Skip to content
lesson Data security and encryption Intermediate 3 min read

What is TLS?

TLS is the protocol that secures a connection between two computers. What it promises, how the handshake works, and which versions to allow.

Transport Layer Security (TLS) is the standard way for two computers to set up a private connection across a network that neither of them controls. It stops a web page, an email being delivered or an app’s traffic from being read or changed on the way.

What TLS promises

The TLS standard describes its goal as a secure channel between two parties, with three properties:

  • Authentication: you know who is at the other end. The server always proves its identity, and the client can be asked to as well.
  • Confidentiality: only the two ends can see the data.
  • Integrity: the data cannot be altered on the way without being noticed.

How a connection starts

Every TLS connection begins with a short exchange called the handshake. The Australian Signals Directorate (ASD) gives a simplified version:

  1. The two sides agree on a version of TLS and a set of algorithms.
  2. The server sends its certificate, and proves it holds the matching private key by signing a message.
  3. The client checks the certificate: the name matches the server it asked for, the dates are current, it has not been revoked, and it was issued by an authority the client trusts.
  4. The two sides establish a shared key for the session.

From then on, everything sent in either direction is encrypted with that shared key and checked for tampering. The person using the device sees none of this unless a check fails.

Where it is used

Web browsing is the best known use, under the name HTTPS. Mail servers use TLS to protect email as it passes from one to the next. Microsoft 365 uses it for files, email and Teams messages while they are moving.

TLS protects the connection and stops there. The data is decrypted at each end, so the server you sent it to can read it, and what happens to it afterwards depends on how that server stores it.

Versions, and the name SSL

TLS grew out of an older protocol called Secure Sockets Layer (SSL), and people still say “SSL” out of habit. SSL itself should no longer be used at all, and TLS 1.0 and 1.1 should be switched off. ASD’s Information Security Manual says to use only the latest version, TLS 1.3. The UK’s National Cyber Security Centre also accepts TLS 1.2 where it is still needed and carefully configured.

What to ask

  • Which TLS versions do our website, mail server and remote access accept? The old ones should be off.
  • Are the certificates renewed automatically?
  • When were the settings last reviewed? ASD suggests every year, and whenever a serious flaw is made public.

A TLS connection fails its checks if the certificate behind it has expired. The free domain and certificate expiry check shows when yours runs out. For the servers and firewalls that handle these connections, see firewall and network security.

Sources

  1. RFC 9846: The Transport Layer Security (TLS) protocol version 1.3 (IETF) rfc-editor.org
  2. Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au
  3. Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au
  4. Using TLS to protect data (UK National Cyber Security Centre) ncsc.gov.uk
  5. Glossary: Transport Layer Security (NIST Computer Security Resource Center) csrc.nist.gov
  6. Encryption in Microsoft 365 (Microsoft Learn) learn.microsoft.com

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.