First time here? Check out the FAQ!
THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.
0

Why is the TLS1.2 Server Hello not recognized?

Got a capture that contains a Server Hello but it is not recognized by wireshark image description

Tried various settings in TCP and TLS protocol without success so far

Would appreciate your thoughts... Regards Matthias

mrEEde's avatar
4k
mrEEde
asked 2019-07-11 20:07:09 +0000, updated 2019-07-12 03:58:19 +0000
edit flag offensive 0 remove flag close merge delete

Comments

add a comment see more comments

1 Answer

2

The Server Hello, Server Certificate and server Hello Done messages are in 3 TCP segments, frames 6, 7 & 9.

You need to have the TCP preference "Allow subdissector to reassemble TCP streams" enabled.

grahamb's avatar
23.8k
grahamb
answered 2019-07-11 20:30:41 +0000
edit flag offensive 0 remove flag delete link

Comments

That one I already had checked. It was the TLS preference Reassemble TLS records spanning multiple TCP segments that needed to be checked Thanks

mrEEde's avatar mrEEde (2019-07-12 03:56:54 +0000) edit
add a comment see more comments

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account. This space is reserved only for answers. If you would like to engage in a discussion, please instead post a comment under the question or an answer that you would like to discuss.

Add Answer