Client and server agree on protocol/cipher, the server proves its identity using a certificate, they perform key exchange to derive shared session keys, and then switch to encrypted, authenticated traffic using those keys.
Client and server agree on protocol/cipher, the server proves its identity using a certificate, they perform key exchange to derive shared session keys, and then switch to encrypted, authenticated traffic using those keys.