SSLKEYLOGFILE
Definition
A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as connections are established. When this file is captured alongside a packet capture, tools such as Wireshark can use the keys to decrypt the recorded sessions. Legitimate use requires access to the endpoint generating the traffic.
- Origin
- Firefox, later adopted by Chrome and others
- Content
- Logs TLS session keys as connections form
- Used with
- Packet capture, decrypted in tools like Wireshark
- Requirement
- Access to the traffic-generating endpoint
Common questions
Why is SSLKEYLOGFILE useful in a forensic network investigation?+
When an analyst has legitimate access to the endpoint and can capture this file alongside a packet capture, it allows encrypted session content to be decrypted for review without breaking TLS or needing the server's private key.
Can SSLKEYLOGFILE decrypt traffic captured after the fact from an uncooperative endpoint?+
No, the file only logs keys for sessions the browser or application actively establishes while logging is enabled, so it cannot retroactively decrypt traffic captured before the endpoint was configured to produce it.
Related terms
- Flow Record
- A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count...
- JA3 Fingerprint
- An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
- Server Name Indication (SNI)
- A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
- SSL Inspection (TLS Interception)
- A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
- Traffic Fingerprinting
- The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...