Wireshark mailing list archives

Re: Wrong protocol detection - wrong decryption


From: Sake Blok <sake () euronet nl>
Date: Tue, 10 Apr 2012 12:28:04 +0200

On 4 apr 2012, at 17:04, bitozoid wrote:

On Wed, Apr 4, 2012 at 12:40 PM, Sake Blok <sake () euronet nl> wrote:
Have you used "start_tls" instead of the port number in your SSL-keys list? So something like:

1.2.3.4,start_tls,smtp,/tmp/key.pem

I have tried both. Same result.


With the start_tls option, you should at least see the pre-TLS command and responses dissected as SMTP and not SSL. 
Just checking, you did not try them both at the same time. You should use one or the other :-)
Are you able to post the capture file and ssl-debug file? And if it is in a test-environment, the private key?

Cheers,
Sake
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: