Repository navigation
How to use new tls.TLSSocket(...) to establish a secure connection? #43994
Description
Activity
- addeddocIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Jul 26, 2022 - addedtlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
on Jul 26, 2022 @tniessen you might be able to help.
The short answer is that
tls.connect()is the intended API for establishing secure connections — it handles certificate validation, thesecureConnectevent, and all the plumbing you described.If you need to use
new tls.TLSSocket(socket)directly (e.g. upgrading an existing connection), the modern approach is:const tlsSocket = new tls.TLSSocket(socket, { ...options }); tlsSocket.on("secureConnect", () => { if (!tlsSocket.authorized) { tlsSocket.destroy(tlsSocket.authorizationError); return; } // connection is ready });
The
secureConnectevent is the non-deprecated replacement for thesecureevent. It fires once the TLS handshake completes. You then checktlsSocket.authorized(boolean) andtlsSocket.authorizationError(set when validation fails). The legacytlsSocket.ssl.verifyError()is still available but undocumented for a reason —authorized/authorizationErroris the public API.The two unmerged docs PRs you referenced are likely stale —
secureConnecthas been the standard event since at least Node 12.This issue has been marked as stale due to 90 days of inactivity.
It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Sep 5, 2026 - added a commit that references this issue
on Sep 8, 2026 This issue has been automatically closed after 30 days of inactivity following its stale status (no activity for a total of 120 days).
If this is still relevant, feel free to reopen it or leave a comment with additional details so we can continue the discussion.
Affected URL(s)
https://nodejs.org/docs/latest-v18.x/api/tls.html
Description of the problem
What is the correct, non-deprecated way to use the
new tls.TLSSocket(...)constructor to establish a secure connection? Context: GHSA-2cpx-6pqp-wf35According to two unmerged docs PRs, when directly calling
new tls.TLSSocket(...)it is the user's responsibility to validate peer certificates and identity.In #10846 it says:
In #23915 it says:
And includes an example:
Both PRs demonstrate how to do this validation, but require use of:
'secure'event. In the current Node.js documentation, the only mention of'secure'is under the deprecatedtls.SecurePair, and is itself deprecated. It is also not clear that the'secure'event is also emitted ontls.TLSSocket.https://nodejs.org/docs/latest-v18.x/api/tls.html#event-secure
tlsSocket.ssl.verifyError(), which does not appear at all in the current documentation. Furthermore, according to TLSCallbacks => TLSWrap, better TLS inception #840 (comment)tlsSocket.sslis a "legacy property".Note that the described validation steps appear to be consistent with internal use
node/lib/_tls_wrap.js
Line 1106 in 5fbf33e
node/lib/_tls_wrap.js
Lines 1044 to 1055 in 5fbf33e
This leaves me with two concerns:
new tls.TLSSocket(...)by itself does not result in a secure connection.new tls.TLSSocket(...)to establish a secure connection without relying on APIs that are undocumented, deprecated, and/or legacy.