This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Decrypting SSL/HTTPs (Mac Mail to Exchange 2010), have private key file, but cannot figure out.

0

Greetings.

I am the administrator of an Exchange 2010 server which is using an SSL certificate that I created using a Windows Server CA. I'm troubleshooting an issue with Mac Mail disconnecting from the mail server every 2-3 minutes, and attempting to see what is going on by decrypting the conversation between Mac Mail and the Exchange server. The communication appears to be happening only over the remote port 443 https, I believe Mac Mail is connecting to "Outlook Anywhere" or perhaps Exchange Web Services and hence only connecting to Port 443.

I exported the private key and certificate from the Exchange server which resulted in a .pfx file. On my macbook I then ran openssl to convert the .pfx file to a .pem file:

openssl pkcs12 -in privkey_careful.pfx -out privkey_careful.pem -nodes

The resulting file contained both the private key and a certificate as well as other metadata, so I deleted everything besides

-----BEGIN PRIVATE KEY-----
.........key data
-----END PRIVATE KEY-----

from the file.

I then opened my capture file created with wireshark on my macbook which captured the period of disconnection of the mail client to the Exchange server. In the wireshark preferences I went to Protocols->SSL and configured a new key, specifiying the IP address of the Exchange server, the port 443 (I also tried 0), and specified a debug file, and the private key file.

I click OK/apply and it looks like Wireshark is applying something to each packet, but I do not see any decrypted information anywhere. Browsing the captured packets looks the same as it did before.

partial SSL debug log file below. Any hints on what I might be doing wrong appreicate. Thank you.

Wireshark SSL debug log

ssl_association_remove removing TCP 443 - http handle 0x109234710
Private key imported: KeyID c5:31:c4:23:0c:6b:e5:df:8f:9b:dd:b4:97:22:1a:fc:...
ssl_load_key: swapping p and q parameters and recomputing u
ssl_init IPv4 addr '27.112.87.163' (27.112.87.163) port '443' filename '/Users/123user/Downloads/privkey_careful.pem' password(only for p12 file) ''
ssl_init private key file /Users/123user/Downloads/privkey_careful.pem successfully loaded.
association_add TCP port 443 protocol http handle 0x109234710

dissect_ssl enter frame #523 (first time) ssl_session_init: initializing ptr 0x10a6a7310 size 688 conversation = 0x10a6a6fe8, ssl_session = 0x10a6a7310 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 38, ssl state 0x10 association_find: TCP port 63069 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63069 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #524 (first time) ssl_session_init: initializing ptr 0x10a6a7a68 size 688 conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #525 (first time) ssl_session_init: initializing ptr 0x10a6a8158 size 688 conversation = 0x10a6a7e30, ssl_session = 0x10a6a8158 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 38, ssl state 0x10 association_find: TCP port 63073 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63073 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #526 (first time) ssl_session_init: initializing ptr 0x10a6a8848 size 688 conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #531 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #533 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #536 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 90 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #537 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 90 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #540 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #541 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #542 (first time) conversation = 0x10a6a7e30, ssl_session = 0x10a6a8158 record: offset = 0, reported_length_remaining = 283 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 278, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #543 (first time) conversation = 0x10a6a7e30, ssl_session = 0x10a6a8158 record: offset = 0, reported_length_remaining = 287 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 282, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #546 (first time) ssl_session_init: initializing ptr 0x10a6aaab8 size 688 conversation = 0x10a6aa790, ssl_session = 0x10a6aaab8 record: offset = 0, reported_length_remaining = 42 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 37, ssl state 0x10 association_find: TCP port 63072 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63072 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #548 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 85 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 80, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #551 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 186 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 149 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 144, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #553 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #558 (first time) ssl_session_init: initializing ptr 0x10a6abfb8 size 688 conversation = 0x10a6ab960, ssl_session = 0x10a6abfb8 record: offset = 0, reported_length_remaining = 217 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 212, ssl state 0x00 association_find: TCP port 63087 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 208 bytes, remaining 217 packet_from_server: is from server - FALSE ssl_find_private_key server 54.200.14.109:443 ssl_find_private_key can't find private key for this server! Try it again with universal port 0 ssl_find_private_key can't find private key for this server (universal port)! Try it again with universal address 0.0.0.0 ssl_find_private_key can't find any private key! dissect_ssl3_hnd_hello_common found CLIENT RANDOM -> state 0x01

dissect_ssl enter frame #562 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #564 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 74 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #566 (first time) ssl_session_init: initializing ptr 0x10a6ad248 size 688 conversation = 0x10a6acf20, ssl_session = 0x10a6ad248 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63067 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63067 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #567 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #570 (first time) conversation = 0x10a6a6fe8, ssl_session = 0x10a6a7310 record: offset = 0, reported_length_remaining = 413 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 408, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #571 (first time) ssl_session_init: initializing ptr 0x10a6adc10 size 688 conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 169 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 164, ssl state 0x00 association_find: TCP port 63088 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 160 bytes, remaining 169 packet_from_server: is from server - FALSE ssl_find_private_key server 54.200.14.109:443 ssl_find_private_key can't find private key for this server! Try it again with universal port 0 ssl_find_private_key can't find private key for this server (universal port)! Try it again with universal address 0.0.0.0 ssl_find_private_key can't find any private key! dissect_ssl3_hnd_hello_common found CLIENT RANDOM -> state 0x01

dissect_ssl enter frame #573 (first time) conversation = 0x10a6a6fe8, ssl_session = 0x10a6a7310 record: offset = 0, reported_length_remaining = 288 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 283, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #575 (first time) ssl_session_init: initializing ptr 0x10a6ae740 size 688 conversation = 0x10a6ae418, ssl_session = 0x10a6ae740 record: offset = 0, reported_length_remaining = 42 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 37, ssl state 0x10 association_find: TCP port 63074 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63074 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #577 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448

dissect_ssl enter frame #578 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 1770 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x11 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 1765, ssl state 0x11 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 77 bytes, remaining 1770 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0005 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 86 length 1676 bytes, remaining 1770 dissect_ssl3_handshake iteration 0 type 14 offset 1766 length 0 bytes, remaining 1770

dissect_ssl enter frame #581 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 267 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 262, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 16 offset 5 length 258 bytes, remaining 267 trying to use SSL keylog in failed to open SSL keylog

dissect_ssl enter frame #582 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - FALSE ssl_change_cipher CLIENT

dissect_ssl enter frame #583 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 41 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 36, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 219 offset 5 length 11403237 bytes, remaining 41

dissect_ssl enter frame #587 (first time) conversation = 0x10a6acf20, ssl_session = 0x10a6ad248 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63067 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63067 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #589 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #590 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 47 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 41 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 36, ssl state 0x17 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 191 offset 11 length 13626809 bytes, remaining 47

dissect_ssl enter frame #592 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 541 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 536, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63088 found 0x0 association_find: TCP port 443 found 0x10e637a70

dissect_ssl enter frame #593 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448

dissect_ssl enter frame #594 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 1638 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 1633, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63088 found 0x0 association_find: TCP port 443 found 0x10e637a70

dissect_ssl enter frame #597 (first time) conversation = 0x10a6acf20, ssl_session = 0x10a6ad248 record: offset = 0, reported_length_remaining = 90 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #598 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 90 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #601 (first time) ssl_session_init: initializing ptr 0x10a6b11f0 size 688 conversation = 0x10a6b0ec8, ssl_session = 0x10a6b11f0 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63064 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63064 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #602 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #604 (first time) conversation = 0x10a6ac4f0, ssl_session = 0x10a6adc10 record: offset = 0, reported_length_remaining = 282 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 277, ssl state 0x17 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x10e637a70

dissect_ssl enter frame #607 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 85 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 80, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #609 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 186 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 149 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 144, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #611 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #612 (first time) ssl_session_init: initializing ptr 0x10a6b26f0 size 688 conversation = 0x10a6b23c8, ssl_session = 0x10a6b26f0 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x10 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63063 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63063 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #615 (first time) conversation = 0x10a6b0ec8, ssl_session = 0x10a6b11f0 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63064 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63064 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #619 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 85 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 80, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #620 (first time) ssl_session_init: initializing ptr 0x10a6b36b0 size 688 conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 201 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 196, ssl state 0x00 association_find: TCP port 63089 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 192 bytes, remaining 201 packet_from_server: is from server - FALSE ssl_find_private_key server 54.200.14.109:443 ssl_find_private_key can't find private key for this server! Try it again with universal port 0 ssl_find_private_key can't find private key for this server (universal port)! Try it again with universal address 0.0.0.0 ssl_find_private_key can't find any private key! dissect_ssl3_hnd_hello_common found CLIENT RANDOM -> state 0x01

dissect_ssl enter frame #622 (first time) conversation = 0x10a6b0ec8, ssl_session = 0x10a6b11f0 record: offset = 0, reported_length_remaining = 138 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 101 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 96, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #625 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 186 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0 record: offset = 37, reported_length_remaining = 149 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 144, ssl state 0x10 association_find: TCP port 993 found 0x10a275fb0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #662 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 32, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #671 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 133 dissect_ssl3_record found version 0x0301(TLS 1.0) -> state 0x11 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 81, ssl state 0x11 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 77 bytes, remaining 86 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 ssl_restore_session can't find stored session trying to use SSL keylog in failed to open SSL keylog cannot find master secret in keylog file either dissect_ssl3_hnd_srv_hello found CIPHER 0x0005 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material record: offset = 86, reported_length_remaining = 47 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 92, reported_length_remaining = 41 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 36, ssl state 0x17 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 206 offset 97 length 15021299 bytes, remaining 133

dissect_ssl enter frame #673 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - FALSE ssl_change_cipher CLIENT

dissect_ssl enter frame #674 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 41 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 36, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 219 offset 5 length 12240129 bytes, remaining 41

dissect_ssl enter frame #675 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 541 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 536, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63089 found 0x0 association_find: TCP port 443 found 0x10e637a70

dissect_ssl enter frame #676 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448

dissect_ssl enter frame #677 (first time) conversation = 0x10a6b2ab8, ssl_session = 0x10a6b36b0 record: offset = 0, reported_length_remaining = 1638 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 1633, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63089 found 0x0 association_find: TCP port 443 found 0x10e637a70

dissect_ssl enter frame #681 (first time) conversation = 0x10a6a8520, ssl_session = 0x10a6a8848 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63057 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63057 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #682 (first time) conversation = 0x10a6b23c8, ssl_session = 0x10a6b26f0 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63063 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63063 found 0x0 association_find: TCP port 993 found 0x10a275fb0

dissect_ssl enter frame #683 (first time) conversation = 0x10a6a7740, ssl_session = 0x10a6a7a68 record: offset = 0, reported_length_remaining = 53 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 48, ssl state 0x10 association_find: TCP port 63061 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 63061 found 0x0 association_find: TCP port 993 found 0x10a275fb0

asked 30 Oct ‘14, 15:53

kevinlong206's gravatar image

kevinlong206
11112
accept rate: 0%

edited 31 Oct ‘14, 01:39

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237