TLS handshake

TLS 핸드셰이크

Client and server agree on cryptographic parameters and a shared secret for a secure channel.

···
html
<div class="n-demo"><div class="n-head"><strong>TLS HANDSHAKE</strong><span>LIVE TRACE</span></div><div class="n-stage"><div class="tls-side n-box">CLIENT</div><div class="tls-wire"><div id="tls-msg" class="n-box mono">ClientHello →</div><div id="tls-lock" class="tls-lock">OPEN CHANNEL</div></div><div class="tls-side n-box">SERVER</div></div><div class="n-foot">tap to step · auto replay</div></div>
css
.n-demo{width:min(94vw,760px);height:min(88vh,324px);padding:clamp(9px,2.2vmin,18px);border:1px solid var(--line);border-radius:13px;background:var(--surface);display:flex;flex-direction:column;gap:clamp(5px,1.3vmin,10px);font:600 clamp(12px,2.4vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;overflow:hidden}.n-head,.n-foot{display:flex;justify-content:space-between;align-items:center;color:var(--muted)}.n-head strong{color:var(--accent)}.n-head span,.n-foot{font-size:12px}.n-stage{flex:1;min-height:0;position:relative;display:flex;align-items:center;justify-content:center;gap:clamp(4px,1vmin,10px)}.mono{font-family:ui-monospace,SFMono-Regular,Consolas,monospace}.n-box{padding:clamp(5px,1.5vmin,11px);border:1px solid var(--line);border-radius:8px;background:var(--bg);text-align:center}.n-on{border-color:var(--accent)!important;color:var(--accent)!important;background:color-mix(in srgb,var(--accent) 12%,var(--surface))!important}.n-muted{color:var(--muted)}@media(max-width:400px){.n-head span{display:none}}.tls-side{width:24%}.tls-wire{width:48%;display:grid;gap:10px}.tls-lock{border:2px dashed var(--line);border-radius:20px;text-align:center;padding:7px;color:var(--muted)}.tls-lock.n-on{border-style:solid}
js
const tlsMessages=['ClientHello →','← ServerHello + cert','derive traffic keys','secure data'];let step=2;function advance(){document.getElementById('tls-msg').textContent=tlsMessages[step];document.getElementById('tls-lock').classList.toggle('n-on',step===3);document.getElementById('tls-lock').textContent=step===3?'PROTECTED CHANNEL':'OPEN CHANNEL';step=(step+1)%4}
const clickTarget=document.querySelector('.n-demo');if(clickTarget&&typeof advance==='function'){advance();const timer=setInterval(advance,1050);clickTarget.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})}

In a TLS handshake, the client advertises supported options and key exchange data; the server replies with its certificate and key exchange data. Both derive matching traffic keys.

The demo switches from handshake messages to protected application data. A failed certificate check must stop the secure connection.

When to use

Use it to separate certificate validation from key exchange when diagnosing HTTPS failures or latency.

Open as page ↗