Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Embed SSL keylog file in pcap-ng

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Fri, 18 May 2018 18:36:13 -0700
On May 18, 2018, at 6:08 PM, Ben Higgins <ben@xxxxxxxxxxxx> wrote:

> Sounds like it'd still be fine for there to be multiple keylog blocks,

Yes.

> but, as you say, they must occur before any packets that require the secrets contained therein. Is that correct?

Yes.