module tls

Supported only in the v8 engine. Introduced in Max v9.2.0.

The tls module exposed by require("tls"): TLS/SSL client and server sockets.

This is a minimal tls subset, not full Node parity.

Obtain the module with const tls = require("tls"). TLS support is intentionally narrow in this pass: no client-certificate auth, no SNI routing, no ALPN/HTTP2, and no advanced TLS options beyond key/cert/ca.

Example

const tls = require("tls");
const socket = tls.connect({ host: "example.com", port: 443 });
socket.on("secureConnect", () => socket.write("GET / HTTP/1.0\r\n\r\n"));
socket.on("data", (chunk) => post(chunk.toString("utf8"), "\n"));

Index

Functions

Classes

Interfaces

function connect

Creates a tls.TLSSocket and connects.

function connect(options: ConnectOptions, callback?: () => void): TLSSocket;
NameTypeDescription
optionsConnectOptions
optional callback() => void
Return ValueTLSSocket

function connect

Creates a tls.TLSSocket and connects to a port/host.

function connect(
  port: number,
  host?: string,
  callback?: () => void,
): TLSSocket;
NameTypeDescription
portnumber
optional hoststring
optional callback() => void
Return ValueTLSSocket

interface ConnectOptions

Options for tls.connect.

Properties

ca string | buffer.IOBuffer

Trusted CA certificate(s) (PEM string or buffer.IOBuffer).

cert string | buffer.IOBuffer

Client certificate (PEM string or buffer.IOBuffer).

host string

key string | buffer.IOBuffer

Client private key (PEM string or buffer.IOBuffer).

port number

rejectUnauthorized boolean

Verify the peer certificate (default true). Set false for self-signed/dev certs.

servername string

Server name for the connection.

function createConnection

Alias of tls.connect.

function createConnection(
  options: ConnectOptions,
  callback?: () => void,
): TLSSocket;
NameTypeDescription
optionsConnectOptions
optional callback() => void
Return ValueTLSSocket

function createServer

Creates a TLS tls.Server. Requires key and cert.

function createServer(
  options: ServerOptions,
  secureConnectionListener?: (socket: TLSSocket) => void,
): Server;
NameTypeDescription
optionsServerOptions
optional secureConnectionListener(socket: TLSSocket) => void
Return ValueServer

interface PeerCertificate

A summary of a peer certificate, as returned by tls.TLSSocket.getPeerCertificate().

Properties

issuer string

subject string

valid_from string

valid_to string

class Server

A TLS server. Accepted secure sockets are delivered as tls.TLSSocket instances.

Events: listening, secureConnection, close, error.

Methods

address()

address(): AddressInfo;
NameTypeDescription
Return ValueAddressInfo

close(callback)

close(callback?: () => void): this;
NameTypeDescription
optional callback() => void
Return Valuethis

listen(port, host, callback)

listen(port: number, host?: string, callback?: () => void): this;
NameTypeDescription
portnumber
optional hoststring
optional callback() => void
Return Valuethis

listen(options, callback)

listen(
  options: { port?: number; host?: string },
  callback?: () => void,
): this;
NameTypeDescription
optionsobjectoptional options.port number
optional options.host string
optional callback() => void
Return Valuethis

off(event, listener)

off(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

on(event, listener)

on(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

once(event, listener)

once(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

interface ServerOptions

Options for tls.createServer(). key and cert are required.

Properties

cert string | buffer.IOBuffer

key string | buffer.IOBuffer

class TLSSocket

A TLS/SSL stream socket. Verifies peer certificates by default.

Events: connect, secureConnect, data, drain, close, error.

Properties

Methods

address()

Returns the local endpoint once connected.

address(): AddressInfo;
NameTypeDescription
Return ValueAddressInfo

authorizationError string read-only

The verification error message, when not authorized.

authorized boolean read-only

Whether the peer certificate was verified.

connect(optionsOrPort, hostOrCallback, callback)

Connects and performs the TLS handshake.

connect(
  optionsOrPort: ConnectOptions | number,
  hostOrCallback?: string | (() => void),
  callback?: () => void,
): this;
NameTypeDescription
optionsOrPortConnectOptions | number
optional hostOrCallbackstring | (() => void)
optional callback() => void
Return Valuethis

destroy()

Destroys the socket.

destroy(): void;

destroyed boolean read-only

encrypted boolean read-only

Always true for a TLS socket.

end(chunk, encoding, callback)

Sends an optional final chunk and half-closes the socket.

end(
  chunk?: string | buffer.IOBuffer | ArrayBufferView,
  encoding?: string,
  callback?: () => void,
): void;
NameTypeDescription
optional chunkstring | buffer.IOBuffer | ArrayBufferView
optional encodingstring
optional callback() => void

getPeerCertificate()

Returns a summary of the peer certificate, when available.

getPeerCertificate(): PeerCertificate | undefined;
NameTypeDescription
Return ValuePeerCertificate | undefined

localAddress string read-only

localPort number read-only

off(event, listener)

Removes an event listener.

off(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

on(event, listener)

Registers an event listener.

on(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

once(event, listener)

Registers a one-shot event listener.

once(event: string, listener: (...args: any[]) => void): this;
NameTypeDescription
eventstring
listener(...args: any[]) => void
Return Valuethis

pause()

Pauses delivery of data events (single pending chunk).

pause(): void;

remoteAddress string read-only

remotePort number read-only

resume()

Resumes delivery of data events.

resume(): void;

write(chunk, encoding, callback)

Queues data to send. Returns false under backpressure.

write(
  chunk: string | buffer.IOBuffer | ArrayBufferView,
  encoding?: string,
  callback?: () => void,
): boolean;
NameTypeDescription
chunkstring | buffer.IOBuffer | ArrayBufferView
optional encodingstring
optional callback() => void
Return Valueboolean