ClientHello
Offers protocol versions, cipher suites, key share, SNI and ALPN.
SECURE APPLICATION TRANSPORT · TLS 1.3
HTTPS is HTTP semantics carried inside a TLS-protected channel. Step through negotiation, certificate validation and key agreement, then inject realistic failures without dismissing a browser security warning.
HANDSHAKE SIMULATOR
A conceptual TLS 1.3 trace. Cryptographic details are simplified, but message order and trust decisions remain explicit.
ClientClientHello ↔ ServerHelloLeaf → Intermediate → RootGET / HTTP/…CERTIFICATE INSPECTOR
WHAT EACH STEP ESTABLISHES
Offers protocol versions, cipher suites, key share, SNI and ALPN.
Selects compatible parameters and contributes a key share.
Proves possession of the private key associated with the certificate.
Authenticates the handshake transcript before application data begins.
BOUNDARIES
| Property | Protected | Important limitation |
|---|---|---|
| Confidentiality | HTTP path, headers and body inside TLS | Endpoints still see plaintext. |
| Integrity | Tampering is detected by authenticated encryption. | Does not make application data truthful. |
| Server identity | Certificate chain and name validation. | Depends on trust-store and CA governance. |
| Metadata | Some handshake fields are increasingly encrypted. | IP addresses, timing and traffic sizes remain observable. |
CLASSROOM TASKS