bk99.de entertain the web since 1997

The first few milliseconds of an HTTPS connection

Summary

Jeff Moser breaks an HTTPS connection down into DNS, TCP, the TLS handshake, certificate validation, key exchange and encrypted HTTP data. The article illustrates a complete TLS handshake. Certificate authorities sign certificates within a chain of trust.

Ideas

  • TCP establishes a reliable bidirectional byte stream before TLS.
  • ClientHello and ServerHello negotiate the version, random values and cipher suite.
  • The certificate binds a public key to a verified name.
  • The client validates the signature chain, validity and target name.
  • The key exchange creates a shared secret without transmitting it in plain text.
  • Symmetric keys then protect large amounts of data efficiently.

Insights

  • Secure connections consist of several independent stages of trust and transport.
  • A valid certificate proves identity according to the rules of the chosen chain of trust.
  • Latency arises from round trips, computation and external validation together.
  • Protocol visualisations make invisible security assumptions verifiable.

Facts

  • HTTPS carries HTTP within a TLS connection.
  • Session resumption can shorten later handshakes.

Recommendations

  • Check the certificate chain, name and clock separately when TLS errors occur.
  • Enable modern protocol versions and remove outdated cipher suites.
  • Measure DNS, TCP, TLS and application time individually.

References

Read the original article

Search the Web Archive