Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Embed SSL keylog file in pcap-ng

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Sat, 5 May 2018 02:19:07 -0700
On May 5, 2018, at 2:07 AM, Ahmad Fatoum <ahmad@xxxxxx> wrote:

>> On 5May 2018, at 10:47, Guy Harris <guy@xxxxxxxxxxxx> wrote:
>> 
>> That doesn't require "some authority that allocates protocol identifiers", because it doesn't require protocol identifiers; all that needs to be done is to allocate pcapng block types to those protocols that require some additional information to decrypt its traffic.
> 
> I like the idea of a "universal"  key pcapng block more than requiring each interested protocol to request its own block.

Each protocol's key format has to be documented, to allow arbitrary programs to use the block, so they'll have to request it *anyway*, supplying the key format as part of the request.