TLS stands for Transport Layer Security, the protocol that encrypts a network connection and lets the client verify who it is talking to. The current version is TLS 1.3. It first appeared as RFC 8446 in August 2018 and is now specified by RFC 9846 (July 2026), which also obsoletes RFC 5246, the TLS 1.2 document. Versions 1.0 and 1.1 were formally deprecated by RFC 8996 in March 2021. HTTPS is HTTP carried over TLS, and WebSocket connections use it too through the wss scheme.
A TLS connection starts with a handshake that agrees on a version and a cipher suite, authenticates the server with a certificate, and derives shared session keys. After that, application data travels in encrypted records.
In TLS 1.3 the client sends a ClientHello that includes a key_share and a supported_versions extension. The server answers with a ServerHello, and everything after that is encrypted: EncryptedExtensions, Certificate, CertificateVerify and Finished. The client replies with its own Finished and can send application data. That is one round trip before data flows.
TLS 1.2 needs a second round trip. With an ECDHE suite, the server sends ServerHello, Certificate, ServerKeyExchange and ServerHelloDone. The client sends ClientKeyExchange, ChangeCipherSpec and Finished, and the server answers with ChangeCipherSpec and its own Finished.
A cipher suite names the algorithms in use:
The commands below connect to a local openssl s_server with a self-signed certificate and show the version and cipher each handshake chose, then the TLS 1.3 handshake message order. The awk filter keeps only the direction and the message name from the -msg trace.
$ openssl s_client -connect localhost:4433 -CAfile c.pem -tls1_3 </dev/null 2>/dev/null | grep "^New,"
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
$ openssl s_client -connect localhost:4433 -CAfile c.pem -tls1_2 </dev/null 2>/dev/null | grep "^New,"
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384
$ openssl s_client -connect localhost:4433 -CAfile c.pem -tls1_3 -msg </dev/null 2>/dev/null | awk '/Handshake/ {print $1, $NF}'
>>> ClientHello
<<< ServerHello
<<< EncryptedExtensions
<<< Certificate
<<< CertificateVerify
<<< Finished
>>> Finished
Only TLS 1.2 and TLS 1.3 should be negotiated. RFC 8996 says implementations must not negotiate TLS 1.0 or TLS 1.1, and it moved both specifications to Historic status. It cites the lack of AEAD cipher suites, which arrived only in TLS 1.2, and handshake integrity that depends on SHA-1. TLS 1.0 also lacks a per-record initialization vector for CBC suites.
openssl ciphers -stdname maps to TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. Configuration files may expect either form.-tls1_1 locally with "no protocols available". OpenSSL 3.0 allows TLS 1.0 and 1.1 only at security level 0, so this failure is the client's own policy and says nothing about the server.