# HTTPS आणि TLS: port 443

Source: https://ravindrabagale.com/mr/cyber/part-01/ch02-ports-and-protocols-ssh-http-https-ftp-sftp-and/2-4-https-and-tls-basics-port-443.html
Language: mr (Marathi with English technical terms)

HTTPS = HTTP + TLS. TLS मुळे connection मध्ये तीन महत्त्वाच्या गोष्टी मिळतात:

Confidentiality: मार्गातला कोणी data सहज वाचू शकत नाही.

Integrity: data मध्ये छेडछाड झाली तर ती ओळखता येते.

Server authentication: certificate पडताळून आपण अपेक्षित domain शी connect झालो आहोत का ते तपासता येतं.

TLS connection चं सोपं चित्र

 Browser                                              Server
   |  ClientHello  (TLS versions, cipher suites, random) -->|
   |<-- ServerHello + Certificate (public key, signed by CA)|
   |  Browser verifies certificate: name, expiry, CA chain  |
   |  Key exchange (ECDHE) -> both derive the same          |
   |  session key; no key is ever sent in clear             |
   |<========= encrypted HTTP (symmetric, e.g. AES-GCM) ===>|

Browser आपल्याला support असलेले TLS options पाठवतो. Server certificate आणि निवडलेले options देतो. Browser certificate मधलं domain name, expiry आणि trusted CA chain तपासतो. Key exchange मधून दोन्ही बाजूंना session keys मिळतात. मग HTTP data symmetric encryption वापरून पाठवला जातो. Diagram हा शिकण्यासाठीचा simplified flow आहे; TLS version नुसार अचूक message order बदलतो.

महत्त्वाचे शब्द

 | Term
 | अर्थ

 | Certificate
 | Server ची public key + domain identity; CA ची digital signature

 | CA
 | Certificate sign करणारी trusted संस्था (उदा. Let's Encrypt)

 | Symmetric encryption
 | Shared key ने encryption/decryption; वेगवान, प्रत्यक्ष data साठी

 | Asymmetric encryption
 | Public/private key pair; identity व key agreement संबंधित कामासाठी

 | TLS 1.2 / 1.3
 | आधुनिक versions; SSL 2/3 आणि TLS 1.0/1.1 जुने आहेत

Certificate: domain identity आणि public key जोडणारा digitally signed document.

CA (Certificate Authority): certificates sign करणारी trusted संस्था; उदाहरणार्थ Let's Encrypt.

Symmetric encryption: data encrypt/decrypt करण्यासाठी shared key वापरतात. ते वेगवान असल्याने प्रत्यक्ष traffic साठी उपयोगी.

Asymmetric cryptography: public/private key pair वापरून identity/signatures आणि key agreement संबंधित कामं होतात.

TLS 1.2/1.3: आधुनिक configurations मध्ये वापरले जाणारे versions. SSL 2/3 आणि TLS 1.0/1.1 जुने आणि असुरक्षित मानले जातात.

Certificate तपासून पाहा

curl -vI https://example.com 2>&1 | grep -E "SSL|TLS|subject|expire"
openssl s_client -connect example.com:443 -servername example.com </dev/null | head -20

पहिली command TLS/certificate संबंधित output शोधते. दुसरी command server च्या TLS connection आणि certificate ची माहिती दाखवते. -servername ने योग्य hostname पाठवला जातो.

HTTPS म्हणजे application मधले सगळे bugs गेले का?

नाही. HTTPS प्रवासातला data protect करतो; application मधली SQL injection सारखी चूक तो दुरुस्त करत नाही. Expired किंवा अविश्वसनीय self-signed certificate च्या warnings नेहमी ignore करायची सवय लावू नका. पुढे Part 6 मध्ये Certbot वापरून certificate जोडण्याचा भाग आहे.

Practice

वरची openssl s_client command public HTTPS site साठी चालवा. Certificate subject, issuer (CA) आणि TLS version लिहून ठेवा.

रवींद्र बागले यांची tip

Browser मधला lock icon म्हणजे connection protected आहे; website प्रामाणिक आहे याची हमी नाही. Phishing websites सुद्धा HTTPS वापरतात. Domain नीट वाचा—paypa1.com आणि paypal.com वेगवेगळे आहेत.
