Secure Sockets Layer (SSL)

The deprecated predecessor of TLS, created at Netscape in the 1990s; the IETF has retired both published SSL versions, though the name survives loosely in phrases like SSL certificate.

Secure Sockets Layer (SSL) was the first widely used protocol for encrypting web sessions, developed at Netscape in the 1990s. SSL 3.0 was the last version; the IETF then standardised its successor as Transport Layer Security, starting with TLS 1.0 in RFC 2246. Both SSL versions still found in the field were later formally retired: RFC 6176 prohibits SSL 2.0 and RFC 7568 deprecates SSL 3.0, as design flaws made both unsafe. PCI DSS no longer treats SSL as strong cryptography for protecting card data.

The difficulty is vocabulary. People still say “SSL” when they mean TLS, and an “SSL certificate” is simply an X.509 certificate used with TLS, issued through a public key infrastructure. The TLS handshake and the cipher suite negotiation descend from SSL, but the protocol that should be running is TLS. Early TLS has been retired too: RFC 8996 deprecates TLS 1.0 and TLS 1.1, which leaves TLS 1.2 and TLS 1.3 as the current versions. The ISC2 exam outline lists them together as SSL/TLS.

Exam relevance: when an option proposes SSL for protecting data in transit, a scenario is likely to be checking whether the candidate knows it is deprecated. Candidates are expected to choose a current TLS version, to treat a server that still accepts SSL as a finding, and to read everyday “SSL” as TLS.