In a TLS handshake, the client advertises supported options and key exchange data; the server replies with its certificate and key exchange data. Both derive matching traffic keys.
The demo switches from handshake messages to protected application data. A failed certificate check must stop the secure connection.
When to use
Use it to separate certificate validation from key exchange when diagnosing HTTPS failures or latency.