Tags: web-dev concept

TLS and HTTPS

Date: 2026-08-17


Encryption plus identity. The encryption is the part everyone names; the identity — proving the server is who it claims to be — is the part that actually stops the attack, and the part that expires and takes sites down.


TLS (Transport Layer Security) encrypts a connection and authenticates the server. HTTPS is HTTP carried over TLS. TLS replaced SSL long ago; “SSL certificate” persists as a name for a TLS certificate.

Three guarantees

CONFIDENTIALITY  nobody in between can read it
INTEGRITY        nobody can alter it undetected
AUTHENTICITY     the server is who it claims
                 ← the one that matters most

Encryption without authenticity is worthless. An encrypted connection to an attacker is still a connection to an attacker. The certificate chain is what prevents that, and it’s why certificate errors are hard blocks rather than warnings.

The handshake

CLIENT                        SERVER
 │ ClientHello       ────────→│
 │   versions, ciphers        │
 │←──────── ServerHello       │
 │   chosen cipher,           │
 │   CERTIFICATE              │
 │                            │
 │ verify the certificate     │
 │ chain against trusted      │
 │ roots                      │
 │                            │
 │ key exchange      ←───────→│
 │                            │
 │ encrypted from here on     │
TLS 1.2    2 round trips
TLS 1.3    1 round trip
           0-RTT on resumption

TLS 1.3 halved the setup cost, which on mobile is the difference between a noticeable and an unnoticeable delay — How the Web Works.

The certificate chain

A certificate authority (CA) is an organisation browsers and operating systems trust to vouch for identities.

ROOT CA              in the OS/browser
  │  signs           trust store
INTERMEDIATE CA
  │  signs
YOUR CERTIFICATE     shop.example.com

The browser trusts the root, the root vouches for the intermediate, the intermediate vouches for you. The server must send the intermediates — omitting them is the classic misconfiguration that works in browsers with cached intermediates and fails in others, which makes it maddening to diagnose.

What actually breaks

EXPIRED CERTIFICATE
  the most common outage in this list,
  and entirely preventable. Automate
  renewal, and alert on 30 days

WRONG HOSTNAME
  cert for example.com, served on
  www.example.com. A wildcard
  *.example.com covers one level only —
  not example.com itself, and not
  a.b.example.com

MISSING INTERMEDIATES
  works in some clients, not others

MIXED CONTENT
  an HTTPS page loading HTTP subresources
  → blocked, silently, and the feature
    just doesn't work

CLOCK SKEW
  a device with the wrong date sees
  every certificate as invalid

Expiry is the one to build process around. Certificates are now typically short-lived — 90 days or less — precisely because it forces automation, and manual renewal at that cadence will eventually be missed.

Headers that go with it

Strict-Transport-Security
  max-age=31536000; includeSubDomains
  → the browser refuses plain HTTP for
    this host, removing the redirect
    from the attack surface

Content-Security-Policy
  → what may load and execute

See: Content Security Policy

HSTS — HTTP Strict Transport Security — is close to irreversible. A browser that has seen the header will not connect over HTTP for the whole max-age, so shipping a long max-age before HTTPS works everywhere locks users out. Start short, then raise it.

What TLS does not hide

HIDDEN                 VISIBLE
the URL path           the hostname (via SNI)
headers, cookies       your IP and theirs
the request body       timing and size
the response           the DNS lookup that
                       preceded it

The hostname leaks because the server needs to know which certificate to present before encryption is established. Encrypted Client Hello addresses this and is not yet universal. The DNS query is usually plaintext too unless DNS-over-HTTPS is in use — DNS.

Practical position

  • HTTPS everywhere, including staging and internal tools. Mixed environments produce mixed-content bugs
  • Automate renewal, and alert well before expiry
  • Redirect HTTP → HTTPS once, then let HSTS remove the redirect entirely
  • Check with an external analyser rather than your own browser, which may have cached what’s missing
  • HTTPS is a ranking signal and a prerequisite for HTTP/2, service workers, and most modern browser APIs — the SEO argument is the least of the reasons — Technical SEO