Wireshark-users: Re: [Wireshark-users] need help with decrypting ssl messages
From: Al <shaselai@xxxxxxxxx>
Date: Mon, 18 Oct 2010 12:14:38 -0700 (PDT)
Hey,
    i think i wasnt sending the file after all... but can you help with the decryption problem i am having?

I checked the server hello and it is not using DH encryption but TLS_RSA_WITH_RC4_128_MD5.  

I checked the debug and i have :
decrypt_ssl3_record: no decoder available

so i am not sure what is wrong here... it is using the server's decoder... 
i know the SSL setting for the private cert exchange is correct since i get "testkey.pem successfully loaded"....

thanks....

--- On Sun, 10/17/10, Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx> wrote:

> From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
> Subject: Re: [Wireshark-users] need help with decrypting ssl messages
> To: "Community support list for Wireshark" <wireshark-users@xxxxxxxxxxxxx>
> Date: Sunday, October 17, 2010, 11:45 PM
> On Thu, Oct 14, 2010 at 01:29:54PM
> -0700, Al wrote:
> 
> > ssl_generate_keyring_material not enough data to
> generate key (0x17 
> > required 0x37 or 0x57)
> 
> > When I am listening on the ip I as client am sending
> files like 
> > 2-3megs. I browsed through the wireshark frames but i
> dont really see 
> > anything that's that big... i am curious as to whether
> the data's size 
> > isn't being shown or the file was never transmitted?
> 
> Did your capture get every byte of each packet or was it
> cut off (a low 
> "snaplen" or "snapshot length" setting).
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>          
>    mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>