# TLS (Transport Layer Security)

URL: https://softwaredictionary.org/terms/tls
Category: Security
Last updated: 2026-09-30

In short: TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.

## What is TLS?

Transport Layer Security is the standard protocol for creating a secure channel between two programs over an untrusted network such as the internet. It provides confidentiality, so eavesdroppers cannot read the data; integrity, so changes in transit are detected; and authentication, so the client can confirm it is talking to the real server. TLS replaced the older SSL protocol, which is now obsolete, although many people still say SSL out of habit.

Every TLS connection starts with a handshake. The client lists the versions and cipher suites it supports, the server replies with its choice and its certificate, and the client checks that the certificate was signed by a trusted certificate authority and matches the domain name. The two sides then agree on fresh session keys and switch to fast symmetric encryption for the rest of the conversation; TLS 1.3 completes the handshake in a single round trip.

If the internet is a public road, TLS is a sealed, armored van whose driver shows verified ID: observers can see which address the van is heading to, but not what is inside. TLS is not only for websites; it also secures email delivery, database connections, APIs between services, and WebSocket connections over `wss://`.

TLS and HTTPS are often confused. TLS is the security layer, and HTTPS is simply HTTP carried over TLS, just as `wss://` is WebSocket over TLS. To configure it safely, allow only TLS 1.2 and 1.3, disable old protocols and weak ciphers, renew certificates automatically with a service such as Let's Encrypt, and never turn off certificate verification in client code, even to silence an error during development.

## Key takeaways

- TLS encrypts network traffic and verifies the server's identity.
- It replaced SSL, which is obsolete and insecure.
- The handshake checks the certificate and agrees on session keys.
- HTTPS is HTTP over TLS; TLS also secures email, databases, and APIs.
- Allow only TLS 1.2 and 1.3, and never disable certificate verification.

## Example: Making a verified TLS request (Node.js)

```javascript
import https from "node:https";

// Secure by default: Node checks that the certificate is valid,
// signed by a trusted authority, and issued for this hostname
https.get("https://api.example.com/health", (res) => {
  console.log(res.socket.getProtocol()); // e.g. "TLSv1.3"
  console.log(res.statusCode);
});

// Dangerous: disabling verification allows man-in-the-middle attacks
// https.get(url, { rejectUnauthorized: false }); // never ship this
```

## Frequently asked questions

**What is the difference between TLS and SSL?**

SSL is the original secure transport protocol from the 1990s, and all its versions are now broken and disabled in modern software. TLS is its successor, with TLS 1.2 and TLS 1.3 in use today, even though certificates are still often called SSL certificates.

**What is the difference between TLS and HTTPS?**

TLS is a general-purpose security protocol that can protect many kinds of network traffic. HTTPS is one specific use of it: ordinary HTTP messages sent through a TLS-encrypted connection.

**What is mutual TLS?**

In mutual TLS, or mTLS, both sides present certificates, so the server also verifies the client's identity. It is common for service-to-service communication in zero trust networks and for high-security APIs.

## Sources

- [RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3](https://www.rfc-editor.org/rfc/rfc8446.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
