Gateway Gus saysTLS uses certificates to prove server identity; SNI lets one IP host many secure domains.
A TLS certificate, issued by a trusted Certificate Authority, binds a domain to a public key — that's how your browser knows it's really talking to the bank. The handshake negotiates encryption keys. SNI (Server Name Indication) sends the requested hostname early so one server/IP can present the correct certificate for many domains. Let's Encrypt made certs free and automatic.
Power-ups you unlock
Certificate (from a CA) binds domain ↔ public key
Handshake negotiates the encryption keys
SNI: many HTTPS domains per IP
Let’s Encrypt = free, automated certs
Timeout Titan attacks — common mistakes
Self-signed certs in production (browser warnings)
Expired certificates breaking the API
Ignoring certificate chain/intermediate issues
Boss battleExplain what a TLS certificate proves and who vouches for it.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>cert: "api.x.com owns this public key" — signed by a CA
SNI: client says "api.x.com" → server picks that cert</pre></body></html>