Wireshark-users: Re: [Wireshark-users] TLS
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 7 Oct 2008 10:18:20 -0700

On Oct 7, 2008, at 9:01 AM, David Moncur wrote:

I am using Wireshark 1.0.3 on Windows XP.

Having captures an SMTP session using TLS,

Is that a session that starts out as regular SMTP and then switches to TLS with a STARTTLS command?

If so...

I was expecting to have Wireshark decode it for me. However it decoded it no further than SMTP, and TLS is not even in the protocol list.

...there's no support for that in the 1.0[.x] releases. I checked code to support STARTTLS into the main branch, but that was fairly recently, after the 1.0[.x] releases were branched off.

How do I get more information from my tcpdump capture ?

The 1.1.0 development build might have STARTTLS support (I don't remember whether it was built before or after I added it):

	http://www.wireshark.org/download/win32/

If not, you'll need one of the automated builds:

	http://www.wireshark.org/download/automated/win32/