TLS: Putting the Pieces Together · seed 1 · A4, ink-friendly. The answer key prints on its own page for grown-ups.

The handshake in order

Computing · Networks & Security · ages 21-22
Name ______________________   Date ____________
  1. What carries the traffic after the secret is agreed?

    • Plain text for speed
    • A fast symmetric cipher with an integrity check
    • A postcard with no envelope
  2. What opens the handshake?

    • The server shows its certificate and public key
    • Both sides delete their keys
    • The browser sends its password first
  3. A name mismatch still allows the key exchange to proceed.

    Circle one:   True   False

  4. What does the certificate step establish?

    • That the key belongs to the requested name
    • That the site loads quickly
    • That prices are low
  5. Certificate says mail, you asked for bank. Which step fails?

    • The final logout button
    • The certificate name check, before any secret
    • The choice of fonts
  6. What does the key exchange establish?

    • A fresh secret nobody else holds
    • A new domain name
    • A longer certificate expiry
  7. A laptop clock reads three years ahead. Which errors fit good sites?

    • Faster downloads than ever
    • Free extra storage
    • Expiry and validity failures on good certificates
  8. A server key leaks a year later. Which visits stay sealed?

    • None, everything reopens
    • Ones with fresh secrets never stored
    • Only the homepage text
LightMySky · lightmysky.comW1-mt_JzIwi-BYG0-s1

Answer key

For grown-ups. Fold this page away before handing over the rest.

The handshake in order W1-mt_JzIwi-BYG0-s1

  1. A fast symmetric cipher with an integrity check · The shared secret feeds a fast cipher that guards secrecy and integrity.
  2. The server shows its certificate and public key · The certificate comes first, like an ID card starting a meeting.
  3. False · The handshake stops at the name check, before any secret.
  4. That the key belongs to the requested name · The ID card binds the public key to the name you typed.
  5. The certificate name check, before any secret · The ID check fails early on purpose, so no secret follows.
  6. A fresh secret nobody else holds · Both sides leave the exchange holding a secret no watcher shares.
  7. Expiry and validity failures on good certificates · A skewed clock judges good dates as expired or not yet valid.
  8. Ones with fresh secrets never stored · Unstored per-visit secrets cannot be rebuilt from the leaked key.
Worksheet · LightMySky