field notes

crypto · networking · defense

The TLS 1.3 handshake in one page

· 1 min read

AbstractTLS 1.3 cut the handshake to a single round trip and dropped every legacy cipher that caused trouble. These are the parts worth remembering.

Contents

Context

TLS 1.3 (RFC 8446) is a cleanup release. It removes static RSA key exchange, renegotiation, compression and the weak ciphers, and it folds the key exchange into the first flight so the client can send application data after one round trip.

The flight

  1. ClientHello — the client sends its supported groups and a key share for the group it guesses the server will pick.
  2. ServerHello — the server picks the group, sends its own key share, and from that point everything is encrypted.
  3. Finished — both sides confirm the transcript hash matches.

If the client guesses the group wrong, the server answers with a HelloRetryRequest and you pay a second round trip.

Things to check in a review

  • Is 0-RTT enabled? Early data is replayable, so it must only carry idempotent requests.
  • Are old versions disabled? Leaving TLS 1.0/1.1 on reintroduces the downgrade surface 1.3 was meant to kill.
  • Is the certificate chain complete and the OCSP staple fresh?

Reference

  • RFC 8446, sections 2 and 4.