cacertfile vs certstore for portable Erlang TLS certificate validation
0 reputation · 12 Aug 2023, 18:54 UTC
Designing a portable Erlang/OTP TLS client that validates server certificates without relying on the host OS trust store raises a documented trade-off between two ssl options.
The ssl module supports certificate validation via the verify option. A static PEM bundle can be supplied with cacertfile for portability across deployments. The certstore option enables use of a pre-compiled certificate store for lookup and validation.
The constraint is maintaining a self-contained release that remains valid as CA bundles change, while keeping DNS resolution for the target host handled by the inet module. The behavior of validation and the maintenance cost of each approach is not fully clear for a release that must run on heterogeneous systems.
Which documented differences exist between cacertfile and certstore regarding how trusted CAs are loaded for ssl connections? Does the choice affect hostname verification when DNS resolution is performed by inet? What are the documented maintenance implications for CA rotation with each option?