Tobias Brunner
875813c055
save-keys: Fix length of AES-GCM with 12-byte ICV
2021-02-23 17:28:46 +01:00
Michał Skalski
b6b8880340
save-keys: Add support for full-length HMAC-SHA256 for ESP
...
Wireshark doesn't really support it, but this way it at least decodes
the ESP packets correctly and the encryption keys are saved and the
packets can be decrypted. The full-length versions of SHA-384 and
SHA-512 are not supported by Wireshark as 256-bit is the longest ICV
it is able to decode currently.
2021-02-23 17:28:46 +01:00
Tobias Brunner
bac71410f3
save-keys: Add warning message to log if keys are being saved
2018-02-15 23:03:29 +01:00
Tobias Brunner
1da1ba01c4
save-keys: Add options to enable saving IKE and/or ESP keys
2018-02-15 23:03:29 +01:00
Codrut Cristian Grosu
88e151d10d
save-keys: Store derived CHILD_SA keys in Wireshark format
2018-02-15 23:03:29 +01:00
Codrut Cristian Grosu
4be7db5f60
save-keys: Store derived IKE_SA keys in Wireshark format
...
The path has to be set first, otherwise, nothing is done.
2018-02-15 23:03:29 +01:00
Codrut Cristian Grosu
345cd4684c
save-keys: Add save-keys plugin
...
This plugin will export IKE_SA and CHILD_SA secret keys in the format used
by Wireshark.
It has to be loaded explicitly.
2018-02-15 23:03:29 +01:00