Skip to main content

Command Palette

Search for a command to run...

Http Vs Https

Published
โ€ข4 min readโ€ขView as Markdown
Http Vs Https
A

Hi everyone, I am Anusha Nayak. ๐Ÿš€I am passionate about bridging the realms of development and operations to propel efficient and seamless software delivery! ๐Ÿ’ป As a DevOps professional, I'm all about making things run smoother, like cutting out unnecessary steps, setting up automatic software installations, and making sure everything flows together nicely๐Ÿ‘จโ€๐Ÿ’ป. I want to help teams create great software quickly every single time.

๐‡๐“๐“๐ (๐‡๐ฒ๐ฉ๐ž๐ซ๐ญ๐ž๐ฑ๐ญ ๐“๐ซ๐š๐ง๐ฌ๐Ÿ๐ž๐ซ ๐๐ซ๐จ๐ญ๐จ๐œ๐จ๐ฅ) is the underlying protocol used for communication on the World Wide Web.

Here's a overview of how it works:

1. ๐—–๐—น๐—ถ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜: ๐Ÿ–ฅ๏ธ A client (usually a web browser) initiates an HTTP request to a server by specifying a URL (Uniform Resource Locator) in the browser's address bar or by clicking on a link.

2. ๐——๐—ก๐—ฆ ๐—Ÿ๐—ผ๐—ผ๐—ธ๐˜‚๐—ฝ: ๐ŸŒ If the URL contains a domain name (e.g., www.example.com), the browser performs a DNS lookup to obtain the server's IP address.

3. ๐—ง๐—–๐—ฃ ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป: ๐Ÿ”— The client establishes a TCP (Transmission Control Protocol) connection with the server on port 80 (or 443 for HTTPS) to initiate communication.

4. ๐—›๐—ง๐—ง๐—ฃ ๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜: ๐Ÿ“ก The client sends an HTTP request message to the server. This request consists of a request line (which includes the HTTP method, such as GET or POST), headers (additional information about the request), and sometimes a message body (data to be sent to the server, typically with methods like POST).

5. ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ฃ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€๐—ถ๐—ป๐—ด: ๐Ÿ–ฅ๏ธโš™๏ธ The server receives the request, processes it, and generates an HTTP response. This may involve accessing databases, executing scripts, or retrieving files.

6. ๐—›๐—ง๐—ง๐—ฃ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ: ๐Ÿ“ฌ The server sends an HTTP response message back to the client. This response includes a status line (indicating whether the request was successful or not), headers (additional information about the response), and possibly a message body (the requested content).

7. ๐—–๐—ผ๐—ป๐˜๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด: ๐Ÿ–ผ๏ธ The client receives the response and renders the content, which may include HTML, CSS, JavaScript, images, or other media types.

8. ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—–๐—น๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ: ๐Ÿ”’ The TCP connection is closed either by the client or the server, depending on whether it's a persistent (keep-alive) or non-persistent connection.

๐‡๐“๐“๐๐’ (๐‡๐ฒ๐ฉ๐ž๐ซ๐ญ๐ž๐ฑ๐ญ ๐“๐ซ๐š๐ง๐ฌ๐Ÿ๐ž๐ซ ๐๐ซ๐จ๐ญ๐จ๐œ๐จ๐ฅ ๐’๐ž๐œ๐ฎ๐ซ๐ž) is an extension of HTTP that adds a layer of encryption and security to the communication between clients and servers.

Here's a overview of how it works:

1. ๐—ฆ๐—ฆ๐—Ÿ/๐—ง๐—Ÿ๐—ฆ ๐—›๐—ฎ๐—ป๐—ฑ๐˜€๐—ต๐—ฎ๐—ธ๐—ฒ: ๐Ÿค The process begins with an SSL/TLS (Secure Sockets Layer/Transport Layer Security) handshake, where the client and server establish a secure connection. This involves several steps:

  • The client sends a "ClientHello" message to the server, indicating supported cryptographic algorithms and other parameters.

  • The server responds with a "ServerHello" message, selecting a mutually supported cryptographic algorithm and providing its SSL certificate.

  • The client verifies the server's certificate to ensure it's valid and issued by a trusted Certificate Authority (CA).

  • If the verification is successful, the client generates a session key, encrypts it with the server's public key (from the certificate), and sends it to the server.

  • The server decrypts the session key using its private key, establishing a secure connection.

2. ๐—˜๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐——๐—ฎ๐˜๐—ฎ ๐—ง๐—ฟ๐—ฎ๐—ป๐˜€๐—ณ๐—ฒ๐—ฟ: ๐Ÿ”’ Once the secure connection is established, data exchanged between the client and server is encrypted using symmetric encryption with the session key. This ensures confidentiality and integrity of the transmitted data.

3. ๐—›๐—ง๐—ง๐—ฃ๐—ฆ ๐—ฅ๐—ฒ๐—พ๐˜‚๐—ฒ๐˜€๐˜๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ๐˜€: ๐ŸŒ๐Ÿ” The client sends HTTPS requests to the server, just like with HTTP. However, the data transmitted over the network is encrypted, preventing eavesdropping or tampering by attackers.

4. ๐—ฆ๐—ฆ๐—Ÿ/๐—ง๐—Ÿ๐—ฆ ๐—ง๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฎ๐˜๐—ถ๐—ผ๐—ป: ๐Ÿ›‘ Upon receiving the encrypted data, the server decrypts it using the session key established during the handshake process. The server processes the request and sends the response back to the client over the secure connection.

5. ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—–๐—น๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ: ๐Ÿ”’โŒ Once the communication is complete, the SSL/TLS connection can be terminated. This may happen after a certain period of inactivity or when explicitly closed by either the client or server.

๐—›๐—ง๐—ง๐—ฃ๐—ฆ provides end-to-end encryption, protecting sensitive information such as login credentials, financial transactions, and personal data exchanged between clients and servers. It's widely used for securing web browsing, online banking, e-commerce transactions, and other sensitive communications over the internet.

Conclusion:

๐—›๐—ง๐—ง๐—ฃ is a stateless protocol, meaning each request-response cycle is independent of previous ones. To maintain state across multiple requests, mechanisms like cookies or sessions are often used.

๐—›๐—ง๐—ง๐—ฃ๐—ฆ(HTTP Secure) provides encryption and authentication to secure data transmission over the web.

HTTP (Hypertext Transfer Protocol)HTTPS (Hypertext Transfer Protocol Secure)
ProtocolHTTP is a protocol used for transmitting data between a web server and a web browser.HTTPS is a secure version of HTTP that uses encryption to protect the data being transmitted.
SecurityHTTP data is transmitted in plain text.HTTPS provides encryption and data integrity, making it more secure than HTTP.
PortTypically operates on port 80.Typically operates on port 443.
UsageHistorically, HTTP has been widely used for transmitting web pages, images, and other content on the internet.HTTPS is used to securely transmit sensitive information such as login credentials, payment details, and personal data.
SpeedHTTP is generally faster than HTTPS because it does not involve encryption and decryption processes.
TrustHTTP does not involve such authentication mechanisms.HTTPS connections rely on digital certificates issued by trusted Certificate Authorities (CAs) to verify the authenticity of the server.
SEOGoogle and other search engines prioritize HTTPS websites in search results to encourage web security.