About this interactive
Not every device can do the same cryptography. There are different ciphers, key lengths and modes of encryption, different hashing algorithms and different ways to exchange keys. A cipher suite is a preconfigured set of those options, so two devices can agree on one name instead of every parameter separately.
The name lists the parts in order. Take TLS_DHE_RSA_WITH_AES_256_GCM_SHA384. DHE is the key exchange (Diffie-Hellman; ECDHE is the elliptic-curve version). RSA is the authentication (ECDSA is another). After WITH comes the symmetric cipher that encrypts the session, AES, then its key length, 256 bits, then its mode, GCM (CBC is an older one). Last is the hashing algorithm, SHA384, which is SHA-384. Where a name has only one method before WITH, as in TLS_RSA_WITH_AES_128_CBC_SHA, RSA does the key exchange and the authentication.
The traffic itself is always encrypted with the symmetric cipher, because asymmetric encryption is too slow and resource-intensive for the bulk of the data. RSA in a suite name is not what encrypts your page.
The client sends the list of suites it supports, the server matches it against its own and picks the best one both can use, and tells the client. Suites are dropped as weaknesses are found: TLS 1.3 does not support Triple DES at all. TLS 1.3 names are also shorter, such as TLS_AES_256_GCM_SHA384, because the key exchange and authentication are no longer part of the suite.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →