I just started working on TLS/SSL(Secure Sockets Layer) related projects.
I happen to read a lot of documents related to SSL for getting comfortable for the project and at some point, it struck me that "While the client and server is connected for communications after the handshake, it said that a secure channel is created between the client and the server for all the communications of a session".
My doubt is, whether the secure channel created between the client and server itself is encrypted and the data transferred through that secure channel is plain text? or the channel is secure but not encrypted and only the data sent through that secure channel is encrypted?"
Some say that "SSL is an encrypted secure channel" and others say "Secure channel is created and the data is encrypted" which puts me in the situation to post this question
I read lot of documents to get clarified but the more i read, the more confused i am.