I have captured full four EAPOL handshakes. But the data captured were not decrypted (always show 802.11 protocols).

Can you give me some directions, how can I decrypt the captured data.

Thanks, --William

asked 17 May, 19:28

converted to question 18 May, 03:05

This question was originally posted as an "answer" to this question.

(18 May, 03:07) grahamb

In some cases it helps to toggle the combo box in the wireless toolbar from "Wireshark" to "None" and back to "Wireshark": https://ask.wireshark.org/questions/60947/why-isnt-wireshark-decrypting-80211-traffic-in-my-capture-even-if-the-eapol-handshake-is-present/60951

answered 18 May, 13:17

Hi Christian_R,

Thank for your input, However, there is no combo box as you mentioned in the Wireshark version I'am using now (2.2.6 version - the latest Wireshark version). Therefore, I cannot decrypt the captured data. Any other solution can I try?

Thanks, -William

(11 hours ago) dknovo

What OS do you use? The same combobox Canberra found in the decryption key dialogue.

(2 hours ago) Christian_R
