Skip to content

expose SSL_export_keying_material via Node API (e.g. like SSL_get_shared_sigalgs)  #31802

Description

@simllll

Is your feature request related to a problem? Please describe.
I'm trying to generate a check sum that is based on the keying material (https://stackoverflow.com/questions/60232165/ssl-export-keying-material-in-node-js). Right now node has no method to call this function, or any other way of retrieving this information.

Describe the solution you'd like
Expose an api like the GetSharedSigalgs that offers a way to access the native SSL export keying material method.
see https://nodejs.org/api/tls.html#tls_tlssocket_getsharedsigalgs
for the keying material method see https://www.openssl.org/docs/man1.0.2/man3/SSL_export_keying_material.html

Describe alternatives you've considered
I tried to get this kind of information via 'keylog' event, but this is never emitted in my scenario. I also believe (couldn't verify though), that this is something else than the exporting keying material function offers, due to the fact that I cannot provide any label to "keylog" which is mandatory for the keying material method.

Subsystem: tls (tls.TLSSocket)

Activity

  1. added
    cryptoIssues and PRs related to the crypto subsystem.
    feature requestIssues requesting new Node.js features.
    on Feb 14, 2020
  2. jasnell commented on Feb 14, 2020

    @jasnell
    Member

    /cc @nodejs/crypto

  3. sam-github commented on Feb 14, 2020

    @sam-github
    Contributor

    keylog is delivered from https://www.openssl.org/docs/man1.1.1/man3/SSL_CTX_set_keylog_callback.html, but if that isn't what you need exposing this new API seems reasonable.

    Care to take a shot at it? It seems you've already found the code it would be similar to.

  4. bnoordhuis commented on Feb 15, 2020

    @bnoordhuis
    Member

    There's a mildly slippery slope here in that SSL_export_keying_material_early() is probably also necessary for TLSv1.3 - although that's only relevant with 0-RTT and Node doesn't really support that right now.

    (I say "not really" because I think a tls.Server instance still accepts it but then proceeds to terminate the connection. We should probably have a test for that so we'll be aware of behavior changes.)

  5. simllll commented on Feb 15, 2020

    @simllll
    ContributorAuthor

    @sam-github I tried my best, do you mind taking a look at it? :-) #31814

  6. added a commit that references this issue on Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.feature requestIssues requesting new Node.js features.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions