How to use scapy to decrypt TLS traffic read from pcap file?

Viewed 238

I want to decrypt TLS traffic in a pcap file using scapy by providing the keylog file (containing client random) recorded with openssl's -keylogfile. I found this documentation page says

if you got a master_secret somehow, use it with tls_session.(w|r)cs.derive_keys() and leave the rest to Scapy

But it's not clear to me how to use it with the keylog file.

I know Wireshark can import the keylogfile and decrypt the traffic. But I want to write some script to analyze the decrypted traffic instead of looking at the GUI manually.

I also tried to export the decrypted traffic from Wireshark so that scapy can use it directly. But it seems that Wireshark can only export the original encrypted traffic.

Could someone give me some suggestions? Thanks in advance.

0 Answers
Related