TLS
Transport Layer Security
In short
TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
What is TLS?
Transport Layer Security is the standard protocol for creating a secure channel between two programs over an untrusted network such as the internet. It provides confidentiality, so eavesdroppers cannot read the data; integrity, so changes in transit are detected; and authentication, so the client can confirm it is talking to the real server. TLS replaced the older SSL protocol, which is now obsolete, although many people still say SSL out of habit.
Every TLS connection starts with a handshake. The client lists the versions and cipher suites it supports, the server replies with its choice and its certificate, and the client checks that the certificate was signed by a trusted certificate authority and matches the domain name. The two sides then agree on fresh session keys and switch to fast symmetric encryption for the rest of the conversation; TLS 1.3 completes the handshake in a single round trip.
If the internet is a public road, TLS is a sealed, armored van whose driver shows verified ID: observers can see which address the van is heading to, but not what is inside. TLS is not only for websites; it also secures email delivery, database connections, APIs between services, and WebSocket connections over wss://.
TLS and HTTPS are often confused. TLS is the security layer, and HTTPS is simply HTTP carried over TLS, just as wss:// is WebSocket over TLS. To configure it safely, allow only TLS 1.2 and 1.3, disable old protocols and weak ciphers, renew certificates automatically with a service such as Let's Encrypt, and never turn off certificate verification in client code, even to silence an error during development.
At a glance
Key takeaways
- TLS encrypts network traffic and verifies the server's identity.
- It replaced SSL, which is obsolete and insecure.
- The handshake checks the certificate and agrees on session keys.
- HTTPS is HTTP over TLS; TLS also secures email, databases, and APIs.
- Allow only TLS 1.2 and 1.3, and never disable certificate verification.
Example
import https from "node:https";
// Secure by default: Node checks that the certificate is valid,
// signed by a trusted authority, and issued for this hostname
https.get("https://api.example.com/health", (res) => {
console.log(res.socket.getProtocol()); // e.g. "TLSv1.3"
console.log(res.statusCode);
});
// Dangerous: disabling verification allows man-in-the-middle attacks
// https.get(url, { rejectUnauthorized: false }); // never ship thisReaders ask
What is the difference between TLS and SSL?
SSL is the original secure transport protocol from the 1990s, and all its versions are now broken and disabled in modern software. TLS is its successor, with TLS 1.2 and TLS 1.3 in use today, even though certificates are still often called SSL certificates.
What is the difference between TLS and HTTPS?
TLS is a general-purpose security protocol that can protect many kinds of network traffic. HTTPS is one specific use of it: ordinary HTTP messages sent through a TLS-encrypted connection.
What is mutual TLS?
In mutual TLS, or mTLS, both sides present certificates, so the server also verifies the client's identity. It is common for service-to-service communication in zero trust networks and for high-security APIs.
See also
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- WebSocketWeb Development, p. 61WebSocket is a protocol that keeps a single connection open between a browser and a server so both sides can send each other messages instantly at any time.
- CDNDevOps & Cloud, p. 7A CDN is a network of servers spread around the world that stores copies of website content and delivers it to each user from the nearest location.
Sources
Spotted a mistake or something missing on this page?Suggest an edit