Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requested
Last timeSomebody Vouching
The complete exchange, in order, with each message traced back to the lesson it came from. Then the cost in round trips, and the two mechanisms that get it down to one or zero.
The exchange in order
Nothing new is introduced in this lesson. Key agreement came from the second,
encryption from the third, the identity problem from the fourth, and
certificates from the fifth. What remains is the order, and the order is short.
| step | direction | what is sent | the job it serves | lesson | what happened |
|---|---|---|---|---|---|
| 1 | client to server | versions, ciphers, a key share | key agreement | agreeing a secret in public | Also carries the name of the site being asked for, which is the one field an observer can still read if the extension that encrypts it is not in use. |
| 2 | server to client | a key share | key agreement | agreeing a secret in public | With this, both sides compute the same secret from values that were all sent in the clear. Everything following is encrypted. |
| 3 | server to client | certificate chain | identity | somebody vouching | Encrypted, so it is no longer visible to a watcher. The chain is validated against the roots already on the machine. |
| 4 | server to client | a signature over the transcript | binding identity to this conversation | who you are talking to | Proves possession of the private key in the certificate, and proves it about this conversation rather than any other. |
| 5 | both ways | finished messages | integrity of the handshake | encrypting the bytes | A value computed over the whole transcript with the derived keys. Any tampering anywhere in the handshake shows up here. |
| 6 | client to server | the actual request | the point of all this | from an address to a page | One round trip after the first message left. The request itself is the sixth thing sent and the first thing anybody wanted. |
What each message buys
The useful discipline is to take each message away and ask what breaks. Three
of them are load bearing in ways that are easy to miss.
| no shared secret at all | no idea who answered | an old recording can be | |
|---|---|---|---|
| the two key shares | 1 | 0 | 0 |
| the certificate | 0 | 1 | 0 |
| the signature over the t | 0 | 1 | 1 |
| the finished messages | 0 | 0 | 1 |
The signature deserves the extra sentence. It is computed over every byte of
the handshake up to that point, which includes the client key share, which the
client chose at random moments ago. An attacker replaying a recorded signature
would be replaying it over a different transcript, and the check fails. The
freshness comes free from the thing that was already there for key agreement.
The lesson stops here
3 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents