HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

ModuleHsOpenSSL-0.11.7.10Haskell2010

OpenSSL.Session

Functions for handling SSL connections. These functions use GHC specific calls to cooperative the with the scheduler so that blocking functions only actually block the Haskell thread, not a whole OS thread.

  • 11 types
  • 47 values
  • PackageHsOpenSSL-0.11.7.10
  • Exports58
  • LanguageHaskell2010
  • LicenceLicenseRef-PublicDomain
  • SourceSession.hsc

Contexts

21 declarations
datadata SSLContext
#

An SSL context. Contexts carry configuration such as a server's private key, root CA certiifcates etc. Contexts are stateful IO objects; they start empty and various options are set on them by the functions in this module. Note that an empty context will pretty much cause any operation to fail since it doesn't even have any ciphers enabled.

Install a private key file in a context. The key is given as a path to the file which contains the key. The file is parsed first as PEM and, if that fails, as ASN1. If both fail, an exception is raised.

Install a certificate (public key) file in a context. The key is given as a path to the file which contains the key. The file is parsed first as PEM and, if that fails, as ASN1. If both fail, an exception is raised.

Install a certificate chain in a context. The certificates must be in PEM format and must be sorted starting with the subject's certificate (actual client or server certificate), followed by intermediate CA certificates if applicable, and ending at the highest level (root) CA.

Specifies that the default locations from which CA certificates are loaded should be used. There is one default directory and one default file.

The default CA certificates directory is called "certs" in the default OpenSSL directory. Alternatively the SSL_CERT_DIR environment variable can be defined to override this location.

The default CA certificates file is called "cert.pem" in the default OpenSSL directory. Alternatively the SSL_CERT_FILE environment variable can be defined to override this location.

See https://www.openssl.org/docs/manmaster/man3/SSL_CTX_set_default_verify_paths.html for more information.

Set context within which session can be reused (server side only).

If client certificates are used and the session id context is not set, attempts by the clients to reuse a session will make the handshake fail.

valuewithContextSetKeylogCallback
  1. :: SSLContext
  2. -> String -> IO ()
  3. -> IO a
  4. -> IO a
#

The key logging callback is called with a String "line". The line is a string containing the key material in the format used by NSS for its SSLKEYLOGFILE debugging output. To recreate that file, the key logging callback should log line, followed by a newline.

FIXME: Not re-entrant (ignores previous callback and resets it to nullFunPtr on exit)

SSL connections

29 declarations
datadata SSL
#

This is the type of an SSL connection

IO with SSL objects is non-blocking and many SSL functions return a error code which signifies that it needs to read or write more data. We handle these calls and call threadWaitRead and threadWaitWrite at the correct times. Thus multiple OS threads can be blocked inside IO in the same SSL object at a time, because they aren't really in the SSL object, they are waiting for the RTS to wake the Haskell thread.

datadata SSLResult a
#

This is the type of an SSL IO operation. Errors are handled by exceptions while everything else is one of these. Note that reading from an SSL socket can result in WantWrite and vice versa.

Constructors

  • SSLDone a

    operation finished successfully

  • WantRead

    needs more data from the network

  • WantWrite

    needs more outgoing buffer space

Instances5Functor, Foldable, Traversable, Eq, Show
valueconnection :: SSLContext -> Socket -> IO SSL
#

Wrap a Socket in an SSL connection. Reading and writing to the Socket after this will cause weird errors in the SSL code. The SSL object carries a handle to the Socket so you need not worry about the garbage collector closing the file descriptor out from under you.

valueaccept :: SSL -> IO ()
#

Perform an SSL server handshake

valueconnect :: SSL -> IO ()
#

Perform an SSL client handshake

valuereadPtr :: SSL -> Ptr a -> Int -> IO Int
#

Read some data into a raw pointer buffer. Retrns the number of bytes read.

valuewrite :: SSL -> ByteString -> IO ()
#

Write a given ByteString to the SSL connection. Either all the data is written or an exception is raised because of an error.

valuelazyRead :: SSL -> IO ByteString
#

Lazily read all data until reaching EOF. If the connection dies without a graceful SSL shutdown, an exception is raised.

valuelazyWrite :: SSL -> ByteString -> IO ()
#

Write a lazy ByteString to the SSL connection. In contrast to write, there is a chance that the string is written partway and then an exception is raised for an error. The string doesn't necessarily have to be finite.

valueshutdown :: SSL -> ShutdownType -> IO ()
#

Cleanly shutdown an SSL connection. Note that SSL has a concept of a secure shutdown, which is distinct from just closing the TCP connection. This performs the former and should always be preferred.

This can either just send a shutdown, or can send and wait for the peer's shutdown message.

valuegetPeerCertificate :: SSL -> IO (Maybe X509)
#

After a successful connection, get the certificate of the other party. If this is a server connection, you probably won't get a certificate unless you asked for it with contextSetVerificationMode

valuegetVerifyResult :: SSL -> IO Bool
#

Get the result of verifing the peer's certificate. This is mostly for clients to verify the certificate of the server that they have connected it. You must set a list of root CA certificates with contextSetCA... for this to make sense.

Note that this returns True iff the peer's certificate has a valid chain to a root CA. You also need to check that the certificate is correct (i.e. has the correct hostname in it) with getPeerCertificate.

valuesslFd :: SSL -> Fd
#

Get the underlying socket Fd

Protocol Options

1 declaration
datadata SSLOption
#

The behaviour of the SSL library can be changed by setting several options. During a handshake, the option settings of the SSL object are used. When a new SSL object is created from a SSLContext, the current option setting is copied. Changes to SSLContext do not affect already created SSL objects.

Constructors

Instances3Eq, Ord, Show
  • Eq SSLOptionDefined in HsOpenSSL-0.11.7.10 · OpenSSL.SSL.Option
  • Ord SSLOptionDefined in HsOpenSSL-0.11.7.10 · OpenSSL.SSL.Option
  • Show SSLOptionDefined in HsOpenSSL-0.11.7.10 · OpenSSL.SSL.Option

SSL Exceptions

3 declarations

Direct access to OpenSSL objects

4 declarations
valuewithSSL :: SSL -> (Ptr SSL_ -> IO a) -> IO a
#

Run continuation with exclusive access to the underlying SSL object.