Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Web Server » SSL Encrypted Communications explained
  • exchange 2016 1
    How to Block Change Password for Specific Exchange Users Network | Monitoring
  • Cluster 1
    Quarantine state in Windows Failover Clusters: How to resolve quarantined Cluster Node on Hyper-V Virtualization
  • windows10
    How to Install and configure Active Directory Certificate Services Windows Server
  • office configuration analyzer tool offcat
    Office Configuration Analyser Tool (OFFCAT): Now Microsoft Support and Recovery Wizard Microsoft Exchange/Office/365
  • Add User to Sudoers
    Add a User to the Sudoers List in Linux Linux
  • maxresdefault
    How to stop Microsoft Edge from remembering your email ID Windows
  • telnet
    Could not open a connection to the host, on the port, connect failed Windows Server
  • qAS
    How to disable the Microsoft Deployment Toolkit Task Sequence property sheet Windows Server

SSL Encrypted Communications explained

Posted on 13/08/201921/09/2023 Christian By Christian No Comments on SSL Encrypted Communications explained
SSL

SSL certificates Type of certificate which allows multiple domains to be secured with one SSL certificate. SSL Stands for secure sockets layer. Protocol for web browsers and servers that allows for the authentication, encryption, and decryption of data sent over the Internet. See the following interesting guides on how to import a certificate into the Trusted Root and Personal file certificate store, how to request a certificate signing request in Windows using Microsoft Management Console, and how to export a certificate in PFX format in Windows.

Transport Layer Security, and its now-deprecated predecessor, Secure Sockets Layer, are cryptographic protocols designed to provide communications security over a computer network. 

I’m going to highlight only the important steps for HTTPS communication.

  • A client contacts the server.
  • The client and server exchange information about the communications they intend to perform, such as the ciphers to use (SSL handshake).
  • The server transmits its certificate to the client.
    Note: It depends on the protocol used here as the server only can send its certificate etc.
  • The client checks that it trusts the certification authority that issued the certificate. If it does not recognize the CA and does not get an override, the communication ends.
  • The client checks for revocation information on the certificate. If the certificate is revoked or revocation information is unavailable, then the client might attempt to obtain an override. Implementations vary on how they deal with null or unreachable CRL information, but almost all will refuse to communicate with any entity using a revoked certificate.
  • The client generates a portion of a temporary key for symmetric encryption.
  • The client uses the server’s public key to encrypt the partial temporary key.
  • The client sends the encrypted partial key to the server.
  • The server decrypts the partial key using its own private key.
  • The server completes the secret key.
  • The client and server agree to use the secret key. All communications in the same conversation are encrypted with that key.

Note:

Furthermore, It would be possible to use asymmetric encryption for the entire conversation. However, as we discussed earlier, asymmetric encryption results in ciphertext that greatly exceeds the size of the unencrypted source. SSL only uses asymmetric encryption to solve that problem without exposing a plaintext key while the client and server establish identity and work together to create a symmetric shared key. From that point forward, they only use symmetric encryption. That keeps the size of transmitted data to a minimum. Even better, if an attacker manages to break any point of the transmission besides the initial negotiation, they will only gain a temporary key.

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Web Server Tags:Cert, Certificate Authority, Certificate Templates, Certificates, SSL

Post navigation

Previous Post: Pleasant User Group Permission and User Access
Next Post: Components needed to create a certificate signing request

Related Posts

  • Remote Desktop 2 1
    How to install RDS via Quick Start Deployment: Install, Publish, Update, and Uninstall Remote Desktop Web Client Web Server
  • FEATURE ZABBIX
    How to Install Zabbix Monitoring Tool on a Linux System Linux
  • http to https redirection
    URL Rewrite: How to redirect from HTTP to HTTPS Web Server
  • kerberosdelegation
    Kerberos Delegation: A Comprehensive Guide Web Server
  • BitLocker result virtualization
    Create a web page to visualize the output of BitLocker Recovery Web Server
  • Wordpress banner
    Fix WordPress Error “The Link You Followed Has Expired” Web Server

More Related Articles

Remote Desktop 2 1 How to install RDS via Quick Start Deployment: Install, Publish, Update, and Uninstall Remote Desktop Web Client Web Server
FEATURE ZABBIX How to Install Zabbix Monitoring Tool on a Linux System Linux
http to https redirection URL Rewrite: How to redirect from HTTP to HTTPS Web Server
kerberosdelegation Kerberos Delegation: A Comprehensive Guide Web Server
BitLocker result virtualization Create a web page to visualize the output of BitLocker Recovery Web Server
Wordpress banner Fix WordPress Error “The Link You Followed Has Expired” Web Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • exchange 2016 1
    How to Block Change Password for Specific Exchange Users Network | Monitoring
  • Cluster 1
    Quarantine state in Windows Failover Clusters: How to resolve quarantined Cluster Node on Hyper-V Virtualization
  • windows10
    How to Install and configure Active Directory Certificate Services Windows Server
  • office configuration analyzer tool offcat
    Office Configuration Analyser Tool (OFFCAT): Now Microsoft Support and Recovery Wizard Microsoft Exchange/Office/365
  • Add User to Sudoers
    Add a User to the Sudoers List in Linux Linux
  • maxresdefault
    How to stop Microsoft Edge from remembering your email ID Windows
  • telnet
    Could not open a connection to the host, on the port, connect failed Windows Server
  • qAS
    How to disable the Microsoft Deployment Toolkit Task Sequence property sheet Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.