ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 2804] most capture filters are inoperative when sniffing w

Date: Thu, 15 Apr 2010 15:02:42 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2804

--- Comment #4 from Jeff Morriss <jeff.morriss.ws@xxxxxxxxx> 2010-04-15 15:02:41 PDT ---
Where does the decryption happen then?  Does it make sense to use capture
filters at all?

(Right now capture filters are pretty simple for us: give them to *pcap and let
them do their magic.  Re-implementing capture filters in, yikes, dumpcap sounds
scary to me.  Or can we decrypt the packet then hand it back to *pcap to run
the filter on it?  But even that assumes dumpcap even has the magic to do the
decryption, which I don't think it does.  If *shark has to decrypt the packet,
well, what's the point, just use a display filter.)

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.