SSL protocol
What is the SSL protocol? What is SSL/TLS used for?
The SSL protocol, short for secure sockets layer or SSL, was the most widely used encryption protocol to guarantee the security of Internet connections until an improved version appeared in 1999: the TLS protocol (short for transport layer security).
SSL creates a secure channel for communication between two computers or devices, either over the Internet or over a local network. A common example of the use of SSL is in the protection of communications between a web browser and a web server.
The SSL protocol changes the address of the website that has the corresponding SSL certificate from HTTP to HTTPS, where the “S” at the end means: security.
1. How does the SSL protocol work?
In the SSL protocol, both asymmetric and symmetric cryptography are used, in the first case to exchange the keys that, in turn, will be used to generate the information encryption, using a symmetric algorithm.
Let’s look at an example of how the SSL protocol is used together with the HTTP protocol when we connect to a website. The website must have an SSL certificate. It would be like this:
- The visitor makes an HTTPS request from their browser to the website they wish to access. The server where the website is hosted sends the certificate with the public key for the website. If it doesn’t exist, it will display an error.
- The visitor’s browser checks that the certificate is trusted. If this is not the case, it will indicate to the user that it is not a secure site and that they can accept the certificate at their own risk.
- After that, the browser will generate a symmetric cryptographic key, which will be encrypted using the server’s public key and sent to the website’s server.
- After that, the communication between the browser and the web server will be established in a secure way, and the exchange of information will be encrypted in both directions.
2. TLS and HTTPS protocols
The TLS protocol appeared as an update to SSL. It stands for transport layer security and is used for many different tasks besides communicating with HTTPS websites.
TLS improves security and privacy in connections, to prevent data from being intercepted, and offers better speed and performance than SSL.
HTTPS is the acronym for hyper text transfer protocol secure. A website is protected when: it uses an SSL/TLS certificate, symmetric and asymmetric encryption algorithms, and also key exchange, thus correctly using the HTTPS protocol.
Therefore, the HTTPS protocol requires an SSL/TLS certificate. It is the one best known to all kinds of Internet users, since the browser shows a padlock, a symbol of security, next to the domain name when we connect to an HTTPS site.
3. Examples of use of the SSL/TLS protocol
Every day, often without realizing it, we exchange information and connect to multiple web servers countless times. Therefore, the use of SSL/TLS for these tasks is essential to keep our communications safe.
Here are some of the most common examples in which you are surely using the SSL/TLS protocol:
- When opening our email client, since it has to connect to the server to stay up to date.
- When making credit card payments over the Internet or other types of online payments.
- When accessing mail servers through webmail to send and receive email.
- On a company intranet (internal network), when we access databases or share files on it.
- When we transfer files through HTTPS or through FTP.
- In general, whenever we connect to remote applications and control panels or to cloud services.
Related entries
Find out how Mailrelay can help you with your email marketing strategy.