Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Decoding TLS H.323 calls

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Sat, 05 Nov 2011 12:02:34 +0100
Hi,

No, that's not a known issue.

Lets have a look at the protocol layers.
Frame
Ethernet
IP
TCP
SSL
TPKT
Q.931
H.225.0

Does this correspond to what you see?

Thanks,
Jaap


On Wed, 2 Nov 2011 16:51:22 +0100, Alexander Nenov wrote:

Hello All ,

When decoding TLS (H.323) calls in Version 1.6.2, having the private key
from the certificate, I partly succeed - H.245 is OK, but H.225.0 is
malformed - as I see it, the Q.931 part is "ignored" and there is
attempt
to decode the whole data part as H.225.0 UUI.
Is that a known issue?

_Kind regards_
__
_ Alexander Nenov_