Skip to main content
Book 07 · SecurityPage 45 of 50

TLS

Transport Layer Security

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/tls

In short

TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.

What is TLS?

Transport Layer Security is the standard protocol for creating a secure channel between two programs over an untrusted network such as the internet. It provides confidentiality, so eavesdroppers cannot read the data; integrity, so changes in transit are detected; and authentication, so the client can confirm it is talking to the real server. TLS replaced the older SSL protocol, which is now obsolete, although many people still say SSL out of habit.

Every TLS connection starts with a handshake. The client lists the versions and cipher suites it supports, the server replies with its choice and its certificate, and the client checks that the certificate was signed by a trusted certificate authority and matches the domain name. The two sides then agree on fresh session keys and switch to fast symmetric encryption for the rest of the conversation; TLS 1.3 completes the handshake in a single round trip.

If the internet is a public road, TLS is a sealed, armored van whose driver shows verified ID: observers can see which address the van is heading to, but not what is inside. TLS is not only for websites; it also secures email delivery, database connections, APIs between services, and WebSocket connections over wss://.

TLS and HTTPS are often confused. TLS is the security layer, and HTTPS is simply HTTP carried over TLS, just as wss:// is WebSocket over TLS. To configure it safely, allow only TLS 1.2 and 1.3, disable old protocols and weak ciphers, renew certificates automatically with a service such as Let's Encrypt, and never turn off certificate verification in client code, even to silence an error during development.

At a glance

A simplified TLS 1.3 handshake: the client sends ClientHello, the server replies with ServerHello and its certificate, the client checks the certificate, both sides agree on session keys, and encrypted data then flows both ways.ClientServer1ClientHello · versions, cipher suites2ServerHello · its choice + certificate3Checks the certificatetrusted CA, matching domain4Session keys agreedencrypted data, both ways
TLS 1.3 needs a single round trip: hellos, a certificate check and fresh keys, then fast symmetric encryption for everything else.

Key takeaways

  • TLS encrypts network traffic and verifies the server's identity.
  • It replaced SSL, which is obsolete and insecure.
  • The handshake checks the certificate and agrees on session keys.
  • HTTPS is HTTP over TLS; TLS also secures email, databases, and APIs.
  • Allow only TLS 1.2 and 1.3, and never disable certificate verification.

Example

Making a verified TLS request (Node.js)javascript
import https from "node:https";

// Secure by default: Node checks that the certificate is valid,
// signed by a trusted authority, and issued for this hostname
https.get("https://api.example.com/health", (res) => {
  console.log(res.socket.getProtocol()); // e.g. "TLSv1.3"
  console.log(res.statusCode);
});

// Dangerous: disabling verification allows man-in-the-middle attacks
// https.get(url, { rejectUnauthorized: false }); // never ship this

Readers ask

What is the difference between TLS and SSL?

SSL is the original secure transport protocol from the 1990s, and all its versions are now broken and disabled in modern software. TLS is its successor, with TLS 1.2 and TLS 1.3 in use today, even though certificates are still often called SSL certificates.

What is the difference between TLS and HTTPS?

TLS is a general-purpose security protocol that can protect many kinds of network traffic. HTTPS is one specific use of it: ordinary HTTP messages sent through a TLS-encrypted connection.

What is mutual TLS?

In mutual TLS, or mTLS, both sides present certificates, so the server also verifies the client's identity. It is common for service-to-service communication in zero trust networks and for high-security APIs.

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings