3 ms·
If you have the private key, you can decrypt it in Wireshark.
by chrj 11y ago
If you have the private key, you can decrypt it in Wireshark.
- nly 11y agoInaccurate. Most browsers will now be using ephemeral key exchange. You pretty much have to configure one of the end points to dump session keys to a log file, then load that in to wireshark alongside the packet dump.
- amelius 11y agoIt would be nice if there was some automated way to do this.
- mhils 11y agoYou can use mitmproxy [1] to dump the TLS Master Secrets for all connnections it intercepts [2]. The dumpfile goes straight into WireShark. Obligatory disclaimer: I'm one of the mitmproxy authors - happy to answer any questions. [1] https://mitmproxy.org/ https://mitmproxy.org/ [2] http://docs.mitmproxy.org/en/stable/dev/sslkeylogfile.html http://docs.mitmproxy.org/en/stable/dev/sslkeylogfile.html