Side by side
SSLvsTLS
What is the difference between SSL and TLS?
Updated 3 min read7 differences
In short
SSL is the old, insecure predecessor of TLS and survives only as a name; every so-called SSL connection today really uses TLS 1.2 or 1.3.
SSL
Secure Sockets Layer
SSL is the deprecated predecessor of TLS for encrypting connections; every version is insecure and prohibited, and today's "SSL" connections actually use TLS.
Read the page on SSLTLS
Transport Layer Security
TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
Read the page on TLSSSL and TLS compared
| Aspect | SSL | TLS |
|---|---|---|
| Status | Deprecated and prohibited; no version is safe | The current standard; versions 1.2 and 1.3 are in use |
| Created by | Netscape, in the mid-1990s | The IETF, from 1999 on |
| Versions | 2.0 (1995) and 3.0 (1996) | 1.0 and 1.1 (retired), 1.2 and 1.3 (current) |
| Security | Broken by attacks such as POODLE | Secure when limited to 1.2 and 1.3 with strong ciphers |
| Handshake | Several round trips, with old and weak algorithms | TLS 1.3: one round trip, with modern ciphers only |
| Where the name lives on | "SSL certificates", OpenSSL, settings such as sslmode | Protocol version settings, standards and security reports |
| What to do today | Disable it everywhere | Allow only TLS 1.2 and 1.3, and renew certificates automatically |
The difference, explained
SSL and TLS are not two competing protocols but two generations of the same one. Netscape created SSL, Secure Sockets Layer, in the mid-1990s to encrypt connections between browsers and web servers, releasing SSL 2.0 in 1995 and SSL 3.0 in 1996. In 1999 the IETF standardized the next version under a new name, Transport Layer Security, so TLS 1.0 was essentially SSL 3.1. TLS has since gone through versions 1.1, 1.2 and 1.3.
Every SSL version is broken and prohibited: SSL 2.0 was banned in 2011, and SSL 3.0 was deprecated in 2015 after the POODLE attack showed that secrets such as cookies could be recovered from its traffic. Even TLS 1.0 and 1.1 were retired in 2021, so a modern server allows only TLS 1.2 and 1.3. TLS 1.3 also removed old, weak options and completes its handshake in a single round trip.
The old name stuck anyway. Certificates are still sold as "SSL certificates", but they are X.509 certificates that work with any TLS version, and tools keep the name for compatibility, such as the OpenSSL library, nginx's ssl_certificate setting and PostgreSQL's sslmode. So when a dashboard says "enable SSL" or a library has an ssl option, it almost always means TLS.
A common misconception is that SSL and TLS are alternatives to choose between, or that the certificate decides which protocol is used. The certificate only proves the server's identity; the server's protocol settings decide how the connection is encrypted. The practical rule is simple: say SSL where people expect the word, configure TLS 1.2 and 1.3, and treat any scan that finds SSLv2 or SSLv3 enabled as a real weakness.
Which one should you use?
Choose SSL when…
- You mean the name, not the protocol: "SSL certificate" is still the familiar term when buying or explaining one.
- A setting is named after it, such as
sslmodeorssl_certificate; behind it, the connection still uses TLS. - You read older code or documentation, where SSL simply means an encrypted connection, never the old protocol itself.
Choose TLS when…
- You configure a server, load balancer or client: allow only TLS 1.2 and 1.3.
- You write security requirements, audits or documentation that must be precise.
- You secure databases, email or APIs between services; they all use TLS too.
- You pick libraries and settings: prefer TLS 1.3 and keep certificate verification on.
Readers ask
Is an SSL certificate different from a TLS certificate?
No. Both are the same X.509 certificates; "SSL certificate" is just the older name, and the certificate works with whichever TLS version the server and client agree on.
Should I disable SSL on my server?
Yes: SSLv2 and SSLv3 should be off everywhere, and so should TLS 1.0 and 1.1. Leave only TLS 1.2 and 1.3 enabled, which all modern clients support.
Does HTTPS use SSL or TLS?
Today, HTTPS is HTTP carried over TLS. Early HTTPS used SSL, which is why the two names are still mixed up.