Packages
hl7v2
2.3.0
3.10.1
3.9.0
3.8.0
3.7.0
3.6.0
3.5.0
3.4.0
3.3.6
3.3.5
3.3.4
3.3.3
3.3.2
3.3.1
3.3.0
3.2.0
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.11.0
2.10.0
2.9.1
2.9.0
2.8.2
2.8.1
2.8.0
2.7.1
2.7.0
2.6.0
2.5.0
2.4.0
2.3.0
2.2.0
2.1.3
2.1.2
2.1.1
2.1.0
1.4.6
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.0
1.2.0
1.1.0
1.0.0
0.6.0
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.1.0
Pure Elixir HL7 v2.x toolkit — schema-driven parsing, typed segments, message builder, MLLP transport
Current section
Files
Jump to
Current section
Files
lib/hl7v2/mllp/tls.ex
defmodule HL7v2.MLLP.TLS do
@moduledoc """
TLS configuration helpers for MLLP connections.
Provides convenience functions for building `:ssl` option lists
suitable for server-side TLS, client-side TLS, and mutual TLS (mTLS).
## Server-side TLS
tls_opts = HL7v2.MLLP.TLS.server_options(
certfile: "server.pem",
keyfile: "server-key.pem"
)
{:ok, _} = HL7v2.MLLP.Listener.start_link(port: 2576, handler: MyHandler, tls: tls_opts)
## Mutual TLS
tls_opts = HL7v2.MLLP.TLS.mutual_tls_options(
certfile: "server.pem",
keyfile: "server-key.pem",
cacertfile: "ca.pem"
)
"""
@doc """
Builds SSL options for server-side TLS.
## Required options
- `:certfile` — path to the server certificate PEM file
- `:keyfile` — path to the server private key PEM file
## Optional options
- `:cacertfile` — path to the CA certificate PEM file
- `:versions` — TLS versions (default: `[:"tlsv1.2", :"tlsv1.3"]`)
- Any additional `:ssl` options are passed through.
"""
@spec server_options(keyword()) :: keyword()
def server_options(opts) do
opts
|> Keyword.put_new(:versions, [:"tlsv1.2", :"tlsv1.3"])
|> validate_required!([:certfile, :keyfile])
end
@doc """
Builds SSL options for client-side TLS.
## Optional options
- `:cacertfile` — path to the CA certificate PEM file
- `:verify` — verification mode (default: `:verify_peer`)
- `:versions` — TLS versions (default: `[:"tlsv1.2", :"tlsv1.3"]`)
- Any additional `:ssl` options are passed through.
"""
@spec client_options(keyword()) :: keyword()
def client_options(opts) do
opts
|> Keyword.put_new(:verify, :verify_peer)
|> Keyword.put_new(:versions, [:"tlsv1.2", :"tlsv1.3"])
end
@doc """
Builds SSL options for mutual TLS (mTLS).
Both the server and client present certificates. This is the recommended
configuration for production MLLP endpoints.
## Required options
- `:certfile` — path to the certificate PEM file
- `:keyfile` — path to the private key PEM file
- `:cacertfile` — path to the CA certificate PEM file
## Optional options
- `:verify` — verification mode (default: `:verify_peer`)
- `:fail_if_no_peer_cert` — reject clients without a certificate
(default: `true`, server-side only)
- `:versions` — TLS versions (default: `[:"tlsv1.2", :"tlsv1.3"]`)
- Any additional `:ssl` options are passed through.
"""
@spec mutual_tls_options(keyword()) :: keyword()
def mutual_tls_options(opts) do
opts
|> Keyword.put_new(:verify, :verify_peer)
|> Keyword.put_new(:fail_if_no_peer_cert, true)
|> Keyword.put_new(:versions, [:"tlsv1.2", :"tlsv1.3"])
|> validate_required!([:certfile, :keyfile, :cacertfile])
end
defp validate_required!(opts, keys) do
Enum.each(keys, fn key ->
unless Keyword.has_key?(opts, key) do
raise ArgumentError, "TLS option #{inspect(key)} is required"
end
end)
opts
end
end