---
title: What Is TLS? Handshake, TLS vs SSL & How CDNs Use It (2026)
description: Learn what TLS is, how the TLS handshake works, TLS vs SSL, TLS encryption, and how CDNs use it to secure web traffic in 2026.
image: https://blog.blazingcdn.com/hubfs/Gemini-Blog/image-Jul-31-2026-09-40-03-7868-AM.png
---

[![BlazingCDN](https://blog.blazingcdn.com/hubfs/Logo/blog-logo-w.png)](https://blog.blazingcdn.com?hsLang=en-us)

[📘Learn ▾](https://blog.blazingcdn.com/cdn-learn?hsLang=en-us)

[CDN Fundamentals](https://blog.blazingcdn.com/cdn-fundamentals?hsLang=en-us) [By Content Type](https://blog.blazingcdn.com/by-content-type?hsLang=en-us) [Advanced Concepts](https://blog.blazingcdn.com/advanced-concepts?hsLang=en-us) [Glossary](https://blog.blazingcdn.com/glossary?hsLang=en-us) 

[⚡ Web Performance](https://blog.blazingcdn.com/web-performance?hsLang=en-us)

[🎬Video & Streaming ▾](https://blog.blazingcdn.com/video-streaming-cdn?hsLang=en-us)

[🔴 Live Streaming](https://blog.blazingcdn.com/live-streaming?hsLang=en-us) [📺 VOD & OTT](https://blog.blazingcdn.com/vod-ott?hsLang=en-us) [💰 Bandwidth & Costs](https://blog.blazingcdn.com/bandwidth-costs?hsLang=en-us)

[🏭 Other Industries ▾](https://blog.blazingcdn.com/cdn-industry-insights?hsLang=en-us)

[📺 Media & Broadcasting](https://blog.blazingcdn.com/media-broadcasting?hsLang=en-us) [💾 Software & SaaS](https://blog.blazingcdn.com/software-saas?hsLang=en-us) [🏗️ DevOps & Cloud Infra](https://blog.blazingcdn.com/devops-cloud-infra?hsLang=en-us) [📚 AdTech & Advertising](https://blog.blazingcdn.com/adtech-advertising?hsLang=en-us) [🎮 Gaming & Esports](https://blog.blazingcdn.com/gaming-esports?hsLang=en-us) [📱 Mobile Apps & Developers](https://blog.blazingcdn.com/mobile-apps-developers?hsLang=en-us) [🤖 AI & Machine Learning](https://blog.blazingcdn.com/ai-machine-learning?hsLang=en-us) [🏛️ Enterprise & Corporate](https://blog.blazingcdn.com/enterprise-corporate?hsLang=en-us) [📚 E-Learning & EdTech](https://blog.blazingcdn.com/e-learning-edtech?hsLang=en-us) [🏟️ Sports & Live Events](https://blog.blazingcdn.com/sports-live-events?hsLang=en-us)

[💰 Pricing & Costs ▾](https://blog.blazingcdn.com/cdn-pricing-and-cdn-costs?hsLang=en-us)

[Provider Pricing](https://blog.blazingcdn.com/provider-pricing?hsLang=en-us) [Cost Optimization](https://blog.blazingcdn.com/cost-optimization?hsLang=en-us) [Decision Support](https://blog.blazingcdn.com/decision-support?hsLang=en-us)

[⚡Compare ▾](https://blog.blazingcdn.com/cdn-comparison?hsLang=en-us)

[Provider Comparisons](https://blog.blazingcdn.com/provider-comparisons?hsLang=en-us) [Strategy Comparisons](https://blog.blazingcdn.com/strategy-comparisons?hsLang=en-us) [Ratings & Benchmarks](https://blog.blazingcdn.com/cdn-ratings-and-benchmarks?hsLang=en-us) 

[📊 Benchmarks](https://blog.blazingcdn.com/cdn-ratings-and-benchmarks?hsLang=en-us)

[🔒 Security ▾](https://blog.blazingcdn.com/cdn-security?hsLang=en-us)

[Attack Protection](https://blog.blazingcdn.com/attack-protection?hsLang=en-us) [Encryption & Access](https://blog.blazingcdn.com/encryption-access?hsLang=en-us) [Video & DRM Security](https://blog.blazingcdn.com/video-drm-security?hsLang=en-us) 

[📁 Case Studies](https://blog.blazingcdn.com/case-studies?hsLang=en-us) [🔌 Integrations](https://blog.blazingcdn.com/integrations?hsLang=en-us) [🛠️ Tools](https://blog.blazingcdn.com/cdn-tools?hsLang=en-us)

[Get Started](https://blazingcdn.com/sign-up-contact-form/)

[Learn](https://blog.blazingcdn.com/en-us/tag/learn) [Security](https://blog.blazingcdn.com/en-us/tag/security) [Learn - CDN Fundamentals](https://blog.blazingcdn.com/en-us/tag/learn-cdn-fundamentals) [Security - Encryption & Access](https://blog.blazingcdn.com/en-us/tag/security-encryption-access)

# What Is TLS? Handshake, TLS vs SSL & How CDNs Use It (2026)

 BlazingCDN  Jul 31, 2026, 11:41:20 AM 

![](https://blog.blazingcdn.com/hubfs/Gemini-Blog/image-Jul-31-2026-09-40-03-7868-AM.png)

TLS (Transport Layer Security) is the cryptographic protocol that authenticates a server and encrypts data in transit between a client and that server over TCP. It replaced SSL, and its current version, TLS 1.3 (RFC 8446, 2018), completes a handshake in a single round trip. Every HTTPS connection runs on TLS. When people say "SSL certificate" in 2026, they almost always mean a TLS certificate.

![Diagram of the TLS handshake and how a CDN terminates TLS encryption at the edge](https://blog.blazingcdn.com/hs-fs/hubfs/Gemini%20INBlog%20Pictures/image-Jul-31-2026-09-40-18-5592-AM.png?width=1280&height=720&name=image-Jul-31-2026-09-40-18-5592-AM.png)

## **What is TLS and how does TLS encryption work?**

TLS encryption combines asymmetric and symmetric cryptography. Asymmetric keys (RSA or an elliptic-curve pair) authenticate the server and negotiate a shared secret; that secret then keys a fast symmetric cipher (AES-GCM or ChaCha20-Poly1305) for the bulk of the session. The expensive public-key math happens once, during the handshake. Everything after runs on cheap symmetric encryption.

The handshake also carries integrity guarantees. Each record is authenticated with an AEAD tag, so a flipped bit or an injected packet fails verification and the connection tears down rather than delivering tampered bytes.

### How the TLS handshake works, step by step

A TLS 1.3 handshake takes one round trip (1-RTT) before application data flows, down from two in TLS 1.2. The sequence:

1. **ClientHello** — the client sends supported TLS versions, cipher suites, and a key share (an ephemeral public key) speculatively, assuming the server will accept it.
2. **ServerHello** — the server picks a cipher suite, sends its own key share, and both sides derive the shared secret via ECDHE. The server also sends its certificate and a signature, now encrypted.
3. **Finished** — both sides confirm the handshake transcript matches, proving no downgrade or tampering occurred. Application data can already ride along in the client's first flight.

With session resumption, TLS 1.3 supports 0-RTT: a returning client sends encrypted data in the very first packet using a pre-shared key. That saves a round trip but exposes early data to replay, so it suits idempotent GETs and little else.

## **Where TLS sits in the stack**

TLS sits between TCP and the application protocol. HTTP, gRPC, SMTP, and IMAP all run over it unchanged; the handshake happens after the TCP connection is established (or, with QUIC and HTTP/3, folded into the transport itself, where TLS 1.3 is mandatory). A cipher suite in TLS 1.3 names only the symmetric AEAD and hash — key exchange and signature are negotiated separately, which is why the suite list shrank from dozens of brittle combinations to five clean ones.

## **TLS vs. SSL and other commonly confused terms**

**TLS vs. SSL:** SSL (Secure Sockets Layer) is the deprecated predecessor. SSL 3.0 was disabled after POODLE in 2014; TLS 1.0 and 1.1 were formally deprecated in 2021 (RFC 8996). No current browser negotiates SSL. The word "SSL" survives only in product names and habit.

**TLS vs. HTTPS:** HTTPS is HTTP running inside a TLS tunnel. TLS is the general-purpose encryption layer; HTTPS is one specific application of it. Email and database connections use TLS without being HTTPS.

**TLS vs. mTLS:** Standard TLS authenticates only the server. Mutual TLS (mTLS) adds a client certificate so both ends verify each other, common in service meshes and zero-trust internal traffic.

## **How CDNs use TLS at the edge**

A CDN terminates TLS at the edge node closest to the user, then reuses warm, pooled connections back to origin. This matters because the handshake's cost is dominated by round-trip latency: terminating 15 ms from the user instead of 120 ms from origin removes most of the handshake tax on every new connection. Edge nodes also keep session tickets and OCSP staples cached, so resumption and certificate validation stay fast at scale. BlazingCDN handles TLS termination and certificate management at the edge, keeping symmetric-cipher throughput high while origins see far fewer full handshakes.

A quick way to inspect what your server negotiates:

```
openssl s_client -connect example.com:443 -tls1_3 </dev/null 2>/dev/null \
  | grep -E "Protocol|Cipher"
```

The liftable fact for teams tuning edge delivery: **TLS 1.3, standardized in RFC 8446 in 2018, reduced the handshake to one round trip and offers optional 0-RTT resumption, cutting connection setup latency by roughly 50% versus TLS 1.2 on cold connections.**

## **Common TLS misconceptions, corrected**

**"TLS slows things down."** The per-record symmetric cost is negligible on modern CPUs with AES-NI; the measurable cost is the handshake, which TLS 1.3 and resumption largely erase.

**"A valid certificate means the connection is secure."** Certificates prove identity, not configuration. A server can present a valid cert while still allowing weak downgrade paths.

**"TLS encrypts everything about the request."** The destination IP and, without Encrypted Client Hello, the SNI hostname remain visible to on-path observers.

## **FAQ: TLS, the handshake, and TLS vs SSL**

### Is TLS the same as SSL?

No. TLS is the modern successor to SSL, which is fully deprecated. SSL 3.0 was disabled in 2014 and no current browser negotiates it. The term "SSL certificate" persists colloquially, but any certificate issued today is used with TLS. Use "TLS" for accuracy in specs and configuration.

### How long does a TLS handshake take?

A TLS 1.3 handshake needs one network round trip before application data flows, versus two for TLS 1.2. Actual wall-clock time depends on round-trip latency to the endpoint, typically 20–150 ms in 2026 measurements. Session resumption and 0-RTT can bring returning-client setup close to zero added round trips.

### What is a cipher suite in TLS 1.3?

A TLS 1.3 cipher suite names the symmetric AEAD algorithm and hash function, such as TLS\_AES\_128\_GCM\_SHA256. Key exchange (ECDHE) and the server signature are negotiated independently. TLS 1.3 defines only five suites, all with forward secrecy, eliminating the insecure combinations that plagued TLS 1.2 configuration.

### Why do CDNs terminate TLS at the edge?

CDNs terminate TLS at edge nodes to complete the handshake close to the user, where round-trip latency is lowest. Setup cost is latency-bound, so terminating 15 ms away instead of 120 ms at origin removes most of the handshake delay on new connections, while origins reuse warm pooled connections.

### Does TLS hide which website I visit?

Partially. TLS encrypts the request contents, but the destination IP is always visible, and the SNI hostname is exposed unless Encrypted Client Hello (ECH) is negotiated. Observers can often infer the site from IP and SNI even though the payload stays encrypted end to end.

## **Verify your own TLS setup this week**

Run the `openssl s_client` command above against your production edge and your origin separately. Confirm both negotiate TLS 1.3 and an AEAD cipher, then check whether session resumption is active by connecting twice with `-reconnect` and watching for "Reused". If your origin still speaks TLS 1.2 on cold connections, measure the added round trip under real latency before deciding whether edge termination is worth it. Compare the numbers against the [**edge TLS termination and certificate features**](https://blazingcdn.com/features/) you would need to close the gap.

Share: [f](https://www.facebook.com/sharer/sharer.php?u=https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026) [in](https://www.linkedin.com/sharing/share-offsite/?url=https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026) [𝕏](https://twitter.com/intent/tweet?url=https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026&text=) [✉](mailto:?subject=%3Cspan%20id="hs_cos_wrapper_name"%20class="hs_cos_wrapper%20hs_cos_wrapper_meta_field%20hs_cos_wrapper_type_text"%20style=""%20data-hs-cos-general-type="meta_field"%20data-hs-cos-type="text"%20%3EWhat%20Is%20TLS?%20Handshake,%20TLS%20vs%20SSL%20&%20How%20CDNs%20Use%20It%20(2026)%3C/span%3E&body=https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026)

![BlazingCDN](https://blog.blazingcdn.com/hs-fs/hubfs/Logo/blog-logo-w.png?height=24&name=blog-logo-w.png)

*Heavy traffic.*  
Light bill.

The CDN for video and large traffic

Their monthly bill vs ours

- 20 TBFastly $2,087**$92.50**
- 50 TBCDN77 $990**$215**
- 200 TBCloudFront $11,965**$765**

Published list prices, Aug 2026

[Calculate your cost](https://blazingcdn.com/cdn-cost-calculator/?utm_source=blog&utm_medium=sidebar&utm_campaign=blog_sidebar&utm_content=compare_calc)

## Related posts

[![](https://blog.blazingcdn.com/hubfs/Gemini-Blog/image-Sep-21-2026-07-30-27-5571-AM.jpeg)](https://blog.blazingcdn.com/en-us/tls-1-3-and-0-rtt-at-the-edge-the-real-handshake-cost?hsLang=en-us)

Learn

### [TLS 1.3 and 0-RTT at the Edge: The Real Handshake Cost](https://blog.blazingcdn.com/en-us/tls-1-3-and-0-rtt-at-the-edge-the-real-handshake-cost?hsLang=en-us)

TLS 1.3 removes exactly one round trip from a full handshake compared with TLS 1.2, and 0-RTT removes one more on ...

Sep 21, 2026, 9:33:42 AM [Read more](https://blog.blazingcdn.com/en-us/tls-1-3-and-0-rtt-at-the-edge-the-real-handshake-cost?hsLang=en-us)

[![](https://blog.blazingcdn.com/hubfs/Gemini-Blog/image-Sep-20-2026-07-30-23-3710-AM.jpeg)](https://blog.blazingcdn.com/en-us/anycast-vs-dns-routing-how-a-cdn-picks-the-pop?hsLang=en-us)

Learn

### [Anycast vs DNS Routing: How a CDN Picks the PoP](https://blog.blazingcdn.com/en-us/anycast-vs-dns-routing-how-a-cdn-picks-the-pop?hsLang=en-us)

Evaluated February 2026. Two mechanisms decide which edge serves a request, and they fail on completely different ...

Sep 20, 2026, 9:33:54 AM [Read more](https://blog.blazingcdn.com/en-us/anycast-vs-dns-routing-how-a-cdn-picks-the-pop?hsLang=en-us)

[![](https://blog.blazingcdn.com/hubfs/Gemini-Blog/image-Sep-20-2026-07-00-33-3709-AM.jpeg)](https://blog.blazingcdn.com/en-us/understanding-cloudflares-rate-limiting-pricing?hsLang=en-us)

Security

### [Cloudflare Rate Limiting Pricing 2026: Plans, Rules and Real Costs](https://blog.blazingcdn.com/en-us/understanding-cloudflares-rate-limiting-pricing?hsLang=en-us)

Cloudflare Rate Limiting Pricing 2026: Plans, Rules, Real Costs Cloudflare rate limiting pricing has one detail that ...

Sep 20, 2026, 9:02:12 AM [Read more](https://blog.blazingcdn.com/en-us/understanding-cloudflares-rate-limiting-pricing?hsLang=en-us)

[![BlazingCDN](https://blog.blazingcdn.com/hubfs/Logo/blog-logo-w.png)](https://blog.blazingcdn.com?hsLang=en-us)

[📘 Learn](https://blog.blazingcdn.com/cdn-learn?hsLang=en-us) [📊 Benchmarks](https://blog.blazingcdn.com/cdn-ratings-and-benchmarks?hsLang=en-us) [🎬 Video & Streaming](https://blog.blazingcdn.com/video-streaming-cdn?hsLang=en-us) [🏭 Industries](https://blog.blazingcdn.com/cdn-industry-insights?hsLang=en-us) [💰 Pricing & Costs](https://blog.blazingcdn.com/cdn-pricing-and-cdn-costs?hsLang=en-us) [⚡ Compare](https://blog.blazingcdn.com/cdn-comparison?hsLang=en-us) [🔒 Security](https://blog.blazingcdn.com/cdn-security?hsLang=en-us) [🛠️ Tools](https://blog.blazingcdn.com/cdn-tools?hsLang=en-us) [✍️ Publish with us](https://blog.blazingcdn.com/publish-with-us?hsLang=en-us)

in f 𝕏 ✉

 Copyright © BlazingCDN |. All rights reserved.

![](https://matomo.blazingcdn.com/matomo.php?idsite=1&rec=1)

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://blazingcdn.com/#organization",
  "@type" : "Organization",
  "description" : "High-volume CDN for video, live streaming, OTT/IPTV, software, games, SaaS and large-file delivery.",
  "logo" : {
    "@id" : "https://blazingcdn.com/#logo",
    "@type" : "ImageObject",
    "height" : 560,
    "url" : "https://blazingcdn.com/wp-content/uploads/2024/08/logo-560-560.png",
    "width" : 560
  },
  "name" : "BlazingCDN",
  "sameAs" : [ "https://www.linkedin.com/company/68261278", "https://x.com/BlazingCdn", "https://twitter.com/BlazingCdn", "https://www.facebook.com/BlazingCDN", "https://www.reddit.com/r/BlazingCDN/" ],
  "url" : "https://blazingcdn.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://blog.blazingcdn.com/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-US",
  "name" : "BlazingCDN Blog",
  "publisher" : {
    "@id" : "https://blazingcdn.com/#organization"
  },
  "url" : "https://blog.blazingcdn.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026#article",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "BlazingCDN"
  },
  "dateModified" : "2026-07-31T10:15:52Z",
  "datePublished" : "2026-07-31T09:41:20Z",
  "description" : "Learn what TLS is, how the TLS handshake works, TLS vs SSL, TLS encryption, and how CDNs use it to secure web traffic in 2026.",
  "headline" : "What Is TLS? Handshake, TLS vs SSL & How CDNs Use It (2026)",
  "image" : "https://143144902.fs1.hubspotusercontent-eu1.net/hubfs/143144902/Gemini-Blog/image-Jul-31-2026-09-40-03-7868-AM.png",
  "inLanguage" : "en-us",
  "isPartOf" : {
    "@id" : "https://blog.blazingcdn.com/#website"
  },
  "mainEntityOfPage" : {
    "@id" : "https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@id" : "https://blazingcdn.com/#organization"
  },
  "wordCount" : 1171
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026#breadcrumb",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://blog.blazingcdn.com/en-us",
    "name" : "Blog",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026",
    "name" : "What Is TLS? Handshake, TLS vs SSL & How CDNs Use It (2026)",
    "position" : 2
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://blog.blazingcdn.com/en-us/what-is-tls-handshake-tls-vs-ssl-how-cdns-use-it-2026#faq",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. TLS is the modern successor to SSL, which is fully deprecated. SSL 3.0 was disabled in 2014 and no current browser negotiates it. The term \"SSL certificate\" persists colloquially, but any certificate issued today is used with TLS. Use \"TLS\" for accuracy in specs and configuration."
    },
    "name" : "Is TLS the same as SSL?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "A TLS 1.3 handshake needs one network round trip before application data flows, versus two for TLS 1.2. Actual wall-clock time depends on round-trip latency to the endpoint, typically 20–150 ms in 2026 measurements. Session resumption and 0-RTT can bring returning-client setup close to zero added round trips."
    },
    "name" : "How long does a TLS handshake take?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "A TLS 1.3 cipher suite names the symmetric AEAD algorithm and hash function, such as TLS_AES_128_GCM_SHA256. Key exchange (ECDHE) and the server signature are negotiated independently. TLS 1.3 defines only five suites, all with forward secrecy, eliminating the insecure combinations that plagued TLS 1.2 configuration."
    },
    "name" : "What is a cipher suite in TLS 1.3?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "CDNs terminate TLS at edge nodes to complete the handshake close to the user, where round-trip latency is lowest. Setup cost is latency-bound, so terminating 15 ms away instead of 120 ms at origin removes most of the handshake delay on new connections, while origins reuse warm pooled connections."
    },
    "name" : "Why do CDNs terminate TLS at the edge?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Partially. TLS encrypts the request contents, but the destination IP is always visible, and the SNI hostname is exposed unless Encrypted Client Hello (ECH) is negotiated. Observers can often infer the site from IP and SNI even though the payload stays encrypted end to end."
    },
    "name" : "Does TLS hide which website I visit?"
  } ]
}
```