TLS termination proxy
proxy server, intermediary between client and server

A TLS termination proxy (or SSL termination proxy, or SSL offloading) is a proxy server that acts as an intermediary point between client and server applications. It is used to terminate and/or establish TLS (or DTLS) tunnels by decrypting and/or encrypting communications. This differs from TLS pass-through proxies, which forward encrypted (D)TLS traffic between clients and servers without terminating the tunnel.
Uses
TLS termination proxies can be used to:
secure plaintext communications over untrusted networks by tunnelling them in (D)TLS,
allow inspection of encrypted traffic by an intrusion detection system to detect and block malicious activities,
allow network surveillance and analysis of encrypted traffic,
enable otherwise unsupported integration with other applications that provide additional capabilities such as content filtering or Hardware security modules,
enable (D)TLS protocol versions, extensions, or capabilities (e.g., OCSP stapling, ALPN, DANE, CT validation, etc.) unsupported by client or server applications to enhance their compatibility and/or security,
work around buggy or insecure (D)TLS implementations in client or server applications to improve their compatibility and/or security,
provide additional certificate-based authentication unsupported by server and/or client applications or protocols,
provide an additional defense-in-depth layer for centralised control and consistent management of (D)TLS configuration and associated security policies, and
reduce the load on the main servers by offloading the cryptographic processing to another machine.
Types
TLS termination proxies can provide three connectivity patterns:
TLS Offloading: Terminates an inbound encrypted (D)TLS connection from a client and forwards communications over a plaintext connection to the server.
TLS Encryption: Accepts an inbound plaintext connection from a client and forwards communications over an encrypted (D)TLS connection to the server.
TLS Bridging: Terminates two encrypted (D)TLS connections to allow inspection and filtering of traffic. The proxy decrypts the inbound (D)TLS connection from the client and re-encrypts it using a separate (D)TLS connection to the server.
Combining a TLS Encrypting proxy in front of a client with a TLS Offloading proxy in front of a server can allow (D)TLS encryption and authentication for protocols and applications that do not otherwise support it, with the two proxies maintaining a secure (D)TLS tunnel over untrusted network segments between client and server.
A proxy used by clients as an intermediary gateway for all outbound connections is typically called a Forward proxy, while a proxy used by servers as an intermediary gateway for all inbound connections is typically called a Reverse proxy.
“TLS termination proxy” enters the record as proxy server, intermediary between client and server. Crown Archives preserves that source wording while asking what termination, proxy and server can confirm, complicate or overturn.
Why this record matters
“TLS termination proxy” is worth following because a concise public description often conceals a longer documentary argument. Here, termination, proxy and server provides the most credible route into that argument.
The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Mar 12, 2026. The linked authority identifier is Q7393022. None of the 0 selected statements returned an explicit reference.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “TLS termination proxy”, its source revision and the description used here.
- Expand the search: follow TLS termination proxy primary sources, TLS termination proxy archive and termination research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “TLS termination proxy”?
- Which cited source is closest to the event, object or claim?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “TLS termination proxy” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.