SSL/TLS Deep Dive Cheat Sheet
Explains the TLS handshake, protocol versions, cipher suites, and practical OpenSSL commands for testing and hardening TLS configurations.
Protocol Versions
TLS/SSL version history and current recommendations.
- SSLv2 / SSLv3- Deprecated and insecure; must be disabled
- TLS 1.0 / 1.1- Deprecated (2020/2021); disable in production
- TLS 1.2- Widely supported, secure when configured with strong cipher suites
- TLS 1.3- Current standard; faster handshake (1-RTT), removes weak ciphers, forward secrecy by default
TLS 1.3 Handshake Overview
Simplified sequence of a TLS 1.3 connection setup.
- 1. ClientHello- Client sends supported cipher suites, TLS version, key share
- 2. ServerHello- Server picks cipher suite, sends its certificate and key share
- 3. Key derivation- Both sides derive session keys via (EC)DHE key exchange
- 4. Certificate verification- Client validates the server's certificate chain
- 5. Finished- Both sides confirm handshake integrity; encrypted application data begins
Nginx TLS Hardening Config
Example server block enforcing modern TLS settings.
server { listen 443 ssl; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256; ssl_prefer_server_ciphers off; ssl_session_timeout 1d; ssl_session_cache shared:SSL:10m; add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;}
Testing a TLS Connection (OpenSSL)
Checking supported protocol versions and certificate details.
# Test connection using a specific TLS versionopenssl s_client -connect example.com:443 -tls1_2openssl s_client -connect example.com:443 -tls1_3# Show negotiated cipher and certificate chainopenssl s_client -connect example.com:443 -showcerts </dev/null 2>/dev/null | openssl x509 -noout -dates
Key Security Properties
Concepts that determine the strength of a TLS deployment.
- Forward secrecy- Session keys derived via ephemeral (EC)DHE, so a leaked private key doesn't expose past sessions
- HSTS- Strict-Transport-Security header forces browsers to always use HTTPS for the domain
- SNI- Server Name Indication lets one IP serve multiple TLS certificates by domain
- Cipher suite- Combination of key exchange, authentication, encryption, and MAC algorithms
OCSP Stapling & Mutual TLS (nginx)
Enabling OCSP stapling for faster revocation checks and requiring client certificates for mutual TLS.
server { listen 443 ssl; # OCSP stapling: server fetches and caches the revocation response # so clients don't have to contact the CA themselves ssl_stapling on; ssl_stapling_verify on; ssl_trusted_certificate /etc/ssl/chain.pem; resolver 1.1.1.1 8.8.8.8 valid=300s; # Mutual TLS: require and verify a client certificate ssl_client_certificate /etc/ssl/ca.pem; ssl_verify_client on; ssl_verify_depth 2; location /internal-api/ { # $ssl_client_verify is 'SUCCESS' only when the client cert is valid if ($ssl_client_verify != SUCCESS) { return 403; } proxy_pass http://backend; }}
Verifying Chain of Trust & Certificate Transparency
Confirming a certificate's chain builds to a trusted root and checking Certificate Transparency logs for unexpected issuance.
# Verify the presented chain against the system trust storeopenssl verify -CAfile /etc/ssl/certs/ca-bundle.crt leaf.pem# Pull the full chain a server sends and inspect each cert's subject/issueropenssl s_client -connect example.com:443 -showcerts </dev/null 2>/dev/null \ | awk '/BEGIN/,/END/{print}' > chain.pemopenssl crl2pkcs7 -nocrl -certfile chain.pem | openssl pkcs7 -print_certs -noout# Query Certificate Transparency logs for all certs ever issued for a domain# (catches mis-issuance / shadow certs from a compromised CA)curl -s "https://crt.sh/?q=example.com&output=json" | jq '.[].name_value' | sort -u
TLS 1.3 Session Resumption & 0-RTT Tradeoffs
Performance features of TLS 1.3 that carry non-obvious security implications.
- Session tickets- Encrypted state the client replays to skip a full handshake on reconnect
- 0-RTT (early data)- Client sends application data with the very first flight, before the handshake completes
- Replay risk- 0-RTT data is NOT guaranteed to be delivered only once — an attacker can capture and resend it
- Safe use of 0-RTT- Only allow it for idempotent requests (e.g. GET); never for state-changing POSTs like payments
- Ticket key rotation- Rotate session ticket encryption keys frequently to bound the blast radius of a key leak
- Disabling 0-RTT- ssl_early_data off; (nginx) is the safe default unless the app explicitly handles replay
Enumerating Weak Ciphers & Fingerprinting (nmap)
Scanning a host's negotiable cipher suites and grabbing a JA3-style TLS fingerprint for detection tooling.
# Enumerate every cipher suite the server is willing to negotiate, per protocolnmap --script ssl-enum-ciphers -p 443 example.com# Flag known-weak/deprecated suites explicitlynmap --script ssl-enum-ciphers -p 443 example.com | grep -E 'RC4|3DES|MD5|EXPORT|CBC.*SHA1'# Check for classic protocol-level vulnerabilities (Heartbleed, POODLE, etc.)nmap --script ssl-heartbleed,ssl-poodle,ssl-ccs-injection -p 443 example.com
Advanced TLS Terminology
Concepts that show up once you move past basic handshake mechanics.
- ALPN- Application-Layer Protocol Negotiation; lets client/server agree on HTTP/2 vs HTTP/1.1 during the handshake
- AEAD ciphers- Authenticated Encryption with Associated Data (e.g. AES-GCM, ChaCha20-Poly1305); combines confidentiality and integrity in one primitive
- X25519- Modern elliptic curve used for (EC)DHE key exchange; faster and simpler than NIST P-256
- Certificate pinning- App hardcodes an expected cert/public key hash to reject even a validly-signed but unexpected certificate
- Downgrade protection- TLS 1.3's ServerHello includes a special random value that detects an attacker forcing a fallback to TLS 1.2
- SCT (Signed Certificate Timestamp)- Proof a certificate was logged to a Certificate Transparency log, embedded in the cert or via TLS extension
Use the Qualys SSL Labs test (ssllabs.com/ssltest) after any TLS config change — it catches misconfigurations like incomplete chain, weak ciphers, or missing forward secrecy that a manual review often misses.