Transport Layer Security (TLS)
Transport Layer Security is a successor of Secure Socket Layer, a cryptographic protocol that is designed to provide secure communications over a computer network, such as the connection oriented Transmission Control Protocol (TCP) that is a key part of the TCP/IP stack that runs the Internet.
The parties of a TLS connection identify and each other by digital certificates, which comprise a public key, the claimed identitity, and a cryptographic signature of a trusted certificate authority (CA). The private key corresponding to the public key is controlled by the certified party. Depending on the application, one or both parties may have to present their certificates before the connection can proceed. The public/private key pair will be used in a key exchange protocol that will assign a unique session key that will be used in subsequent communication.
It is customary that public web servers use HTTPS certificates whose certificate chain can be tracked down to one of the trusted certificate authorities that has been built into the web browser.
In a virtual private network, it makes sense to define a private root certificate authority, so that no secret domain names will have to be leaked to a public certificate authority that operates in the Internet. A custom certificate authority may be added to devices that may connect to a VPN gateway.
Sometimes, client certificates may be used. While this is rarely used in HTTPS, certificates do offer better security than passwords, which often are vulnerable to dictionary attacks. Our VPN gateway authenticates peers by client certificates.