Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Decrypt TLS browser traffic with Wireshark

From Tech-Wiki


Decrypt browser TLS sessions in Wireshark by providing per-session secrets through a TLS key log file.

ⓘ
Validation status
Reviewed against the current Wireshark User's Guide and Wireshark TLS documentation on 27 September 2026.
!
TLS key log files contain sensitive session secrets
Anyone with the relevant packet capture and matching TLS session secrets may be able to decrypt the captured sessions. Store key log files securely, share them only when necessary and remove them when the troubleshooting activity is complete.

How key-log decryption works

Wireshark supports TLS decryption using a key log file containing per-session secrets. Applications such as Firefox, Chrome and curl can generate this file when the SSLKEYLOGFILE environment variable is set.

The key-log method works with modern TLS key exchanges and is generally preferable to attempting decryption with a server RSA private key.

Configure the browser

The environment variable must be present when the browser process starts. Fully close existing browser processes before launching a new instance for the capture.

Windows PowerShell

>_Set SSLKEYLOGFILE for the current PowerShell session
$env:SSLKEYLOGFILE="$env:USERPROFILE\tls-keys.log"

Launch the browser from that PowerShell session so it inherits the environment variable.

Linux and macOS shell

>_Set SSLKEYLOGFILE for the current shell session
export SSLKEYLOGFILE="$HOME/tls-keys.log"

Launch the browser from the same shell session.

Configure Wireshark

  1. Open Edit → Preferences.
  2. Expand Protocols and select TLS.
  3. Set (Pre)-Master-Secret log filename to the generated key log file.
  4. Capture or open the packet trace containing the matching TLS session.

When matching secrets are available, Wireshark can dissect the decrypted application data supported by the protocol stack.

✓
Start with a fresh browser process
If the key log file remains empty, confirm that every existing browser process was closed before starting the browser from the environment where SSLKEYLOGFILE was set.

Sharing captures

Wireshark can export known TLS session keys and can also inject TLS secrets into capture formats that support decryption-secret blocks, such as pcapng.

Treat any capture containing embedded TLS secrets as sensitive data.

Official references

See also