learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

TLS & HTTPS

How two strangers agree on a secret while everyone listens, and how the client knows who it is talking to.

An interactive Networking lesson: 22 steps, about 32 minutes, on a live simulation in your browser.

Ada is at home, about to sign in to shop.example. The shop still serves its login page over plain HTTP on port 80. Her laptop opens a TCP connection to web and asks for /login.

Follow the packets. Between the laptop and the server there are three machines that neither Ada nor the shop controls: her home router, her ISP, and the backbone. Each one receives every packet in full, looks at it, and passes it on.

What you will learn

  1. HTTP in the clear

    • A shop that still speaks plain HTTP
    • Every hop can read it: Plain HTTP is a postcard: every machine that carries it can read it, copy it and rewrite it, and nobody can tell.
    • Three promises: TLS promises three things: nobody on the path can read it, nobody can change it unnoticed, and the other end is who the name says.
  2. The TLS 1.3 handshake

    • Two strangers, one open line
    • ClientHello: the only cleartext: The ClientHello is the one message anyone can read: it names the site (SNI) and already carries the client's half of the key exchange.
    • The server answers everything at once: TLS 1.3 is one round trip: hello and key share out; key share, certificate, proof and Finished back; then data.
    • A secret nobody sent: Each side combines its own secret with the other's public value and gets the same key. The key itself never crosses the wire.
    • The same request, encrypted
  3. Certificates and trust

    • Who vouches for the key?: A certificate is a name and a public key, signed by someone the client already trusts, or by someone who is signed by one.
    • Three checks on every certificate: The client checks three things: a signature chain to a root it trusts, today's date inside the validity window, and its hostname in the SAN list.
  4. When the handshake fails

    • Break it: the certificate expires
    • Break it: a wildcard that misses
    • Break it: an issuer nobody knows: An untrusted-issuer error means the chain does not reach a root this client holds. Fix the chain or the trust store, never the check.
    • Break it: no version in common: curl 35: the handshake itself failed (version, cipher, not TLS at all). curl 60: the handshake worked and the certificate was refused.
  5. Round trips and resumption

    • TLS 1.2 pays a second round trip: TLS 1.2: hello, then keys, then data, two round trips. TLS 1.3 sends the key share with the hello and saves one.
    • Resumption: skip the introductions: Resumption reuses a ticket from an earlier handshake: no certificate, no signature, the same one round trip.
  6. What HTTPS does not hide

    • What the ISP still sees: Under HTTPS the path can no longer read what was said. It still sees whom you spoke to, when and how much: addresses, ports, the server name, sizes, timing.
  7. Debugging a handshake

    • Read the error, find the layer: curl's exit code names the layer: 6 DNS, 7 and 28 TCP, 35 the TLS handshake, 60 the certificate.
    • Drill: look at the handshake
    • Drill: is it in date, and for whom?
  8. Recap & playground

    • Cheat sheet
    • Playground