Can Wireshark decode a LDAPs conversation?

asked 2018-04-13

I captured a 'regular' (no TLS) LDAP conversation and Wireshark decoded the LDAP conversation.

I captured a LDAPs conversation and, because I had the private key of the server, Wireshark was able to decode the TCP packets and show the data inside them.

But Wireshark was not able to decode / display the LDAP conversation inside the decrypted TCP packets. Should Wireshark have been able to do this, and I just didn't set it up correctly?

Thanks! tl

answered 2018-04-14

updated 2018-04-14

Yes, it should be possible.

Have you tried using 'Analyze' -> 'Decode as...' -> 'Field': 'SSL Port', 'Value': 'your TCP port, e.g. 636', 'Currrent': 'LDAP'?

That worked great! I had fiddled with this, but had not used these values: Field - SSL Port Value - 636 Type - Integer, base 10 Default - data Current - LDAP

Thanks for the help!

tlemons ( 2018-04-16 )

