Start a TLS handshake thread for a QUIC client. The client will use the specified TLS parameters and call the provided callback functions to send and receive handshake data.
Moduletls-2.1.6Haskell2010
Network.TLS.QUIC
API to run the TLS handshake establishing a QUIC connection.
On the northbound API:
QUIC starts a TLS client or server thread with tlsQUICClient or tlsQUICServer.
TLS invokes QUIC callbacks to use the QUIC transport
TLS uses quicSend and quicRecv to send and receive handshake message fragments.
TLS calls quicInstallKeys to provide to QUIC the traffic secrets it should use for encryption/decryption.
TLS calls quicNotifyExtensions to notify to QUIC the transport parameters exchanged through the handshake protocol.
TLS calls quicDone when the handshake is done.
- 16 types
- 12 values
- Packagetls-2.1.6
- Exports29
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceQUIC.hs
Handshakers
2 declarationsStart a TLS handshake thread for a QUIC server. The server will use the specified TLS parameters and call the provided callback functions to send and receive handshake data.
Callback
3 declarationsCallbacks implemented by QUIC and to be called by TLS at specific points during the handshake. TLS may invoke them from external threads but calls are not concurrent. Only a single callback function is called at a given point in time.
Constructors
QUICCallbacksquicSend :: [(CryptLevel, ByteString)] -> IO ()Called by TLS so that QUIC sends one or more handshake fragments. The content transiting on this API is the plaintext of the fragments and QUIC responsability is to encrypt this payload with the key material given for the specified level and an appropriate encryption scheme.
The size of the fragments may exceed QUIC datagram limits so QUIC may break them into smaller fragments.
The handshake protocol sometimes combines content at two levels in a single flight. The TLS library does its best to provide this in the same
quicSendcall and with a multi-valued argument. QUIC can then decide how to transmit this optimally.quicRecv :: CryptLevel -> IO (Either TLSError ByteString)Called by TLS to receive from QUIC the next plaintext handshake fragment. The argument specifies with which encryption level the fragment should be decrypted.
QUIC may return partial fragments to TLS. TLS will then call
quicRecvagain as long as necessary. Note however that fragments must be returned in the correct sequence, i.e. the order the TLS peer emitted them.The function may return an error to TLS if end of stream is reached or if a protocol error has been received, believing the handshake cannot proceed any longer. If the TLS handshake protocol cannot recover from this error, the failure condition will be reported back to QUIC through the control interface.
quicInstallKeys :: Context -> KeyScheduleEvent -> IO ()quicNotifyExtensions :: Context -> [ExtensionRaw] -> IO ()Called by TLS when QUIC-specific extensions have been received from the peer.
quicDone :: Context -> IO ()Called when handshake is done. tlsQUICServer is finished after calling this hook. tlsQUICClient calls recvData after calling this hook to wait for new session tickets.
TLS encryption level.
Constructors
CryptInitialUnprotected traffic
CryptMainSecretProtected with main secret (TLS < 1.3)
CryptEarlySecretProtected with early traffic secret (TLS 1.3)
CryptHandshakeSecretProtected with handshake traffic secret (TLS 1.3)
CryptApplicationSecretProtected with application traffic secret (TLS 1.3)
Instances2Eq, Show
Eq CryptLevelDefined in tls-2.1.6 · Network.TLS.Record.StateShow CryptLevelDefined in tls-2.1.6 · Network.TLS.Record.State
Argument given to quicInstallKeys when encryption material is available.
Constructors
InstallEarlyKeys (Maybe EarlySecretInfo)Key material and parameters for traffic at 0-RTT level
InstallHandshakeKeys HandshakeSecretInfoKey material and parameters for traffic at handshake level
InstallApplicationKeys ApplicationSecretInfoKey material and parameters for traffic at application level
Secrets
9 declarationsHandshake information generated for traffic at 0-RTT level.
Constructors
Instances1Show
Show EarlySecretInfoDefined in tls-2.1.6 · Network.TLS.Handshake.Control
Handshake information generated for traffic at handshake level.
Constructors
Instances1Show
Show HandshakeSecretInfoDefined in tls-2.1.6 · Network.TLS.Handshake.Control
Handshake information generated for traffic at application level.
Constructors
Instances1Show
Show ApplicationSecretInfoDefined in tls-2.1.6 · Network.TLS.Handshake.Control
Phantom type indicating early traffic secret.
Instances2HasCryptLevel, LogLabel
HasCryptLevel EarlySecretDefined in tls-2.1.6 · Network.TLS.Record.StateLogLabel (ClientTrafficSecret EarlySecret)Defined in tls-2.1.6 · Network.TLS.Handshake.Key
Phantom type indicating handshake traffic secrets.
Instances3HasCryptLevel, LogLabel
HasCryptLevel HandshakeSecretDefined in tls-2.1.6 · Network.TLS.Record.StateLogLabel (ClientTrafficSecret HandshakeSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyLogLabel (ServerTrafficSecret HandshakeSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.Key
Phantom type indicating application traffic secrets.
Instances3HasCryptLevel, LogLabel
HasCryptLevel ApplicationSecretDefined in tls-2.1.6 · Network.TLS.Record.StateLogLabel (ClientTrafficSecret ApplicationSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyLogLabel (ServerTrafficSecret ApplicationSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.Key
Hold both client and server traffic secrets at the same step.
A server traffic secret, typed with a parameter indicating a step in the TLS key schedule.
Constructors
Instances4Show, LogLabel, TrafficSecret
Show (ServerTrafficSecret a)Defined in tls-2.1.6 · Network.TLS.Types.SecretLogLabel (ServerTrafficSecret ApplicationSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyLogLabel (ServerTrafficSecret HandshakeSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyHasCryptLevel a => TrafficSecret (ServerTrafficSecret a)Defined in tls-2.1.6 · Network.TLS.Handshake.State13
A client traffic secret, typed with a parameter indicating a step in the TLS key schedule.
Constructors
Instances5Show, LogLabel, TrafficSecret
Show (ClientTrafficSecret a)Defined in tls-2.1.6 · Network.TLS.Types.SecretLogLabel (ClientTrafficSecret ApplicationSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyLogLabel (ClientTrafficSecret EarlySecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyLogLabel (ClientTrafficSecret HandshakeSecret)Defined in tls-2.1.6 · Network.TLS.Handshake.KeyHasCryptLevel a => TrafficSecret (ClientTrafficSecret a)Defined in tls-2.1.6 · Network.TLS.Handshake.State13
Negotiated parameters
2 declarationsID of the application-level protocol negotiated between client and server. See values listed in the IANA registry.
Type to show which handshake mode is used in TLS 1.3.
Constructors
FullHandshakeFull handshake is used.
HelloRetryRequestFull handshake is used with hello retry request.
RTT0Server authentication is skipped and early data is sent.
Instances2Eq, Show
Eq HandshakeMode13Defined in tls-2.1.6 · Network.TLS.Handshake.StateShow HandshakeMode13Defined in tls-2.1.6 · Network.TLS.Handshake.State
Extensions
3 declarationsThe raw content of a TLS extension.
Constructors
Instances2Eq, Show
Eq ExtensionRawDefined in tls-2.1.6 · Network.TLS.ExtensionShow ExtensionRawDefined in tls-2.1.6 · Network.TLS.Extension
Identifier of a TLS extension. http://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.txt
Constructors
ExtensionIDfromExtensionID :: Word16
Instances2Eq, Show
Eq ExtensionIDDefined in tls-2.1.6 · Network.TLS.ExtensionShow ExtensionIDDefined in tls-2.1.6 · Network.TLS.Extension
Errors
5 declarationsCan be used by callbacks to signal an unexpected condition. This will then generate an "internal_error" alert in the TLS stack.
Return the alert that a TLS endpoint would send to the peer for the specified library error.
Return the message that a TLS endpoint can add to its local log for the specified library error.
Decode an alert from the assigned value.
Hash
3 declarationsHKDF-Expand-Label function. Returns output keying material of the
specified length from the PRK, customized for a TLS label and context.
HKDF-Extract function. Returns the pseudorandom key (PRK) from salt and
input keying material (IKM).
Digest size in bytes.
Constants
1 declarationMax early data size for QUIC.