Part 7 · 2 chapters · ~12 min

TLS

What TLS protects, the TLS 1.3 handshake, ECDHE and forward secrecy, certificates, chains and trust stores, hostname verification and SNI, ALPN, session resumption and 0-RTT, mutual TLS, certificate lifecycle with ACME, and common TLS failures in production.

14

The handshake

code
openssl s_client -connect api.bank.example:443 -servername api.bank.example -alpn h2 </dev/null 2>/dev/null | \
  grep -E 'Protocol|Cipher|subject|issuer|ALPN|Verify'
curl -sv https://api.bank.example 2>&1 | grep -E 'SSL connection|ALPN|subject|expire'
A TLS 1.3 HANDSHAKE
one round trip to an encrypted, authenticated channel
clientserverClientHello: versions, ciphers, key share, SNI, ALPN
swipe the figure sideways, or tap expand for full screen
1/4
key shares first
The client guesses the key exchange group and sends its key share in the first message (ECDHE). SNI names the site; ALPN offers h2 or http/1.1.
ECDHE key share in the first flightSNI and ALPN ride along
15

Certificates in production

failurecauseprevention
expired certificatemanual renewal forgottenACME automation (Let's Encrypt, cert-manager), expiry alerts
incomplete chainserver sends the leaf without intermediates; some clients failserve the full chain; test with several clients
hostname mismatchcertificate does not cover the name (missing SAN)SANs for every name; wildcards where appropriate
old Android devices failingtrust store lacks a newer rootcheck chain compatibility for your users' devices
mTLS client rejectedclient cert from the wrong CA or expiredshort-lived certs issued automatically (Mesh course, SPIFFE)

Cryptography and Security Foundations (course 34) explains the primitives underneath: key exchange, signatures, AEAD ciphers and PKI.