Catégorie
TLS et transport
Tous les outils et articles de cette catégorie, rassemblés au même endroit.
Outils
Articles
Anatomie d'une suite de chiffrement TLS
Ce qu'une suite de chiffrement TLS nomme réellement, comment lire une suite comme TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 morceau par morceau, et comment le même point de code de deux octets apparaît sous trois conventions de noms différentes.
LireLire les noms de suites de chiffrement : IANA, OpenSSL et GnuTLS
Pourquoi la même suite de chiffrement a trois noms différents et un point de code de deux octets, comment traduire entre les conventions de l'IANA, d'OpenSSL et de GnuTLS, et ce que la colonne Recommended de l'IANA, avec Y, N et D, signifie réellement.
LireAEAD contre CBC : pourquoi le mode compte
La différence pratique entre un chiffrement AEAD comme AES-GCM et un ancien chiffrement CBC avec un HMAC distinct, les attaques par oracle de remplissage qui ont eu raison du MAC-then-encrypt, et le seul compromis que l'AEAD demande encore.
LireLa confidentialité persistante et l'échange de clés
Ce qu'apporte la confidentialité persistante, pourquoi le transport de clé RSA statique ne la fournit pas, comment ECDHE et DHE le font, et pourquoi l'authentification et l'échange de clés sont deux tâches distinctes que le nom d'une suite garde séparées.
LireSuites de chiffrement TLS 1.3 : ce qui a changé
Pourquoi une suite TLS 1.3 ne nomme qu'un chiffrement et un hachage, où sont passés l'échange de clés et l'authentification, et pourquoi la liste des suites est passée de centaines à une poignée.
LireWhat a Quantum Computer Would Break, and What It Would Not
A large quantum computer would not weaken all cryptography equally. Shor's algorithm breaks the public-key math behind RSA, Diffie-Hellman, and elliptic curves outright; Grover's algorithm only halves the strength of symmetric ciphers and hashes, which AES-256 and SHA-384 already survive. This explains the split, why 'harvest now, decrypt later' makes it a today problem, and why a broken candidate like SIKE is a reminder to stay humble.
LireThe NIST Post-Quantum Standards: ML-KEM, ML-DSA, and SLH-DSA
In August 2024 NIST finalized the first three post-quantum standards: FIPS 203 (ML-KEM, from Kyber) for key establishment, and FIPS 204 (ML-DSA, from Dilithium) and FIPS 205 (SLH-DSA, from SPHINCS+) for signatures. This explains what each one is for, why there are two signature standards on different math, and where HQC and FN-DSA fit as the backups still coming down the pipeline.
LireHybrid Key Exchange in TLS 1.3: What X25519MLKEM768 Does on the Wire
The web did not swap classical key exchange for post-quantum; it runs both at once. X25519MLKEM768 combines a 1990s elliptic curve with lattice-based ML-KEM-768 in a single TLS 1.3 group, so a break of either still leaves the session secure. This covers why hybrid rather than replacement, the wire format and its size problem, and where deployment stands across browsers, servers, and the middleboxes it breaks.
LireInbound TLS: Offload, Bridging, and Passthrough at the Reverse Proxy
A reverse proxy handling inbound HTTPS has three choices for the TLS session: terminate it and send plaintext to the backend (offload), terminate and re-encrypt to the backend (bridging), or forward the encrypted bytes untouched (passthrough). Each trades visibility against confidentiality and cost differently. This explains all three, why the proxy holds the server's certificate, and what SNI and mutual TLS change.
LireTLS 1.2 vs TLS 1.3 vs DTLS vs QUIC: One Handshake Family, Four Shapes
TLS 1.2 and TLS 1.3 secure a TCP stream, DTLS carries the same guarantees over datagrams, and QUIC absorbs the TLS 1.3 handshake into the transport itself. What each one is, which RFC defines it today, what actually changed between them, and where each one runs.
LireWhat Is a JA4 TLS Fingerprint?
How a TLS ClientHello becomes a stable fingerprint of the client software, why JA3 faded once browsers began randomizing extension order, how JA4 fixes that by sorting before hashing, and what JA4 can and cannot tell you.
LireWhy Do We Say SSL When We Mean TLS?
SSL has been prohibited, deprecated, and dead for years - and the industry still sells 'SSL certificates,' configures 'SSL inspection,' and links openssl. The history explains the habit: Netscape's SSL, the political rename to TLS in 1999 (the wire version field still said 3.1), and a quarter century of marketing inertia. Plus the musing the question deserves: what would a protocol-independent name even look like, and do any exist?
Lire