSA private key
PrivKeyEC PrivKeyECEC private key
PrivKeyX25519 SecretKeyX25519 private key
PrivKeyX448 SecretKeyX448 private key
PrivKeyEd25519 SecretKeyEd25519 private key
PrivKeyEd448 SecretKeyEd448 private key
Ciphers & Predefined ciphers
module Network.TLS.Cipher
Deprecated
4 declarationsDeprecated. use recvData that returns strict bytestring
same as recvData but returns a lazy bytestring.
Deprecated. Use Data.ByteString.Bytestring instead of Bytes.
A set of checks to activate or parametrize to perform on certificates.
It's recommended to use defaultChecks to create the structure, to better cope with future changes or expansion of the structure.
Constructors
ValidationCheckscheckTimeValidity :: Boolcheck time validity of every certificate in the chain. the make sure that current time is between each validity bounds in the certificate
checkAtTime :: Maybe DateTimeThe time when the validity check happens. When set to Nothing, the current time will be used
checkStrictOrdering :: BoolCheck that no certificate is included that shouldn't be included. unfortunately despite the specification violation, a lots of real world server serves useless and usually old certificates that are not relevant to the certificate sent, in their chain.
checkCAConstraints :: BoolCheck that signing certificate got the CA basic constraint. this is absolutely not recommended to turn it off.
checkExhaustive :: BoolCheck the whole certificate chain without stopping at the first failure. Allow gathering a exhaustive list of failure reasons. if this is turn off, it's absolutely not safe to ignore a failed reason even it doesn't look serious (e.g. Expired) as other more serious checks would not have been performed.
checkLeafV3 :: BoolCheck that the leaf certificate is version 3. If disable, version 2 certificate is authorized in leaf position and key usage cannot be checked.
checkLeafKeyUsage :: [ExtKeyUsageFlag]Check that the leaf certificate is authorized to be used for certain usage. If set to empty list no check are performed, otherwise all the flags is the list need to exists in the key usage extension. If the extension is not present, the check will pass and behave as if the certificate key is not restricted to any specific usage.
checkLeafKeyPurpose :: [ExtKeyUsagePurpose]Check that the leaf certificate is authorized to be used for certain purpose. If set to empty list no check are performed, otherwise all the flags is the list need to exists in the extended key usage extension if present. If the extension is not present, then the check will pass and behave as if the certificate is not restricted to any specific purpose.
checkFQHN :: BoolCheck the top certificate names matching the fully qualified hostname (FQHN). it's not recommended to turn this check off, if no other name checks are performed.
Instances3Eq, Show, Default
Eq ValidationChecksDefined in crypton-x509-validation-1.6.14 · Data.X509.ValidationShow ValidationChecksDefined in crypton-x509-validation-1.6.14 · Data.X509.ValidationDefault ValidationChecksDefined in crypton-x509-validation-1.6.14 · Data.X509.Validation
A set of hooks to manipulate the way the verification works.
BEWARE, it's easy to change behavior leading to compromised security.
Constructors
ValidationHookshookMatchSubjectIssuer :: DistinguishedName -> Certificate -> Boolcheck whether a given issuer DistinguishedName matches the subject DistinguishedName of a candidate issuer certificate.
hookValidateTime :: DateTime -> Certificate -> [FailedReason]check whether the certificate in the second argument is valid at the time provided in the first argument. Return an empty list for success or else one or more failure reasons.
hookValidateName :: HostName -> Certificate -> [FailedReason]validate the certificate leaf name with the DNS named used to connect
hookFilterReason :: [FailedReason] -> [FailedReason]user filter to modify the list of failure reasons
Instances1Default
Default ValidationHooksDefined in crypton-x509-validation-1.6.14 · Data.X509.Validation