Hi, I noticed that this method (see this question) to decrypt IKE (v1) packets doesn't work when certificate are used instead of PSK. At first, I thought it would be the fragmentation as phase 1 message 5 and 6 exceeded the 1500 byte size and got fragmented into two packets. But after enabling JUMBO frames, the problem remained the same. I haven't changed all other algorithms (still 3DES, MD5 etc.) that I used in PSK test. Any ideas? I'm happy to provide my capture and the pluto log file on request... Cheers, Dominik asked 02 Nov '12, 06:25 Dominik converted to question 02 Nov '12, 06:40 grahamb ♦ |
Converted from an "answer" to a question from http://ask.wireshark.org/questions/12019/how-can-i-decrypt-ikev1-packets