YouTube2Text

TLS Handshake - EVERYTHING that happens when you visit an HTTPS website — Transcript

by Practical Networking · 4,610 words · 752 segments · language en · Watch on YouTube

Full transcript

  1. 0:00and that is the entire TLS handshake and
  2. 0:04everything that occurs throughout that
  3. 0:05handshake in order to calculate the keys
  4. 0:07to protect application data
  5. 0:10all right YouTube I'm doing it I'm
  6. 0:13giving away the Keystone Main Attraction
  7. 0:16the Crux of my practical TLS course
  8. 0:19this lesson is the culmination of every
  9. 0:21lesson prior and is what the entire
  10. 0:24course has been gradually building you
  11. 0:25towards now there's a reason I'm doing
  12. 0:28this and that reason will become clear
  13. 0:30to you at the end of this video in the
  14. 0:32meantime get ready for the most complete
  15. 0:34and most thorough explanation of the TLs
  16. 0:36handshake done in the true practical
  17. 0:39networking Style
  18. 0:42foreign
  19. 0:44[Music]
  20. 0:46we finally made it to the lesson that
  21. 0:48this whole course has been building
  22. 0:50towards
  23. 0:51in this lesson we'll be picking apart
  24. 0:53the actual TLS handshake
  25. 0:55this handshake is what will build the
  26. 0:58actual tunnel which will protect bulk
  27. 1:00data transfer between the client and the
  28. 1:02server
  29. 1:03now I want to give you a fair warning
  30. 1:05that this is going to be a rather
  31. 1:06involved lesson
  32. 1:08throughout this course I took particular
  33. 1:10care to break up every idea and concept
  34. 1:13into small bite-sized chunks
  35. 1:15but breaking up the handshake into
  36. 1:17multiple different lessons might detract
  37. 1:19from understanding how it all fits
  38. 1:21together
  39. 1:22so instead I chose to do the entire TLS
  40. 1:25handshake in one longer lesson
  41. 1:28I'd recommend being nice and alert
  42. 1:30before you start and let this be the
  43. 1:32first lesson you watch of the day
  44. 1:34instead of something you watch at the
  45. 1:36end of a series of other lessons
  46. 1:38so grab yourself that cup of coffee do a
  47. 1:41few stretches and let's get to it
  48. 1:43we're going to illustrate the TLs
  49. 1:45handshake on a record by record basis
  50. 1:48recall that records don't necessarily
  51. 1:50correlate to packets meaning sometimes
  52. 1:53multiple records will fit inside a
  53. 1:55single packet and sometimes multiple
  54. 1:57packets will be used to send a single
  55. 1:59record
  56. 2:00we're going to show you the handshake in
  57. 2:02its most basic form meaning a TLS
  58. 2:05handshake using an RSA key exchange
  59. 2:08the lessons that follow in this module
  60. 2:10will show you different variations of
  61. 2:12this basic handshake
  62. 2:13but we're all going to show you how
  63. 2:15those variations are different to the
  64. 2:17handshake we're going to discuss in this
  65. 2:19lesson so make sure you very thoroughly
  66. 2:22understand everything we discuss in this
  67. 2:24video
  68. 2:25that being said it is now time to show
  69. 2:28you the entire TLS handshake that'll
  70. 2:30occur between this client and the server
  71. 2:33throughout this handshake the client and
  72. 2:35the server are going to exchange and
  73. 2:37calculate certain values
  74. 2:39we're going to show you the pieces of
  75. 2:41information that each party has in these
  76. 2:43two boxes
  77. 2:44to begin the server already has a few
  78. 2:47pieces of information
  79. 2:49namely the server has its own
  80. 2:51certificate the server has its own
  81. 2:53public key and the server has its own
  82. 2:55matching private key
  83. 2:57with this as our starting point we can
  84. 3:00now show you everything that occurs in
  85. 3:02the TLs handshake keep in mind
  86. 3:04everything we're about to show you
  87. 3:05occurs every time you visit an https
  88. 3:08website or connect to an SSL VPN
  89. 3:13the first message of the TLs handshake
  90. 3:15is the client hello
  91. 3:17inside the client hello are five
  92. 3:19different fields
  93. 3:21this version number is going to include
  94. 3:23the highest version of SSL that the
  95. 3:25client supports
  96. 3:27meaning if the client supports TLS
  97. 3:29version 1.3 it's going to send in this
  98. 3:32field the hex code
  99. 3:350304 to indicate that it supports TLS
  100. 3:38version 1.3
  101. 3:40this random number is 32 bytes generated
  102. 3:44by the client
  103. 3:45the first four bytes of that is going to
  104. 3:47include the time stamp down to the
  105. 3:49second
  106. 3:50what this does is it makes it impossible
  107. 3:52for two different client hellos sent
  108. 3:55more than a second apart from each other
  109. 3:57to have duplicate random numbers
  110. 4:00then we have the session ID
  111. 4:02the session ID is an 8 byte value used
  112. 4:05to identify this specific session we're
  113. 4:08going to explore the inner workings of
  114. 4:10the session ID when we discuss session
  115. 4:12resumption later in this module for now
  116. 4:14though for this simple version of the
  117. 4:16handshake the client will send a session
  118. 4:18ID of all zeros
  119. 4:20or sometimes the client won't include an
  120. 4:22actual session ID
  121. 4:24this will prompt the server to randomly
  122. 4:26generate a session ID to use as a
  123. 4:28reference for this particular TLS
  124. 4:30session
  125. 4:31which brings us to The Cypher Suites
  126. 4:34we discussed in the last module how the
  127. 4:36cipher seats work
  128. 4:37the client will send a list of ciphers
  129. 4:39that the client supports in the order
  130. 4:42that the client prefers and the server
  131. 4:44will pick from this list
  132. 4:47and finally if any additional extensions
  133. 4:49are going to be included in this
  134. 4:51particular session it would be done in
  135. 4:53the client hello
  136. 4:54for this version of the handshake we
  137. 4:56will proceed with an empty extensions
  138. 4:58field indicating no additional
  139. 5:00extensions are being requested
  140. 5:02but in later lessons in this module
  141. 5:04we'll be showing you various handshake
  142. 5:05extensions and how they will affect this
  143. 5:08core handshake that we're illustrating
  144. 5:09in this lesson
  145. 5:12so those are the five fields in the
  146. 5:15client hello
  147. 5:17upon receiving the client hello the
  148. 5:20server will then respond with the server
  149. 5:22hello and the server hello happens to
  150. 5:25have the exact same five fields
  151. 5:28the version number in the server hello
  152. 5:31will indicate the highest version of a
  153. 5:33cell that the server supports
  154. 5:36this random number is also 32 bytes with
  155. 5:39the time stamp down to the second
  156. 5:40encoded in the first four bytes
  157. 5:43the session ID sent from the server is
  158. 5:46going to be a randomly generated value
  159. 5:48that'll be used to identify the ensuing
  160. 5:50session keys
  161. 5:51this value is purely arbitrary it's
  162. 5:54simply going to be used as a label to
  163. 5:56reference this particular session
  164. 5:59the server will then select a Cipher
  165. 6:01from the list that the client suggested
  166. 6:04and Echo it back to the client in the
  167. 6:06ciphers field of the server hello
  168. 6:09and finally if there are any extensions
  169. 6:11that are going to be included in this
  170. 6:13particular TLS handshake this is where
  171. 6:15the server would provide the necessary
  172. 6:17information back to the client
  173. 6:19and again in this particular
  174. 6:21illustration we're going to exclude all
  175. 6:23the additional extensions that exist
  176. 6:26at the end of the client hello and the
  177. 6:28server Hello both the client and the
  178. 6:30server now have additional pieces of
  179. 6:32information
  180. 6:34both know the highest version of a TLS
  181. 6:36that is mutually supported
  182. 6:38meaning if the client send TLS version
  183. 6:401.3 in its version field and the server
  184. 6:44sent TLS version 1.2 in its version
  185. 6:47field that tells both the client and the
  186. 6:49server that the highest mutually
  187. 6:51supported version of a cell is TLS 1.2
  188. 6:53and both the client and the server will
  189. 6:55continue the negotiation using the TLs
  190. 6:581.2 handshake
  191. 7:00moreover both the client and the server
  192. 7:02are going to know both random numbers
  193. 7:06the client knows the random number it
  194. 7:08generated and sent to the server and it
  195. 7:10knows the random number that it received
  196. 7:12from the server
  197. 7:14in the same way the server knows the
  198. 7:17client number that was sent by the
  199. 7:18client and the server knows its own
  200. 7:21random number that it randomly generated
  201. 7:22so both the client the server know both
  202. 7:25random numbers
  203. 7:28they also both know the session ID that
  204. 7:31will be used to reference this
  205. 7:32particular session in the future
  206. 7:34and finally they both know the mutually
  207. 7:37agreed Cipher Suite that'll be used to
  208. 7:39protect the bulk data transfer in this
  209. 7:41TLS session
  210. 7:43now we'll take a quick pulse check right
  211. 7:45here go ahead and pause real quick for a
  212. 7:48moment and make sure you understand how
  213. 7:50the client and the server have attained
  214. 7:52the mutual pieces of information that
  215. 7:54we've just discussed if you feel good
  216. 7:57about that we can now continue
  217. 8:00next record in the TLs handshake is the
  218. 8:02certificate record sent by the server
  219. 8:05and as you can infer inside the
  220. 8:07certificate record is the server's full
  221. 8:09certificate chain
  222. 8:11to be clear if the server had three
  223. 8:14certificates and its end entity
  224. 8:16certificate it's going to be sending all
  225. 8:18four of them in this message it's not
  226. 8:20going to send four different certificate
  227. 8:22records
  228. 8:24after receiving the certificate and
  229. 8:26certificate chain from the server the
  230. 8:28client is now going to attain two new
  231. 8:30pieces of information
  232. 8:32namely the certificate and of course the
  233. 8:35public key which was contained in that
  234. 8:37certificate
  235. 8:39the next record that will be sent will
  236. 8:41be from the server and is called the
  237. 8:43server hello done
  238. 8:44this is an empty record which simply
  239. 8:47indicates that the server has nothing
  240. 8:48more to send at this time
  241. 8:51there are other variants to the
  242. 8:52handshake in which the server is going
  243. 8:54to send more content in between the
  244. 8:57certificate and server hello done
  245. 8:59but the fact that the server hello done
  246. 9:00is sent right after the certificate is
  247. 9:02an indication that we are not doing
  248. 9:04those other variants
  249. 9:06we'll be looking at some of those other
  250. 9:07variants in the next few lessons of this
  251. 9:09module
  252. 9:11now recall that after receiving the
  253. 9:14certificate from the server the client
  254. 9:16needs to ask itself two questions
  255. 9:19first is is the certificate legitimate
  256. 9:22that'll be validated by verifying the
  257. 9:24signature in the certificate using the
  258. 9:26ca's public key
  259. 9:28and at this point the client has
  260. 9:30everything it needs to validate that
  261. 9:31signature
  262. 9:33the second question that the client is
  263. 9:35going to ask is is the server the true
  264. 9:37owner of the certificate
  265. 9:39that is going to be validated by
  266. 9:40verifying that the server has the
  267. 9:42matching private key
  268. 9:45which will be done using the next record
  269. 9:47that the client sends
  270. 9:49that record is known as the client key
  271. 9:51exchange record and there are two
  272. 9:54primary purposes for the client key
  273. 9:56exchange record
  274. 9:57first is to establish Mutual keying
  275. 10:00material meaning a seed value which both
  276. 10:02the client the server will then use to
  277. 10:04generate session keys
  278. 10:06second purpose of the client key
  279. 10:08exchange is to prove that the server is
  280. 10:11indeed the true owner of this
  281. 10:12certificate
  282. 10:14both of these goals are going to be done
  283. 10:16using a special value known as The
  284. 10:19pre-master Secret
  285. 10:21now notice this value is Illustrated
  286. 10:23with this red dotted line around it
  287. 10:26that's an indication that that
  288. 10:27particular value is sent encrypted
  289. 10:30let me show you how this value works
  290. 10:33the client is going to generate the
  291. 10:35pre-master secret the pre-master secret
  292. 10:38is 48 bytes and is for the most part
  293. 10:41randomly generated except the first two
  294. 10:43bytes are going to include the TLs
  295. 10:45version that is being negotiated in this
  296. 10:47handshake
  297. 10:49the pre-master secret is then going to
  298. 10:51be encrypted with the server's public
  299. 10:53key which the client has because it
  300. 10:56acquired it when the server sent its
  301. 10:58certificate
  302. 11:00the encrypted version of The pre-master
  303. 11:02Secret is what's going to be sent on The
  304. 11:04Wire
  305. 11:05which means the only person that can
  306. 11:07extract the actual pre-master secret
  307. 11:09from the encrypted version that was sent
  308. 11:11on the wire is whomever has the matching
  309. 11:14private key which our server does
  310. 11:17which means the server is able to take
  311. 11:19this and extract the original pre-master
  312. 11:21Secret
  313. 11:23now both parties have the identical
  314. 11:26pre-master Secret
  315. 11:28this pre-master secret will be the seed
  316. 11:30value from which all additional session
  317. 11:32keys for this session will be calculated
  318. 11:36now what we've just described is how RSA
  319. 11:39establishes that seed value there are
  320. 11:41other key exchange protocols that
  321. 11:43establish the seed value a little
  322. 11:45differently and we'll show those to you
  323. 11:46in future lessons in this module
  324. 11:49but for now we're going to continue with
  325. 11:51the very basic handshake which includes
  326. 11:53the RSA key exchange protocol
  327. 11:56with that said I want to show you what
  328. 11:58actually happens to that pre-master
  329. 12:00secret value
  330. 12:01that pre-master secret value will be
  331. 12:04used as the seed value to generate
  332. 12:06session keys for this particular TLS
  333. 12:08session
  334. 12:09let me show you how that's done
  335. 12:11first the pre-master secret is going to
  336. 12:14be used to derive the master Secret
  337. 12:16that's going to be done by taking that
  338. 12:18pre-master secret and combining it with
  339. 12:21a few other values
  340. 12:23those other values are the client random
  341. 12:25number and the server random number
  342. 12:26which were established in the client
  343. 12:28hello and the server hello and the
  344. 12:30literal string Master secret it's
  345. 12:33actually written into the RFC that way
  346. 12:35those four values will be combined to
  347. 12:37create the master Secret
  348. 12:40now notice that both parties have the
  349. 12:42necessary values to calculate this
  350. 12:44master Secret
  351. 12:45both parties have the pre-master secret
  352. 12:48both parties know the string Master
  353. 12:50secret it's public knowledge it's in the
  354. 12:52rfcs and then both parties have the
  355. 12:54client random and the server random
  356. 12:57which means both the client and the
  357. 12:59server are able to put together the
  358. 13:01master Secret
  359. 13:02that Master secret is then going to be
  360. 13:05used to generate session keys and it can
  361. 13:07be done by combining the master secret
  362. 13:09with a few other values
  363. 13:12those values are going to be the literal
  364. 13:14string key expansion
  365. 13:16and then once again the client random
  366. 13:18and server random that were established
  367. 13:20in the client hello and the server hello
  368. 13:22combining these four values would lead
  369. 13:25to the generation of the session keys
  370. 13:27and at minimum four session keys will be
  371. 13:29created
  372. 13:31a symmetric encryption key and an hmac
  373. 13:34key to protect what is sent from the
  374. 13:36client
  375. 13:37and a symmetric encryption key and an
  376. 13:39hmac key to protect what is sent from
  377. 13:41the server
  378. 13:42and again both parties had the master
  379. 13:45secret both parties know the string key
  380. 13:47expansion and both parties have the
  381. 13:49client and server random numbers which
  382. 13:52means both parties have the same
  383. 13:54identical session keys
  384. 13:57now you might be asking yourself why two
  385. 14:00sets of keys well that's a great
  386. 14:01question
  387. 14:03what TLS is actually doing is it's
  388. 14:05creating two separate tunnels
  389. 14:07one to protect all the data sent from
  390. 14:10the client to the server and another to
  391. 14:12protect all the data sent from the
  392. 14:14server back to the client
  393. 14:16in both cases these are symmetric keys
  394. 14:20meaning whatever the client sends will
  395. 14:22be encrypted and protected with these
  396. 14:24keys and the server will use its copy of
  397. 14:27the same keys to decrypt that content
  398. 14:30and in the other direction whatever the
  399. 14:32server sends will be protected by those
  400. 14:34keys and the client will use those same
  401. 14:37identical keys to decrypt and read that
  402. 14:40content
  403. 14:41the benefit of all this is even if the
  404. 14:43client and their server send the exact
  405. 14:46identical duplicate data sets to each
  406. 14:48other
  407. 14:49since they're going to be encrypted with
  408. 14:51different Keys they're going to look
  409. 14:53different on The Wire
  410. 14:55moreover if someone were to do all the
  411. 14:57hard work to brute force one set of keys
  412. 15:00at best they're only going to capture
  413. 15:02and decrypt half of the conversation
  414. 15:04meaning the conversation in Only One
  415. 15:06Direction
  416. 15:07because the conversation in the other
  417. 15:09direction is using an entirely new set
  418. 15:11of keys
  419. 15:13so that is how TLS and SSL will generate
  420. 15:16the session keys to protect the actual
  421. 15:18bulk data transfer
  422. 15:20the main thought there is that TLS is
  423. 15:22essentially building two different
  424. 15:23tunnels one tunnel to protect the data
  425. 15:26transfer in each Direction
  426. 15:29now I'll also mention here that if any
  427. 15:31additional secrets are required this
  428. 15:34same calculation is what's going to
  429. 15:35generate them
  430. 15:37earlier we discussed encryption
  431. 15:39protocols in the cipher Suite module we
  432. 15:41mentioned that certain encryption
  433. 15:42protocols require what's known as an IV
  434. 15:45or an initialization vector well this is
  435. 15:48the step that's actually going to
  436. 15:50calculate any necessary IVs
  437. 15:53of course you might be asking yourself
  438. 15:55now how is this one calculation going to
  439. 15:58generate all the necessary keys and IVs
  440. 16:00that we need for this session
  441. 16:02consider sometimes we're using a 128-bit
  442. 16:05encryption protocol which only needs 128
  443. 16:08bits for each of the encryption keys and
  444. 16:10other times we're using 256-bit
  445. 16:12encryption keys in which case we're
  446. 16:14going to need two sets of symmetric keys
  447. 16:16that are each 256 bits
  448. 16:18well the way it works is that these
  449. 16:20values are combined in what's known as a
  450. 16:23prf or a pseudo-random function
  451. 16:27a pseudo random function is sort of like
  452. 16:29a hashing algorithm but it creates a
  453. 16:31digest of any length you want
  454. 16:34internally a prf includes a hashing
  455. 16:37algorithm that feeds back in on itself
  456. 16:39which means you can run the prf for as
  457. 16:41long as you want to generate as many
  458. 16:43necessary bits as you need for all the
  459. 16:46secrets for this session
  460. 16:47but just like a hashing algorithm the
  461. 16:50only way to get an identical bit stream
  462. 16:52is to have identical starting values
  463. 16:55meaning only Whoever has these four
  464. 16:58values can generate this exact set of
  465. 17:01keys that was generated in this session
  466. 17:05that wraps up all the events that occur
  467. 17:07as a result of sending the client key
  468. 17:10exchange
  469. 17:12so far in the handshake we've discussed
  470. 17:14these five records
  471. 17:17and now is another good time to take a
  472. 17:19quick pulse check go ahead and pause
  473. 17:21right here for a moment and make sure
  474. 17:23you understand how the client and the
  475. 17:25server have attained this most recent
  476. 17:27set of values and in particular how they
  477. 17:29calculated the session Keys which will
  478. 17:31be used to actually protect bulk data
  479. 17:35if you feel good about that then we can
  480. 17:37continue
  481. 17:39at this point in the handshake both the
  482. 17:42client and the server have identical
  483. 17:44session keys
  484. 17:46however at this point neither of them
  485. 17:49know that the other has the correct keys
  486. 17:52the client simply sent the client key
  487. 17:55exchange and then calculated the
  488. 17:56necessary keys but hasn't received
  489. 17:59anything from the server confirming that
  490. 18:01the server has the correct keys
  491. 18:03in the same way the server simply
  492. 18:06received the client key exchange and
  493. 18:08went through these calculations but
  494. 18:10still hasn't received anything from the
  495. 18:11client to prove that the client had the
  496. 18:14right keys
  497. 18:15the purpose of the rest of the records
  498. 18:17in the handshake is to validate that
  499. 18:20each party has the right set of keys
  500. 18:22and that's going to start with the
  501. 18:24client sending the change Cipher spec
  502. 18:27record
  503. 18:28This Record is an indication that the
  504. 18:31client has everything it needs to speak
  505. 18:33securely meaning it was able to
  506. 18:35calculate the session keys
  507. 18:37you can read this record as the client
  508. 18:40saying it is ready to change to the
  509. 18:42cipher that they have specified in the
  510. 18:44client and server hello
  511. 18:46now notice that this record is in Black
  512. 18:49that's there to indicate that this is
  513. 18:51not a handshake record remember that the
  514. 18:53change Cipher spec is another record
  515. 18:55entirely
  516. 18:57following the change Cipher spec the
  517. 18:59client is going to send the finished
  518. 19:01record
  519. 19:02the finished record is a handshake
  520. 19:04record and is going to be used to prove
  521. 19:06to the server that the client has the
  522. 19:09right session keys
  523. 19:11that's going to be done using a special
  524. 19:13value known as the encrypted
  525. 19:15verification let me show you how that is
  526. 19:18constructed
  527. 19:20the client is going to calculate a hash
  528. 19:22of all the handshake records that have
  529. 19:24been seen so far
  530. 19:25so if we pull back down our handshake at
  531. 19:28this point in the negotiation there have
  532. 19:30been five handshake records that have
  533. 19:32been sent so far
  534. 19:33the client hello the server hello the
  535. 19:36certificate the server hello done and
  536. 19:38the client key exchange
  537. 19:40so all the content of all five of those
  538. 19:43handshake records will be hashed
  539. 19:45together and that's going to create what
  540. 19:47I'm going to call a handshake hash
  541. 19:50then that handshake hash is going to be
  542. 19:52combined with a few other values to
  543. 19:55create what I'm going to call
  544. 19:55verification data
  545. 19:57those other values are the literal
  546. 19:59string client finished and the master
  547. 20:02Secret
  548. 20:03those will all be combined in a prf to
  549. 20:06create the verification data
  550. 20:08and finally the verification data will
  551. 20:10then be encrypted with the client
  552. 20:12session keys that's what's going to
  553. 20:15create this encrypted verification which
  554. 20:17was sent on The Wire
  555. 20:19in theory the server saw the exact same
  556. 20:22handshake record so far so the server is
  557. 20:26also able to put together this exact
  558. 20:28same handshake cache
  559. 20:30the server also knows the string client
  560. 20:32finished again it's built into the RFC
  561. 20:34so that's public knowledge and the
  562. 20:37server has the master Secret
  563. 20:39which means the server is able to put
  564. 20:41together the same verification data
  565. 20:44the server will then take what was sent
  566. 20:46on The Wire
  567. 20:47decrypt it with its copy of the client
  568. 20:50session keys and if the result of that
  569. 20:53is identical to the verification data
  570. 20:55that the server put together this tells
  571. 20:57the server that the client definitely
  572. 20:59has the same session keys
  573. 21:03moreover calculating the handshake hash
  574. 21:06from What was seen or sent by the client
  575. 21:08or the server also proves that the
  576. 21:10client and the server saw the same
  577. 21:12handshake records
  578. 21:15if someone had tampered with the client
  579. 21:17hello after the client had sent it and
  580. 21:19before the server had received it this
  581. 21:21verification data on either side of the
  582. 21:23wire would not match
  583. 21:25so using the handshake hash in this way
  584. 21:28proves that no one messed with the
  585. 21:30content that was sent to negotiate this
  586. 21:32particular session
  587. 21:34so that is how the client will prove to
  588. 21:37the server that the client has the
  589. 21:39correct session keys
  590. 21:42so at this point the server knows the
  591. 21:45client has the correct session keys but
  592. 21:47the client still doesn't know that the
  593. 21:49server has the correct session keys
  594. 21:52so this same process will now be done
  595. 21:54but from the other direction the server
  596. 21:57is going to send a change Cipher spec
  597. 21:59record and then the server is going to
  598. 22:01send its finished message which is going
  599. 22:04to include its own encrypted
  600. 22:06verification data
  601. 22:08just like before the change Cipher spec
  602. 22:11record is not a handshake record it's
  603. 22:13simply a record that is there to
  604. 22:15indicate that the server has everything
  605. 22:17it needs to start speaking securely
  606. 22:20and the finished message will be there
  607. 22:22to prove to the client that the server
  608. 22:24has the correct session keys
  609. 22:28this encrypted verification is put
  610. 22:30together in a similar way as to the one
  611. 22:32that the client sent but for the sake of
  612. 22:34thoroughness I'm going to show it to you
  613. 22:36just like when the client did it the
  614. 22:39server is going to calculate a hash of
  615. 22:41all the handshake records that have been
  616. 22:42seen so far if we bring back down our
  617. 22:45TLS handshake
  618. 22:46and count out all the handshake records
  619. 22:49that have been sent we have the client
  620. 22:50hello the server hello the certificate
  621. 22:53the server hello done the client key
  622. 22:55exchange and the client finished
  623. 22:58all the content of those handshake
  624. 23:00records will be combined in a hashing
  625. 23:02algorithm and the result of that will be
  626. 23:05a handshake hash and once again as long
  627. 23:08as both the client and the server saw or
  628. 23:10sent the same records both the client
  629. 23:13and the server will be able to put
  630. 23:14together the identical handshake hash
  631. 23:17that handshake hash is then combined
  632. 23:19with other values to create the
  633. 23:21verification data those other values are
  634. 23:24the literal string server finished and
  635. 23:27the master Secret
  636. 23:28which both the server and the client
  637. 23:30have which means both the client and the
  638. 23:33server are able to put together at The
  639. 23:34Identical verification data
  640. 23:37that verification data is then going to
  641. 23:39be encrypted by the server using the
  642. 23:41server encryption keys and then sent on
  643. 23:44The Wire
  644. 23:45the client will then take what was sent
  645. 23:47by the server decrypt it with its copies
  646. 23:50of the server session keys and verify
  647. 23:53that it matches what the client
  648. 23:55calculated as the verification data
  649. 23:58that will prove to the client that the
  650. 24:00server has the exact same set of keys
  651. 24:03that the client expected
  652. 24:07so at the end of the server finished
  653. 24:09message the client has the necessary
  654. 24:12proof that the server has the right
  655. 24:14session keys
  656. 24:17which means at this point in the
  657. 24:20handshake both the client and the server
  658. 24:22have calculated the correct session keys
  659. 24:24and have proven to each other that they
  660. 24:26have the correct session Keys which
  661. 24:28means there's nothing further to do and
  662. 24:31the handshake and they can now start
  663. 24:33sharing bulk data with each other
  664. 24:35protecting that data with the session
  665. 24:37keys that they have negotiated
  666. 24:40and that is the entire TLS handshake and
  667. 24:44everything that occurs throughout that
  668. 24:46handshake in order to calculate the keys
  669. 24:48to protect application data
  670. 24:51if you've made it this far then you
  671. 24:53should give yourself a round of applause
  672. 24:55because we just covered a lot of
  673. 24:58information
  674. 24:59I would highly recommend watching this
  675. 25:02video again to make sure it all sinks in
  676. 25:05remember this TLS handshake that we just
  677. 25:07discussed occurs every single time you
  678. 25:09browse to an https website or every time
  679. 25:12you connect to an SSL VPN
  680. 25:15in the remaining lessons of this module
  681. 25:17we're going to look at variations to the
  682. 25:19handshake we just discussed
  683. 25:21these variations are going to include
  684. 25:23different key exchange protocols
  685. 25:24different features or different
  686. 25:26extensions
  687. 25:27but understanding the core handshake
  688. 25:29that we just Illustrated is crucial
  689. 25:32because when we show you the variations
  690. 25:34we're only going to show you how they
  691. 25:36are different
  692. 25:37so again I would highly recommend giving
  693. 25:39this video a watch one more time to make
  694. 25:42sure it all syncs in before you start
  695. 25:44watching the other lessons in this
  696. 25:46module
  697. 25:47moreover before you get to the other
  698. 25:49lessons there's also a lab that you're
  699. 25:51going to have to complete which goes
  700. 25:53with this particular lesson in your next
  701. 25:55Lab you're going to be inspecting a TLS
  702. 25:58handshake in Wireshark you'll get to see
  703. 26:00and pick apart each of the records we
  704. 26:02discussed in a real live capture of a
  705. 26:04TLS session
  706. 26:06there will also be some questions for
  707. 26:08you to answer to help guide your
  708. 26:09exploration of the TLs handshake
  709. 26:12so you have that to look forward to
  710. 26:15I hope you enjoyed that lesson it's the
  711. 26:17culmination of what every lesson prior
  712. 26:19in the course was building towards if as
  713. 26:21you're going through that there was any
  714. 26:22part of it that left you asking other
  715. 26:24questions I guarantee you that there's
  716. 26:26probably another lesson earlier in the
  717. 26:28course that spoke to your question
  718. 26:29exactly what you just saw was the
  719. 26:31handshake or TLS versions 1.2 and prior
  720. 26:35TLS 1.3 came out a few years ago and is
  721. 26:38slowly building traction on the internet
  722. 26:39TLS 1.3 is a major departure to how we
  723. 26:42did Internet Security before
  724. 26:44plus it's going to be used everywhere
  725. 26:46not only with just browsing the web but
  726. 26:48also in quick the new layer 4 Protocol
  727. 26:50so wherever you work in the internet
  728. 26:52ecosystem you will definitely come
  729. 26:54across TLS 1.3
  730. 26:56all the illustrations and all the
  731. 26:58details we just saw in the TLs 1.2
  732. 27:00handshake I'm going to do again with the
  733. 27:02TLs 1.3 hand check and to motivate
  734. 27:05myself to finish I'm going to Discount a
  735. 27:07practical TLS course to the lowest price
  736. 27:09I've ever offered until I finish the TLs
  737. 27:121.3 module purchasing the course now
  738. 27:14will give you instant access to
  739. 27:16everything already published and all the
  740. 27:18TLs 3.3 content that I'm currently
  741. 27:20creating as we speak so if there's any
  742. 27:22part of you or your job responsibilities
  743. 27:24that require in-depth knowledge of TLS
  744. 27:26this is an absolute must buy course for
  745. 27:29you
  746. 27:30but don't wait too long because as soon
  747. 27:31as I finish the TLs 1.3 content the
  748. 27:34course is going back to its full price
  749. 27:36I hope you got a lot out of this video I
  750. 27:38look forward to seeing you in the
  751. 27:40Practical TLS course
  752. 27:54[Music]

About this transcript

This page contains the full transcript of TLS Handshake - EVERYTHING that happens when you visit an HTTPS website by Practical Networking, generated from the public captions YouTube serves with the video. The transcript has 4,610 words across 752 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.