Skip to content
⚠️ This article was written in 2020. Some content may be outdated.

HTTPS TLS Handshake Process Explained

When it comes to the HTTPS TLS handshake, many developers only operate at the API-call level. This article tries to look at it from a production-environment perspective, discussing the problems you'll actually run into and how to solve them.

Basic Principles ​

In real projects, the usage gets a bit more involved:

javascript
function setCSP(req, res, next) {
  const nonce = crypto.randomBytes(16).toString('base64')
  res.setHeader('Content-Security-Policy', [
    "default-src 'self'",
    `script-src 'self' 'nonce-${nonce}'`,
    "style-src 'self' 'unsafe-inline'",
    "img-src 'self' data: https:",
    "connect-src 'self' https://api.example.com",
    "frame-ancestors 'none'"
  ].join('; '))
  next()
}

This approach improves both the testability and extensibility of the code.

Advanced Features ​

Here is a complete example:

javascript
function setCSP(req, res, next) {
  const nonce = crypto.randomBytes(16).toString('base64')
  res.setHeader('Content-Security-Policy', [
    "default-src 'self'",
    `script-src 'self' 'nonce-${nonce}'`,
    "style-src 'self' 'unsafe-inline'",
    "img-src 'self' data: https:",
    "connect-src 'self' https://api.example.com",
    "frame-ancestors 'none'"
  ].join('; '))
  next()
}

Pay attention to edge-case handling — it's critical in production.

Project Practice ​

The key is understanding the core logic:

javascript
function setCSP(req, res, next) {
  const nonce = crypto.randomBytes(16).toString('base64')
  res.setHeader('Content-Security-Policy', [
    "default-src 'self'",
    `script-src 'self' 'nonce-${nonce}'`,
    "style-src 'self' 'unsafe-inline'",
    "img-src 'self' data: https:",
    "connect-src 'self' https://api.example.com",
    "frame-ancestors 'none'"
  ].join('; '))
  next()
}

Performance optimization has to be tied to the actual scenario; not every case calls for over-optimizing.

Best Practices ​

Here's how we can improve on it:

javascript
function setCSP(req, res, next) {
  const nonce = crypto.randomBytes(16).toString('base64')
  res.setHeader('Content-Security-Policy', [
    "default-src 'self'",
    `script-src 'self' 'nonce-${nonce}'`,
    "style-src 'self' 'unsafe-inline'",
    "img-src 'self' data: https:",
    "connect-src 'self' https://api.example.com",
    "frame-ancestors 'none'"
  ].join('; '))
  next()
}

This approach has been running stably in production for over half a year, so it's proven in practice.

Summary ​

  • A deep dive into the HTTPS TLS handshake is no silver bullet; choose it based on your project's scale and tech stack.
  • Understanding the underlying principles matters more than memorizing APIs.
  • Before using it in production, make sure to verify compatibility.
  • In team collaboration, conventions and documentation matter more than the technology itself.
  • Keep an eye on community developments; technical solutions need continuous iteration.

MIT Licensed