TLS and HTTPS
Date: 2026-08-17
Encryption plus identity. The encryption is the part everyone names; the identity — proving the server is who it claims to be — is the part that actually stops the attack, and the part that expires and takes sites down.
TLS (Transport Layer Security) encrypts a connection and authenticates the server. HTTPS is HTTP carried over TLS. TLS replaced SSL long ago; “SSL certificate” persists as a name for a TLS certificate.
Three guarantees
CONFIDENTIALITY nobody in between can read it
INTEGRITY nobody can alter it undetected
AUTHENTICITY the server is who it claims
← the one that matters most
Encryption without authenticity is worthless. An encrypted connection to an attacker is still a connection to an attacker. The certificate chain is what prevents that, and it’s why certificate errors are hard blocks rather than warnings.
The handshake
CLIENT SERVER
│ ClientHello ────────→│
│ versions, ciphers │
│←──────── ServerHello │
│ chosen cipher, │
│ CERTIFICATE │
│ │
│ verify the certificate │
│ chain against trusted │
│ roots │
│ │
│ key exchange ←───────→│
│ │
│ encrypted from here on │
TLS 1.2 2 round trips
TLS 1.3 1 round trip
0-RTT on resumption
TLS 1.3 halved the setup cost, which on mobile is the difference between a noticeable and an unnoticeable delay — How the Web Works.
The certificate chain
A certificate authority (CA) is an organisation browsers and operating systems trust to vouch for identities.
ROOT CA in the OS/browser
│ signs trust store
INTERMEDIATE CA
│ signs
YOUR CERTIFICATE shop.example.com
The browser trusts the root, the root vouches for the intermediate, the intermediate vouches for you. The server must send the intermediates — omitting them is the classic misconfiguration that works in browsers with cached intermediates and fails in others, which makes it maddening to diagnose.
What actually breaks
EXPIRED CERTIFICATE
the most common outage in this list,
and entirely preventable. Automate
renewal, and alert on 30 days
WRONG HOSTNAME
cert for example.com, served on
www.example.com. A wildcard
*.example.com covers one level only —
not example.com itself, and not
a.b.example.com
MISSING INTERMEDIATES
works in some clients, not others
MIXED CONTENT
an HTTPS page loading HTTP subresources
→ blocked, silently, and the feature
just doesn't work
CLOCK SKEW
a device with the wrong date sees
every certificate as invalid
Expiry is the one to build process around. Certificates are now typically short-lived — 90 days or less — precisely because it forces automation, and manual renewal at that cadence will eventually be missed.
Headers that go with it
Strict-Transport-Security
max-age=31536000; includeSubDomains
→ the browser refuses plain HTTP for
this host, removing the redirect
from the attack surface
Content-Security-Policy
→ what may load and execute
HSTS — HTTP Strict Transport Security — is close to irreversible. A browser that has seen the header will not connect over HTTP for the whole max-age, so shipping a long max-age before HTTPS works everywhere locks users out. Start short, then raise it.
What TLS does not hide
HIDDEN VISIBLE
the URL path the hostname (via SNI)
headers, cookies your IP and theirs
the request body timing and size
the response the DNS lookup that
preceded it
The hostname leaks because the server needs to know which certificate to present before encryption is established. Encrypted Client Hello addresses this and is not yet universal. The DNS query is usually plaintext too unless DNS-over-HTTPS is in use — DNS.
Practical position
- HTTPS everywhere, including staging and internal tools. Mixed environments produce mixed-content bugs
- Automate renewal, and alert well before expiry
- Redirect HTTP → HTTPS once, then let HSTS remove the redirect entirely
- Check with an external analyser rather than your own browser, which may have cached what’s missing
- HTTPS is a ranking signal and a prerequisite for HTTP/2, service workers, and most modern browser APIs — the SEO argument is the least of the reasons — Technical SEO