Decrypt TLS 1.3 with Wireshark

asked 2019-06-12

Hey all!

For a university project, my colleagues and me decrypted a TLS 1.2 Session with the help of the following guide: Unfortunately, it did not work out on Websites (like facebook) that used TLS 1.3 for encryption. Does anyone know, how to accomplish that?

Thanks a lot!

What version of Wireshark are you using? If you're not using the latest version, I'd highly recommend that you upgrade.

cmaynard ( 2019-06-12 )edit

answered 2019-06-12

grahamb

updated 2019-06-12 22:00:35 +0000

Decryption of TLS 1.3 was demonstrated at SharkFest'19 US by @Lekensteyn and his presentation should be up on the SharkFest retrospective page after the conference, and is also available from previous SharkFest presentations.

You will need to user the pre-master secret method as TLS 1.3 doesn't support the RSA key exchange methods that were used in previous versions of TLS.

Do you have the pre-master log file? Have you configured the TLS dissector preferences to use that log file?

The slides are now up here: You need at least Wireshark 2.6 for TLS 1.3 decryption support.

Lekensteyn ( 2019-06-12 )edit

Thank you very much for your immediate help. Unfortunately, we could not apply the additional settings that were needed, since the due date was too close and we had infrastructural issues at the university. We will include your comment and link your slides in our seminar paper though to provide help for further projects.

schwinge17 ( 2019-06-14 )edit

