What is tls handshake
Last updated: April 1, 2026
Key Facts
- The TLS handshake authenticates the server's identity through a digital certificate signed by a trusted certificate authority
- TLS 1.2 handshakes typically require 2 round-trips of communication between client and server
- TLS 1.3 reduced the handshake to 1 round-trip in most scenarios, improving connection speed by approximately 25%
- During the handshake, the client and server agree on a shared encryption key used for all subsequent data transmission
- The handshake prevents man-in-the-middle attacks and ensures only authorized parties can establish and decrypt the connection
What is the TLS Handshake?
The TLS handshake is the initial negotiation process between a client and a server that establishes a secure connection before any data is transmitted. It's a critical security mechanism that authenticates the server (and optionally the client), agrees on encryption methods, and generates the shared secret key that encrypts all subsequent communications. Without the handshake, secure communication would be impossible—it's the foundation of all HTTPS connections, secure emails, and encrypted communications across the internet.
The TLS 1.2 Handshake Process
The TLS 1.2 handshake typically involves the following steps:
- ClientHello - The client sends a message listing supported TLS versions, cipher suites, and other parameters
- ServerHello - The server responds by selecting a TLS version and cipher suite from the client's options
- Certificate - The server sends its digital certificate to prove its identity
- Key Exchange - The client and server exchange information to establish a shared secret key
- Finished - Both parties send a verification message confirming the handshake is complete
This process typically requires two round-trips of communication between the client and server, adding latency to connection establishment.
The TLS 1.3 Handshake
TLS 1.3 streamlined this process significantly. The main improvements include reducing the handshake to just one round-trip in typical scenarios. The client can now send its key share in the initial ClientHello message, and the server can immediately respond with its selection and key share. This enables the "0-RTT" (zero round-trip time) feature in specific cases, where clients can send encrypted data even before the handshake is fully complete. These changes make TLS 1.3 approximately 25% faster than TLS 1.2 for connection establishment.
Certificate Verification
During the handshake, the server presents a digital certificate to authenticate its identity. The client verifies this certificate by checking that it was signed by a trusted certificate authority (CA). This verification ensures the client is communicating with the legitimate server and not an imposter. Certificate authorities maintain hierarchies of trust, allowing clients to verify any certificate by tracing it back to a root certificate authority they already trust. Public key cryptography enables this authentication mechanism—the CA's private key signs the certificate, and anyone can verify it with the CA's public key.
Security Implications
The TLS handshake is essential for preventing man-in-the-middle attacks, where an attacker intercepts communications between two parties. By verifying the server's certificate, clients can ensure they're communicating with the genuine server. The key exchange during the handshake establishes a shared secret that only the client and server know, making it impossible for eavesdroppers to decrypt subsequent communications. The handshake also provides forward secrecy in modern implementations, meaning that compromising a server's long-term private key doesn't compromise past sessions encrypted with session-specific keys generated during the handshake.
Related Questions
Why does the TLS handshake take multiple round-trips?
TLS 1.2 requires multiple round-trips because the client and server need to exchange multiple messages to authenticate each other, negotiate security parameters, and establish a shared key. TLS 1.3 optimized this by allowing key exchange information in the initial messages.
What happens if the TLS handshake fails?
If the handshake fails—typically due to certificate verification issues, unsupported cipher suites, or version mismatches—the connection is not established. The browser displays a security warning, and no data is transmitted. This protection prevents insecure connections.
How long does a TLS handshake take?
A typical TLS 1.2 handshake takes 100-300 milliseconds depending on network latency and server response time. TLS 1.3 reduces this to 50-150 milliseconds. For subsequent connections, session resumption can reduce handshake overhead significantly.
More What Is in Daily Life
- What is ambienAmbien is a prescription sedative medication containing zolpidem, used to treat insomnia by helping …
- What is amortizationAmortization is the process of paying off a loan through regular installment payments over a fixed p…
- What is amishThe Amish are a Christian religious group known for their plain lifestyle, limited use of modern tec…
- What is apathyApathy is a psychological state characterized by a lack of emotion, motivation, interest, or concern…
- What is aptApt is an adjective meaning appropriate, suitable, or having a natural tendency to do something. In …
- What is american pie aboutAmerican Pie is a 1999 teen comedy film about four high school friends who make a pact to lose their…
- What is amazon haulAmazon Haul is a mobile shopping app by Amazon offering discounted products, typically under $20 per…
- What is amnesiaAmnesia is a medical condition involving partial or complete loss of memory. It can result from brai…
- What is aortaThe aorta is the largest artery in the human body that carries oxygenated blood from the left ventri…
- What is aoAO is an acronym with multiple meanings depending on context, most commonly referring to the AO Foun…
- What is aorAOR stands for Album-Oriented Radio, a radio format that emphasizes playing complete album tracks an…
- What is aot oadsAttack on Titan OADs are original anime DVD/Blu-ray episodes released as bonus content exclusive to …
- What is aoe damageAOE damage stands for Area of Effect damage, a game mechanic where a single attack or ability damage…
- What is anemiaAnemia is a condition where your blood lacks enough healthy red blood cells or hemoglobin to carry a…
- What is an argAn ARG (Alternate Reality Game) is an interactive fiction experience that blurs the boundary between…
- What is an iedAn IED (Improvised Explosive Device) is a homemade bomb made from conventional or commercial explosi…
- What is an adverbAn adverb is a word that modifies a verb, adjective, or another adverb, describing how, when, where,…
- What is anti aliasingAnti-aliasing is a technique used in computer graphics to smooth jagged edges that appear on curved …
- What is ao3AO3 is Archive of Our Own, a non-profit fan fiction archive and community website. It allows users t…
- What is aosAOS can refer to several things: Age of Sigmar (a tabletop wargame), Armor of Ships (military vessel…
Also in Daily Life
- How To Save Money
- What does awol mean
- What does asl mean
- What does ad mean
- What does asap mean
- What does apex mean
- What does asmr stand for
- What does atp mean
- What causes autism
- What does abg mean
- Is it safe to abort at 2 months
- Is it safe to apply for citizenship now
- Is it safe to accept zelle for facebook marketplace
- Is it safe to apply vaseline on face
- Is it safe to accept venmo for facebook marketplace
More "What Is" Questions
Trending on WhatAnswer
Browse by Topic
Browse by Question Type
Sources
- Wikipedia - Transport Layer Security CC-BY-SA-4.0
- IETF RFC 8446 - TLS 1.3 Specification IETF
- Cloudflare - TLS 1.3 Overview CC-BY-4.0