N
N
Nightbane2021-05-08 16:43:57
Google Chrome
Nightbane, 2021-05-08 16:43:57

What keys does chrome write using SSLKEYLOGFILE and how does wireshark use them?

Hello, I am studying TLS and trying to decrypt traffic, but some points are not clear to me

1) What keys does chrome write with the active SSLKEYLOGFILE environment variable and why are there so many of them? to go to 1 resource of the order of 120-150 lines, there are lines such as CLIENT_HANDSHAKE_TRAFFIC_SECRET, SERVER_HANDSHAKE_TRAFFIC_SECRET, CLIENT_TRAFFIC_SECRET_0, SERVER_TRAFFIC_SECRET_0, EXPORTER_SECRET and then repeated, I would like to understand the meaning of these lines

2) how wireshark uses them to decrypt packets, symmetrical key among these lines definitely not, they do not fit in size, for the session that I am analyzing, AES 128 is used, and in the lines all values ​​​​are 32 bit

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question