Wireshark-users: [Wireshark-users] Wireshark compatibility with A10Networks axdebug pcapng TLS se

From: Peschel Frank <Frank.Peschel@xxxxxxxxxx>
Date: Mon, 13 Nov 2023 20:55:41 +0000

Hello,

 

some machines from A10Networks support packet capturing to pcapng including the tls session secrets with their “axdebug capture” commands.

 

In contrast to injecting the key material afterwards for example from an sslkeylogfile the key material is scattered all over the file.

I guess that is the reason why decryption only works fine for me after reloading LUA ([Ctrl]-[Shift]-L).

I used Wireshark 4.0.10 x64 on Windows 10 and 11 .

 

Before pressing [Ctrl]-[Shift]-L :
cid:image001.png@01D9DEAD.CCF58050

 

AFTER pressing [Ctrl]-[Shift]-L :

cid:image002.png@01D9DEAD.CCF58050

 

You may have a look at the attached file.

Looking forward to hearing from you.


Freundliche Grüße / Best regards

Frank Peschel
Informationssicherheitsbeauftragter
IT Management

Management Services Helwig Schmitt GmbH
Garnisonstr. 12, 34369 Hofgeismar, Germany
Tel: +49-5671-5085-852
www.manserv.com

Commercial register: Amtsgericht Kassel HRB 9217
Registered office: Hofgeismar
Managing Director: Andreas Schmitt
Data protection information

Attachment: 20230903T1846Z with injected secrets.pcapng
Description: 20230903T1846Z with injected secrets.pcapng