2026-09-23 11:38 UTC
If you need to debug TLS encrypted connections: A lot of software supports the SSLKEYLOGFILE environment variable. Software will write its TLS keys into the given file. Wireshark can load this file and present you all the packets decrypted.
Replies (1)
-
@mildsunrise@tech.lgbt 2026-09-23 13:21
@varbin@infosec.exchange fun story: i wanted Node.js to have SSLKEYLOGFILE support as well. found there was discussion where the Node.js devs were overwhelmingly against the feature because they thought of it as a security risk. I disagreed but I wasn't involved in the project, so I figured I'd just expose the API. but then, another core dev used the API to implement a CLI option --tls-keylog and no one objected... even though CLI options can be passed through the NODE_OPTIONS environment variable. sooooo we ended up having the same functionality we were supposedly afraid of (an env var that causes keys to be dumped) just without the standard SSLKEYLOGFILE name :neofox: