BLOG     |     FORUM
Welcome, Guest
Username: Password: Remember me
All your questions answered real quick by Unleash Networks Engineers.
  • Page:
  • 1

TOPIC: TLS Decryption

TLS Decryption 13 years 6 days ago #435

  • nigel
  • nigel's Avatar
Hi there,

I downloaded the Unsniff trial version to test its TLS decryption features. I am particularly interested in decrypting resumed session.

For that purpose, I captured the entire traffic of an FTPS (implicit) connection and saved it as .pcap file. I then followed the instructions on www.unleashnetworks.com/resources/articl...tls-decryption.html.

Unfortunately, nothing happens and nothing is being decrypted. For example, I don't even see unsniff identifying the TLS handshake packets as such. Am I missing a step maybe?

The cipher used is RSA_WITH_AES_256_CBC_SHA, which I read is supported. Also, I am certain that I am using the correct key and have it imported correctly into unsniff.

Any advice?

Regards,
Nigel
The administrator has disabled public write access.

Re:TLS Decryption 13 years 6 days ago #436

HI Nigel,

You need to tell Unsniff that what ports should be considered as TLS.

1. Go to Plugins > Manage Access Points
2. Click on TCP
3. Click on "New TCP Access Point"
4. Specify the port & select TLS from drop down.

Can you try the above ?

Thanks,


Vivek. R.
Vivek R
Unleash Networks
Support : www.unleashnetworks.com/forums
The administrator has disabled public write access.
  • Page:
  • 1
Moderators: vivek [unleash]
Time to create page: 0.028 seconds