Decrypt TLS browser traffic with Wireshark
More actions
Decrypt browser TLS sessions in Wireshark by providing per-session secrets through a TLS key log file.
How key-log decryption works
Wireshark supports TLS decryption using a key log file containing per-session secrets. Applications such as Firefox, Chrome and curl can generate this file when the SSLKEYLOGFILE environment variable is set.
The key-log method works with modern TLS key exchanges and is generally preferable to attempting decryption with a server RSA private key.
Configure the browser
The environment variable must be present when the browser process starts. Fully close existing browser processes before launching a new instance for the capture.
Windows PowerShell
$env:SSLKEYLOGFILE="$env:USERPROFILE\tls-keys.log"
Launch the browser from that PowerShell session so it inherits the environment variable.
Linux and macOS shell
export SSLKEYLOGFILE="$HOME/tls-keys.log"
Launch the browser from the same shell session.
Configure Wireshark
- Open Edit → Preferences.
- Expand Protocols and select TLS.
- Set (Pre)-Master-Secret log filename to the generated key log file.
- Capture or open the packet trace containing the matching TLS session.
When matching secrets are available, Wireshark can dissect the decrypted application data supported by the protocol stack.
SSLKEYLOGFILE was set.Sharing captures
Wireshark can export known TLS session keys and can also inject TLS secrets into capture formats that support decryption-secret blocks, such as pcapng.
Treat any capture containing embedded TLS secrets as sensitive data.