Wireshark mailing list archives

Re: Embed SSL keylog file in pcap-ng


From: Guy Harris <guy () alum mit edu>
Date: Sat, 5 May 2018 02:19:07 -0700

On May 5, 2018, at 2:07 AM, Ahmad Fatoum <ahmad () a3f at> wrote:

On 5May 2018, at 10:47, Guy Harris <guy () alum mit edu> wrote:

That doesn't require "some authority that allocates protocol identifiers", because it doesn't require protocol 
identifiers; all that needs to be done is to allocate pcapng block types to those protocols that require some 
additional information to decrypt its traffic.

I like the idea of a "universal"  key pcapng block more than requiring each interested protocol to request its own 
block.

Each protocol's key format has to be documented, to allow arbitrary programs to use the block, so they'll have to 
request it *anyway*, supplying the key format as part of the request.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: