TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
ECDHE-RSA-CHACHA20-POLY1305 is the TLS 1.2 version of the ChaCha20-Poly1305 cipher suite. Like its TLS 1.3 counterpart, it is preferred for mobile and IoT devices without hardware AES acceleration. Introduced by Google and added to TLS 1.2 via RFC 7905.
Key Exchange
ECDHE
Authentication
RSA
Encryption
ChaCha20
MAC / Integrity
Poly1305 (AEAD – integrated)
RFC 7905 added ChaCha20-Poly1305 to TLS 1.2. This cipher suite provides the same ChaCha20-Poly1305 advantages as in TLS 1.3 – excellent performance on ARM processors without AES-NI – combined with ECDHE forward secrecy and RSA authentication. Modern Nginx and OpenSSL configurations include this alongside AES suites.