Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

HTTPS आणि TLS: port 443

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

HTTPS = HTTP + TLS. TLS मुळे connection मध्ये तीन महत्त्वाच्या गोष्टी मिळतात:

TLS connection चं सोपं चित्र

 Browser                                              Server
   |  ClientHello  (TLS versions, cipher suites, random) -->|
   |<-- ServerHello + Certificate (public key, signed by CA)|
   |  Browser verifies certificate: name, expiry, CA chain  |
   |  Key exchange (ECDHE) -> both derive the same          |
   |  session key; no key is ever sent in clear             |
   |<========= encrypted HTTP (symmetric, e.g. AES-GCM) ===>|

Browser आपल्याला support असलेले TLS options पाठवतो. Server certificate आणि निवडलेले options देतो. Browser certificate मधलं domain name, expiry आणि trusted CA chain तपासतो. Key exchange मधून दोन्ही बाजूंना session keys मिळतात. मग HTTP data symmetric encryption वापरून पाठवला जातो. Diagram हा शिकण्यासाठीचा simplified flow आहे; TLS version नुसार अचूक message order बदलतो.

महत्त्वाचे शब्द

Term अर्थ
Certificate Server ची public key + domain identity; CA ची digital signature
CA Certificate sign करणारी trusted संस्था (उदा. Let's Encrypt)
Symmetric encryption Shared key ने encryption/decryption; वेगवान, प्रत्यक्ष data साठी
Asymmetric encryption Public/private key pair; identity व key agreement संबंधित कामासाठी
TLS 1.2 / 1.3 आधुनिक versions; SSL 2/3 आणि TLS 1.0/1.1 जुने आहेत

Certificate तपासून पाहा

curl -vI https://example.com 2>&1 | grep -E "SSL|TLS|subject|expire"
openssl s_client -connect example.com:443 -servername example.com </dev/null | head -20

पहिली command TLS/certificate संबंधित output शोधते. दुसरी command server च्या TLS connection आणि certificate ची माहिती दाखवते. -servername ने योग्य hostname पाठवला जातो.

HTTPS म्हणजे application मधले सगळे bugs गेले का?

नाही. HTTPS प्रवासातला data protect करतो; application मधली SQL injection सारखी चूक तो दुरुस्त करत नाही. Expired किंवा अविश्वसनीय self-signed certificate च्या warnings नेहमी ignore करायची सवय लावू नका. पुढे Part 6 मध्ये Certbot वापरून certificate जोडण्याचा भाग आहे.

Practice

वरची openssl s_client command public HTTPS site साठी चालवा. Certificate subject, issuer (CA) आणि TLS version लिहून ठेवा.