Wireshark mailing list archives

HTTP spanning multiple TLS records


From: Dmitry Bugrimenko <dmitry.bugrimenko () gmail com>
Date: Wed, 27 Jun 2012 12:20:18 +0400

Hi,

HTTP GET request spanning multiple TLS records within same TCP segment
in one packet is decoded by Wireshark 1.8.0 (SVN Rev 43431 from
/trunk-1.8, running on Mac OS X 10.6.8 or Windows 7 64-bit) as
"Continuation of non-HTTP traffic", HTTP decode in packet details pane
is per record not for entire request. Sample trace, session key,
decoded text output are attached.

Is this a bug or expected behavior?

Thanks,
Dmitry.

Attachment: NASC5515A_TLSv1_RSA_with_reuse_FFox__cut_12.txt
Description:

Attachment: NASC5515A_TLSv1_RSA_with_reuse_FFox.key
Description:

Attachment: NASC5515A_TLSv1_RSA_with_reuse_FFox__cut_1-13.pcap
Description:

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: