TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.3 ISC2 CISSP 4.3 Cisco CCST Cybersecurity 1.4 ISC2 CISSP 3.6 NIST 800-53 SC-8 ISC2 CC 4.1
InteractiveSecurityFree

TLS 1.2, TLS 1.3 or Both?

Is it the TLS 1.2 handshake, the TLS 1.3 handshake, or true of both? Sort each card.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Both handshakes pick up after TCP has made its connection. In TLS 1.2 the client sends a client hello; the server answers with a server hello, its certificate, a server key exchange and a server hello done; the client sends a client key exchange, a change cipher spec and a finished; the server sends its own change cipher spec and finished. Only then can data flow, and encryption only begins with the finished messages. That is why you can open a TLS 1.2 certificate in Wireshark. TLS 1.3 sets out to talk less and encrypt sooner. The client puts a Diffie-Hellman key share into its very first message, and the server returns its own in the server hello. Where the two sides set up a pre-shared key in advance, the hello names it but never sends the key itself, and usually adds a Diffie-Hellman share as well. From the two shares both sides derive the same symmetric keys, so every handshake message after the server hello is encrypted, the certificate included, and data flows after fewer messages. RFC 8446 describes the handshake in three phases: key exchange, server parameters, authentication. Some things do not change. The client hello lists the cipher suites the client supports and the server hello names the one chosen. The server proves who it is with its site certificate and an intermediate certificate, checked up to a root certificate on the client's machine; client authentication is optional. And in both versions the data is encrypted with symmetric session keys, never with the server's public key.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
CompTIA SecurityX
2.3 Given a scenario, implement appropriate cryptographic protocols and algorithms.
ISC2 CISSP
4.3 Implement secure communication channels according to design
3.6 Select and determine cryptographic solutions
Cisco CCST Cybersecurity
1.4 Explain encryption methods and applications
NIST 800-53
SC-8 Transmission Confidentiality and Integrity
ISC2 CC
4.1 Understand network security

Key terms

TLS Handshake Protocol
A sub-protocol of TLS responsible for authentication, key exchange, and negotiating cryptographic parameters before secure communication begins.
Transport Layer Security
TLS
A cryptographic protocol that provides secure communication over a network, successor to SSL.
Key Exchange
A method used to securely share cryptographic keys between parties over an insecure channel.
Diffie-Hellman
A key exchange algorithm that allows two parties to independently generate a shared secret over an insecure channel using two private keys, two public keys, and a shared value, without ever transmitting the secret itself.
Pre-Shared Key
PSK
A shared secret passphrase used for authentication in wireless networks and VPNs without requiring a dedicated authentication server. In WPA-Personal mode, the PSK is used to derive the Pairwise Master Key (PMK) for encrypting the wireless session.
Cipher Suite
A preconfigured set of algorithms specifying the symmetric cipher, key length, mode of operation, hashing algorithm, and key exchange method used to secure TLS communication.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Intermediate Certificate
A certificate issued by a root CA that passes trust down to end-entity certificates, adding a layer of security by keeping the root CA offline.
Root Certificate
The self-signed certificate at the top of a PKI hierarchy that serves as the ultimate anchor of trust for all subordinate certificates.
Session Key
A temporary symmetric key generated for a single communication session, used to encrypt the bulk of data exchanged between two parties.
TCP Three-Way Handshake
The process by which two devices establish a TCP connection using three steps: SYN, SYN-ACK, and ACK.
Wireshark
Wireshark is an open-source network protocol analyzer that captures and interactively displays packet-level traffic, used by security professionals for network forensics, vulnerability research, and incident investigation.

Topics

Tls Handshake Protocol Transport Layer Security Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →