Contains the security properties of the request (ie. SSL/TLS information).

interface SecurityInfo {
    certificates: CertificateInfo[];
    certificateTransparencyStatus?: CertificateTransparencyStatus;
    cipherSuite?: string;
    errorMessage?: string;
    hpkp?: string;
    hsts?: boolean;
    isDomainMismatch?: boolean;
    isExtendedValidation?: boolean;
    isNotValidAtThisTime?: boolean;
    isUntrusted?: boolean;
    keaGroupName?: string;
    overridableErrorCategory?: _SecurityInfoOverridableErrorCategory;
    protocolVersion?: _SecurityInfoProtocolVersion;
    secretKeyLength?: number;
    signatureSchemeName?: string;
    state: _SecurityInfoState;
    usedDelegatedCredentials?: boolean;
    usedEch?: boolean;
    usedOcsp?: boolean;
    usedPrivateDns?: boolean;
    weaknessReasons?: "cipher"[];
}
Index
certificates: CertificateInfo[]

Certificate data if state is "secure". Will only contain one entry unless certificateChain is passed as an option.

certificateTransparencyStatus?: CertificateTransparencyStatus

Certificate transparency compliance per RFC 6962. See https://www.certificate-transparency.org/what-is-ct for more information.

cipherSuite?: string

The cipher suite used in this request if state is "secure".

errorMessage?: string

Error message if state is "broken"

hpkp?: string

True if host uses Public Key Pinning and state is "secure".

hsts?: boolean

True if host uses Strict Transport Security and state is "secure".

isDomainMismatch?: boolean

The domain name does not match the certificate domain.

Please use SecurityInfo.overridableErrorCategory.

isExtendedValidation?: boolean
isNotValidAtThisTime?: boolean

The certificate is either expired or is not yet valid. See CertificateInfo.validity for start and end dates.

Please use SecurityInfo.overridableErrorCategory.

isUntrusted?: boolean

Please use SecurityInfo.overridableErrorCategory.

keaGroupName?: string

The key exchange algorithm used in this request if state is "secure".

overridableErrorCategory?: _SecurityInfoOverridableErrorCategory

The type of certificate error that was overridden for this connection, if any.

Protocol version if state is "secure"

secretKeyLength?: number

The length (in bits) of the secret key.

signatureSchemeName?: string

The signature scheme used in this request if state is "secure".

usedDelegatedCredentials?: boolean

True if the TLS connection used Delegated Credentials.

usedEch?: boolean

True if the TLS connection used Encrypted Client Hello.

usedOcsp?: boolean

True if the TLS connection made OCSP requests.

usedPrivateDns?: boolean

True if the TLS connection used a privacy-preserving DNS transport like DNS-over-HTTPS.

weaknessReasons?: "cipher"[]

list of reasons that cause the request to be considered weak, if state is "weak"