module tls
Supported only in the v8 engine. Introduced in Max v9.2.0.
The tls module exposed by require("tls"): TLS/SSL client and server sockets.
This is a minimal tls subset, not full Node parity.
Obtain the module with const tls = require("tls"). TLS support is intentionally narrow in this pass: no client-certificate auth, no SNI routing, no ALPN/HTTP2, and no advanced TLS options beyond key/cert/ca.
Example
const tls = require("tls");
const socket = tls.connect({ host: "example.com", port: 443 });
socket.on("secureConnect", () => socket.write("GET / HTTP/1.0\r\n\r\n"));
socket.on("data", (chunk) => post(chunk.toString("utf8"), "\n"));
Index
Functions
- connect(options, callback)
- connect(port, host, callback)
- createConnection(options, callback)
- createServer(options, secureConnectionListener)
Classes
Interfaces
function connect
Creates a tls.TLSSocket and connects.
function connect(options: ConnectOptions, callback?: () => void): TLSSocket;
| Name | Type | Description |
|---|---|---|
| options | ConnectOptions | |
| optional callback | () => void | |
| Return Value | TLSSocket |
function connect
Creates a tls.TLSSocket and connects to a port/host.
function connect(
port: number,
host?: string,
callback?: () => void,
): TLSSocket;
| Name | Type | Description |
|---|---|---|
| port | number | |
| optional host | string | |
| optional callback | () => void | |
| Return Value | TLSSocket |
interface ConnectOptions
Options for tls.connect.
Properties
ca string | buffer.IOBuffer
Trusted CA certificate(s) (PEM string or buffer.IOBuffer).
cert string | buffer.IOBuffer
Client certificate (PEM string or buffer.IOBuffer).
host string
key string | buffer.IOBuffer
Client private key (PEM string or buffer.IOBuffer).
port number
rejectUnauthorized boolean
Verify the peer certificate (default true). Set false for self-signed/dev certs.
servername string
Server name for the connection.
function createConnection
Alias of tls.connect.
function createConnection(
options: ConnectOptions,
callback?: () => void,
): TLSSocket;
| Name | Type | Description |
|---|---|---|
| options | ConnectOptions | |
| optional callback | () => void | |
| Return Value | TLSSocket |
function createServer
Creates a TLS tls.Server. Requires key and cert.
function createServer(
options: ServerOptions,
secureConnectionListener?: (socket: TLSSocket) => void,
): Server;
| Name | Type | Description |
|---|---|---|
| options | ServerOptions | |
| optional secureConnectionListener | (socket: TLSSocket) => void | |
| Return Value | Server |
interface PeerCertificate
A summary of a peer certificate, as returned by tls.TLSSocket.getPeerCertificate().
Properties
issuer string
subject string
valid_from string
valid_to string
class Server
A TLS server. Accepted secure sockets are delivered as tls.TLSSocket instances.
Events: listening, secureConnection, close, error.
Methods
- address()
- close(callback)
- listen(port, host, callback)
- listen(options, callback)
- off(event, listener)
- on(event, listener)
- once(event, listener)
address()
address(): AddressInfo;
| Name | Type | Description |
|---|---|---|
| Return Value | AddressInfo |
close(callback)
close(callback?: () => void): this;
| Name | Type | Description |
|---|---|---|
| optional callback | () => void | |
| Return Value | this |
listen(port, host, callback)
listen(port: number, host?: string, callback?: () => void): this;
| Name | Type | Description |
|---|---|---|
| port | number | |
| optional host | string | |
| optional callback | () => void | |
| Return Value | this |
listen(options, callback)
listen(
options: { port?: number; host?: string },
callback?: () => void,
): this;
| Name | Type | Description |
|---|---|---|
| options | object | optional options.port number optional options.host string |
| optional callback | () => void | |
| Return Value | this |
off(event, listener)
off(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
on(event, listener)
on(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
once(event, listener)
once(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
interface ServerOptions
Options for tls.createServer(). key and cert are required.
Properties
cert string | buffer.IOBuffer
key string | buffer.IOBuffer
class TLSSocket
A TLS/SSL stream socket. Verifies peer certificates by default.
Events: connect, secureConnect, data, drain, close, error.
Properties
Methods
- address()
- connect(optionsOrPort, hostOrCallback, callback)
- destroy()
- end(chunk, encoding, callback)
- getPeerCertificate()
- off(event, listener)
- on(event, listener)
- once(event, listener)
- pause()
- resume()
- write(chunk, encoding, callback)
address()
Returns the local endpoint once connected.
address(): AddressInfo;
| Name | Type | Description |
|---|---|---|
| Return Value | AddressInfo |
authorizationError string read-only
The verification error message, when not authorized.
authorized boolean read-only
Whether the peer certificate was verified.
connect(optionsOrPort, hostOrCallback, callback)
Connects and performs the TLS handshake.
connect(
optionsOrPort: ConnectOptions | number,
hostOrCallback?: string | (() => void),
callback?: () => void,
): this;
| Name | Type | Description |
|---|---|---|
| optionsOrPort | ConnectOptions | number | |
| optional hostOrCallback | string | (() => void) | |
| optional callback | () => void | |
| Return Value | this |
destroy()
Destroys the socket.
destroy(): void;
destroyed boolean read-only
encrypted boolean read-only
Always true for a TLS socket.
end(chunk, encoding, callback)
Sends an optional final chunk and half-closes the socket.
end(
chunk?: string | buffer.IOBuffer | ArrayBufferView,
encoding?: string,
callback?: () => void,
): void;
| Name | Type | Description |
|---|---|---|
| optional chunk | string | buffer.IOBuffer | ArrayBufferView | |
| optional encoding | string | |
| optional callback | () => void |
getPeerCertificate()
Returns a summary of the peer certificate, when available.
getPeerCertificate(): PeerCertificate | undefined;
| Name | Type | Description |
|---|---|---|
| Return Value | PeerCertificate | undefined |
localAddress string read-only
localPort number read-only
off(event, listener)
Removes an event listener.
off(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
on(event, listener)
Registers an event listener.
on(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
once(event, listener)
Registers a one-shot event listener.
once(event: string, listener: (...args: any[]) => void): this;
| Name | Type | Description |
|---|---|---|
| event | string | |
| listener | (...args: any[]) => void | |
| Return Value | this |
pause()
Pauses delivery of data events (single pending chunk).
pause(): void;
remoteAddress string read-only
remotePort number read-only
resume()
Resumes delivery of data events.
resume(): void;
write(chunk, encoding, callback)
Queues data to send. Returns false under backpressure.
write(
chunk: string | buffer.IOBuffer | ArrayBufferView,
encoding?: string,
callback?: () => void,
): boolean;
| Name | Type | Description |
|---|---|---|
| chunk | string | buffer.IOBuffer | ArrayBufferView | |
| optional encoding | string | |
| optional callback | () => void | |
| Return Value | boolean |