radcli_ctx_set_tls_psk(3) Radius client library radcli_ctx_set_tls_psk(3) NAME radcli_ctx_set_tls_psk - Set the RFC 6614/7360 TLS-transport Pre-Shared Key credentials for the configured authserver. SYNOPSIS #include int radcli_ctx_set_tls_psk( radcli_ctx *ctx, const void *identity, size_t identity_len, const uint8_t *key, size_t keylen ); DESCRIPTION The equivalent, for the new API, of the legacy authserver host:port:psk@username@hexkey inline form but with identity and key as independent byte buffers instead of a delimited string, so a username containing @ cannot be misparsed (the legacy form splits on the first @ after the psk@ prefix) and the key never needs to be hex-encoded by the caller. Only meaningful when #RADCLI_OPT_SERV_TYPE is tls or dtls; takes priority over any psk@username@hexkey embedded in #RADCLI_OPT_AUTHSERVER's value, should both somehow be set. PARAMETERS ctx a context, before radcli_ctx_apply(). identity the PSK identity; GnuTLS treats this as a NUL-terminated string once passed on, so an identity containing an embedded NUL byte is truncated there a GnuTLS API constraint, not an ambiguity this function introduces. identity_len identity's length in bytes. key the raw PSK key bytes (not hex-encoded text). keylen key's length in bytes. RETURN VALUE 0 on success, -1 on failure (NULL ctx/identity/key, or keylen 0). SEE ALSO radcli_ctx_apply(3), radcli_ctx_free(3), radcli_ctx_get_opt_int(3), radcli_ctx_get_opt_str(3), radcli_ctx_new(3), radcli_ctx_read_config(3), radcli_ctx_read_dictionary(3), radcli_ctx_read_dictionary_from_buffer(3), radcli_ctx_set_opt_int(3), radcli_ctx_set_opt_str(3), radcli_ctx_set_secret(3) radcli 2026-09-03 radcli_ctx_set_tls_psk(3)