tls.createSecureContext
History
certificateCompression option has been added.allowPartialTrustChain option has been added.clientCertEngine, privateKeyEngine and privateKeyIdentifier options depend on custom engine support in OpenSSL which is deprecated in OpenSSL 3.dhparam option can now be set to 'auto' to enable DHE with appropriate well-known parameters.privateKeyIdentifier and privateKeyEngine options to get private key from an OpenSSL engine.sigalgs option to override supported signature algorithms.ca: option now supports BEGIN TRUSTED CERTIFICATE.minVersion and maxVersion can be used to restrict the allowed TLS protocol versions.ecdhCurve cannot be set to false anymore due to a change in OpenSSL.options parameter can now include clientCertEngine.ecdhCurve option can now be multiple ':' separated curve names or 'auto'.key option is an array, individual entries do not need a passphrase property anymore. Array entries can also just be strings or Buffers now.ca option can now be a single string containing multiple CA certificates.tls.createSecureContext(options?): void
Objectbooleantls.getCACertificates() using the
default type. If specified, the default list would be completely replaced
(instead of being concatenated) by the certificates in the ca option.
Users need to concatenate manually if they wish to add additional certificates
instead of completely overriding the default.
The value can be a string or Buffer, or an Array of
strings and/or Buffers. Any string or Buffer can contain multiple PEM
CAs concatenated together. The peer's certificate must be chainable to a CA
trusted by the server for the connection to be authenticated. When using
certificates that are not chainable to a well-known CA, the certificate's CA
must be explicitly specified as a trusted or the connection will fail to
authenticate.
If the peer uses a certificate that doesn't match or chain to one of the
default CAs, use the ca option to provide a CA certificate that the peer's
certificate can match or chain to.
For self-signed certificates, the certificate is its own CA, and must be
provided.
For PEM encoded certificates, supported types are "TRUSTED CERTIFICATE",
"X509 CERTIFICATE", and "CERTIFICATE".key,
followed by the PEM formatted intermediate certificates (if any), in order,
and not including the root CA (the root CA must be pre-known to the peer,
see ca). When providing multiple cert chains, they do not have to be in
the same order as their private keys in key. If the intermediate
certificates are not provided, the peer will not be able to validate the
certificate, and the handshake will fail.string[]'zlib', 'brotli', and 'zstd'. When set, enables TLS certificate
compression (RFC 8879) which compresses certificates during the TLS
handshake, reducing handshake size. Only effective with TLSv1.3.
Default: [] (disabled).stringSHA256, MD5 etc.), public key
algorithms (RSA-PSS, ECDSA etc.), combination of both (e.g
'RSA+SHA384') or TLS v1.3 scheme names (e.g. rsa_pss_pss_sha512).
See OpenSSL man pages
for more info.stringtls.getCiphers(). Cipher names must be
uppercased in order for OpenSSL to accept them.string'auto' or custom Diffie-Hellman parameters,
required for non-ECDHE perfect forward secrecy. If omitted or invalid,
the parameters are silently discarded and DHE ciphers will not be available.
ECDHE-based perfect forward secrecy will still be available.stringP-521:P-384:P-256, X25519, or X25519MLKEM768. The
historical name of this option refers to ECDH key agreement in TLSv1.2 and
below. In TLSv1.3, this option configures the TLS Supported Groups and
key share groups offered or accepted by the TLS stack. Set to auto to
select the group automatically. Use crypto.getCurves() to obtain a
list of available elliptic curve names. For TLS group names, use
openssl list -tls-groups or consult the IANA TLS Supported Groups
registry.
Default: tls.DEFAULT_ECDH_CURVE.booleantrue, causes
SSL_OP_CIPHER_SERVER_PREFERENCE to be set in secureOptions, see
OpenSSL Options for more information.options.passphrase. Multiple keys using
different algorithms can be provided either as an array of unencrypted key
strings or buffers, or an array of objects in the form
{pem: <string|buffer>[, passphrase: <string>]}. The object form can only
occur in an array. object.passphrase is optional. Encrypted keys will be
decrypted with object.passphrase if provided, or options.passphrase if
it is not.stringprivateKeyIdentifier. Deprecated.stringprivateKeyEngine.
Should not be set together with key, because both options define a
private key in different ways. Deprecated.string'TLSv1.3', 'TLSv1.2', 'TLSv1.1', or 'TLSv1'. Cannot be specified
along with the secureProtocol option; use one or the other.
Default: tls.DEFAULT_MAX_VERSION.string'TLSv1.3', 'TLSv1.2', 'TLSv1.1', or 'TLSv1'. Cannot be specified
along with the secureProtocol option; use one or the other. Avoid
setting to less than TLSv1.2, but it may be required for
interoperability. Versions before TLSv1.2 may require downgrading the OpenSSL Security Level.
Default: tls.DEFAULT_MIN_VERSION.stringpfx is an alternative to providing
key and cert individually. PFX is usually encrypted, if it is,
passphrase will be used to decrypt it. Multiple PFX can be provided either
as an array of unencrypted PFX buffers, or an array of objects in the form
{buf: <string|buffer>[, passphrase: <string>]}. The object form can only
occur in an array. object.passphrase is optional. Encrypted PFX will be
decrypted with object.passphrase if provided, or options.passphrase if
it is not.numberSSL_OP_* options from
OpenSSL Options.stringminVersion and maxVersion instead. The possible values are listed as
SSL_METHODS, use the function names as strings. For example,
use 'TLSv1_1_method' to force TLS version 1.1, or 'TLS_method' to allow
any TLS protocol version up to TLSv1.3. It is not recommended to use TLS
versions less than 1.2, but it may be required for interoperability.
Default: none, see minVersion.stringBuffernumber300.tls.createServer() sets the default value of the honorCipherOrder option
to true, other APIs that create secure contexts leave it unset.
tls.createServer() uses a 128 bit truncated SHA1 hash value generated
from process.argv as the default value of the sessionIdContext option, other
APIs that create secure contexts have no default value.
The tls.createSecureContext() method creates a SecureContext object. It is
usable as an argument to several tls APIs, such as server.addContext(),
but has no public methods. The tls.Server constructor and the
tls.createServer() method do not support the secureContext option.
A key is required for ciphers that use certificates. Either key or
pfx can be used to provide it.
If the ca option is not given, then Node.js will default to using
Mozilla's publicly trusted list of CAs.
Custom DHE parameters are discouraged in favor of the new dhparam: 'auto'
option. When set to 'auto', well-known DHE parameters of sufficient strength
will be selected automatically. Otherwise, if necessary, openssl dhparam can
be used to create custom parameters. The key length must be greater than or
equal to 1024 bits or else an error will be thrown. Although 1024 bits is
permissible, use 2048 bits or larger for stronger security.