You need to enable JavaScript to use the communication tool powered by OpenWidget

What Is Perfect Forward Secrecy (PFS)?

Perfect Forward Secrecy (PFS) — a key-agreement property that keeps past sessions confidential even if a server's long-term private key is later compromised.

During a TLS connection, the peers negotiate a protocol version and cipher suite, validate the certificate, derive session keys, and only then exchange protected data. Feature availability depends on the client, server, and selected TLS version.

🔐 The .LOCKER promotion has been extended — save over 83%

Popular Questions About Perfect Forward Secrecy (PFS)

  • What does Perfect Forward Secrecy (PFS) mean?

    Perfect Forward Secrecy (PFS) — a key-agreement property that keeps past sessions confidential even if a server's long-term private key is later compromised.

  • At what stage is it used?

    The mechanism operates while establishing or reusing a TLS session and affects compatibility, connection latency, confidentiality, and resistance to later key compromise.

  • How should it be configured securely?

    Disable obsolete versions and weak algorithms, use a valid certificate, verify SNI and ALPN behavior, update TLS libraries, and test with modern supported clients.

  • Helpful articles

    • Glossary

      • Latest news & promotions

          Loading…