Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] ssl decryption question

From: Tatar Kolos <kolos@xxxxxxxx>
Date: Wed, 6 Dec 2006 16:22:47 +0100 (CET)
Hi,

Can anyone tell me what kind of problem is described in this ssldebug.log file?

Thanks,
Kolos

[..]
dissect_ssl enter frame #26
dissect_ssl3_record: content_type 23
association_find: TCP port 1024 found (nil)
association_find: TCP port 8181 found 0x91da478
dissect_ssl enter frame #15
ssl_session_init: initializing ptr 0xb2d2cb18 size 568
association_find: TCP port 1024 found (nil)
packet_from_server: is from server 0
dissect_ssl server 172.31.96.207:8181
dissect_ssl3_record: content_type 22
decrypt_ssl3_record: app_data len 77 ssl state 0
decrypt_ssl3_record: no session key
dissect_ssl3_handshake iteration 1 type 1 offset 5 length 73 bytes, remaining 82
dissect_ssl3_hnd_hello_common found random state 1
dissect_ssl enter frame #17
dissect_ssl3_record: content_type 22
decrypt_ssl3_record: app_data len 1085 ssl state 11
decrypt_ssl3_record: no session key
dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 1090
dissect_ssl3_hnd_hello_common found random state 13
dissect_ssl3_hnd_srv_hello found cipher 16, state 17
dissect_ssl3_hnd_srv_hello not enough data to generate key (required 37)
dissect_ssl3_handshake iteration 0 type 11 offset 79 length 606 bytes, remaining 1090
dissect_ssl3_handshake iteration 0 type 12 offset 689 length 393 bytes, remaining 1090
dissect_ssl3_handshake iteration 0 type 14 offset 1086 length 0 bytes, remaining 1090
dissect_ssl enter frame #19
dissect_ssl3_record: content_type 22
decrypt_ssl3_record: app_data len 134 ssl state 17
decrypt_ssl3_record: no session key
dissect_ssl3_handshake iteration 1 type 16 offset 5 length 130 bytes, remaining 139
dissect_ssl3_handshake found SSL_HND_CLIENT_KEY_EXCHG state 17
ssl_decrypt_pre_master_secret key 17 diferent from KEX_RSA(16)
dissect_ssl3_handshake can't decrypt pre master secret
dissect_ssl3_record: content_type 20
dissect_ssl3_change_cipher_spec
dissect_ssl3_record: content_type 22
decrypt_ssl3_record: app_data len 40 ssl state 17
decrypt_ssl3_record: no session key
dissect_ssl3_handshake iteration 1 type 97 offset 150 length 10209886 bytes, remaining 190
dissect_ssl enter frame #22
dissect_ssl3_record: content_type 20
dissect_ssl3_change_cipher_spec
[..]