NETWORKING / A CONCEPT NOTE

TLS

how encryption happens before the lock icon appears

~75 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A handshake where the client and server agree on a cipher, exchange keys, and verify identity via a certificate chain. After that, every byte is encrypted with a session key only they know.

02 / FOLLOW THE MECHANISM

How a TLS handshake flows

  1. Client

    sends a ClientHello listing supported cipher suites and TLS versions.

  2. Server

    responds with its chosen cipher, a session ID, and its certificate chain.

  3. Client

    validates the certificate against trusted CAs, then generates a pre-master secret encrypted with the server's public key.

  4. Both

    derive the same session keys from the pre-master secret and switch to encrypted communication.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

inspect the full certificate chain

openssl s_client -connect supraj.dev:443 -showcerts

EXAMPLE 02 · REFERENCE

watch every TLS handshake step

curl -vI https://supraj.dev

Explore command anatomy in the CLI lab