Standard Library
class TlsAccept
Accepts a TLS client on a server socket, with a deadline.
since 0.1.0-alpha.1linux
Overview
TlsAccept takes the descriptor of a freshly accepted client connection, arms TLS with the server's certificate and key, and drives the handshake. A client that is slow or fails the handshake is dropped: the descriptor is closed and your function is called with -1. Nothing is thrown, so one bad client cannot unwind the accept loop. A deadline limits how long a client may take, which protects the server from clients that connect and then stall.
Examples
Securing every client a listener accepts
TcpListener listener = TcpListener(8443);
listener.connections((TcpStream client) => {
TlsAccept accept = TlsAccept();
accept.begin(client.rawFd(), "server.pem", "server.key", "", 5000, (fd) => {
if (fd < 0) {
console.writeln("client dropped");
} else {
console.writeln("secure client connected");
}
});
});
Methods
begin
begin(int f, string cert, string key, string alpn, int deadlineMs, (int) => void cb) -> voidStart the server-side handshake for an accepted client.
The callback is called once. If TLS cannot be armed, the handshake fails, or the deadline passes first, the descriptor is closed and the callback receives -1.
Parameters
- f
- The descriptor of an accepted client connection.
- cert
- The path of the server's certificate file in PEM format.
- key
- The path of the server's private key file in PEM format.
- alpn
- The application protocols to accept, comma separated;
""for none. - deadlineMs
- The longest time the client may take to finish the handshake, in milliseconds.
- cb
- The function called with the descriptor on success, or with
-1when the client is dropped.
See also
- tlsAccept — Secure an accepted client connection with TLS, with a deadline.
- TcpListener — A listening socket that delivers each incoming connection as a
TcpStream.