Tprotocols
TLS
The protocol that encrypts a session and checks the server you reached, so the bytes of a file transfer are not readable on the path.
Version 1.3 is RFC 8446. HTTPS is HTTP inside TLS. FTPS is FTP with TLS on its connections. NIST SP 800-52 is the deployment guide: which versions to allow, and how to check the certificate.
The handshake agrees algorithms and proves the server holds the private key for the name in the certificate. The records after that carry the HTTP or FTP bytes as ciphertext. A certificate for the wrong name, or one signed by a root the client does not trust, fails closed on a strict client. The file is not sent. Clicking through the warning opens an encrypted channel to an unverified host. Encryption held. Authentication did not.
A drop site presents a certificate for `drop.example` from a public root, TLS 1.3. The browser uploads. A second environment uses a private root the guest laptop does not have. The guest sees a warning, the operator installs the root, and the upload proceeds. A third environment still allows TLS 1.0. SP 800-52 tells agencies not to. A client that negotiates 1.0 against a modern browser will fail, and the fix is the server, not the file.
SSL is the retired name. The last SSL versions are obsolete. A product that says SSL and speaks TLS 1.2 is using the old word. A product that still speaks SSL 3.0 is a finding. TLS ends at the terminator. A load balancer that ends TLS sees the file. That is encryption in transit, not encryption at rest, and not zero-knowledge. SFTP does not use TLS. It uses SSH for the same job. Asking a partner to "turn on TLS" on an SFTP port 22 host misunderstands which protocol is on the socket.
Related
Sources
- RFC 8446, The Transport Layer Security Protocol Version 1.3
Handshake, record protection, and server authentication
- NIST SP 800-52 Rev. 2, Guidelines for TLS Implementations
Which versions and checks a deployment should allow