Transport Layer Security (TLS)
The standard cryptographic protocol that provides encryption, integrity and server authentication for data in transit, used by HTTPS and many other protocols; it replaced the older, now-deprecated SSL.
A TLS connection begins with a handshake in which client and server agree on a protocol version and cipher suite, the server proves its identity with an X.509 certificate issued by a trusted certificate authority, and both sides derive shared session keys, typically through ephemeral Diffie-Hellman key exchange that provides forward secrecy. Application data is then protected with authenticated encryption such as AES-GCM or ChaCha20-Poly1305. TLS 1.3, defined in RFC 8446, simplified the handshake and removed legacy algorithms.
TLS secures websites, APIs, email transport, many VPNs and machine-to-machine traffic, including MQTT connections between devices and brokers. Browsers mark sites without HTTPS as not secure, and standards such as PCI DSS require strong cryptography when cardholder data is transmitted over open, public networks. Mutual TLS, in which the client also presents a certificate, authenticates devices and services in zero trust and IoT architectures.
SSL 2.0 and 3.0 are long obsolete, and RFC 8996 formally deprecated TLS 1.0 and 1.1, so servers should offer only TLS 1.2 and 1.3 with strong cipher suites. Common weaknesses include expired or misconfigured certificates, weak ciphers and missing HSTS. Configurations can be checked with scanners and against guidance such as NIST SP 800-52 and Mozilla's server-side TLS recommendations.
Key points
- Encrypts and authenticates data in transit and is the basis of HTTPS.
- TLS 1.3 is defined in RFC 8446; TLS 1.0 and 1.1 are deprecated.
- Certificates from trusted authorities prove server identity.
- Mutual TLS also authenticates clients and devices.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers SSL/TLS among more than 170 checks, with severity ratings and remediation steps in its report.
Related terms
- Public Key Infrastructure (PKI)Cybersecurity & Compliance
- HTTP Strict Transport Security (HSTS)Cybersecurity & Compliance
- Encryption at Rest and in TransitCybersecurity & Compliance
- Cryptographic Key ManagementCybersecurity & Compliance
- MQTTIndustrial IoT & Edge
- HTTP Security HeadersCybersecurity & Compliance