[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #96 from Gerrit Code Review  ---
Change 26993 merged by Anders Broman:
QUIC: implement PATH_CHALLENGE and PATH_RESPONSE frames (draft-10)

https://code.wireshark.org/review/26993

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #95 from Gerrit Code Review  ---
Change 26992 merged by Anders Broman:
QUIC: initial draft-10 decryption support

https://code.wireshark.org/review/26992

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14180] Add range capability to "in" display filters

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14180

--- Comment #6 from Gerrit Code Review  ---
Change 26945 merged by Anders Broman:
dfilter: add range support to set membership operator ("f in {x .. y}")

https://code.wireshark.org/review/26945

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #94 from Gerrit Code Review  ---
Change 26993 had a related patch set uploaded by Peter Wu:
QUIC: implement PATH_CHALLENGE and PATH_RESPONSE frames (draft-10)

https://code.wireshark.org/review/26993

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

Peter Wu  changed:

   What|Removed |Added

  Attachment #16267|0   |1
is obsolete||

--- Comment #93 from Peter Wu  ---
Created attachment 16268
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=16268=edit
QUIC draft-10 (ngtcp2 client and server) - keys in comment 93

Same commands as in comment 93, but this time with a keylog that actually has
exporter secrets. Only the handshake of the previous capture could be
decrypted, for the protected packets, the EXPORTER_SECRET key is actually
required.

Using openssl 7c7fd678c93eb1c5ba44e98f606c92242b96581c
(https://github.com/openssl/openssl/pull/5702) with EXPORTER_SECRET keylogging
support.

TLS cipher for ngtcp2-10.pcap: AES256-GCM-SHA384

handshake_secret=fdf5f1701950fc85eda154a231776f10fac217b9c0a57ac3acdb5564426b841e
client_hs_secret=800a90444fe36216b9fd68c9bc6239806adbe35a616ece4f7de045ea1d865e90
+ client_pp_key=09af2e887e2631eb834bcb1e9e640448
+ client_pp_iv=b0ca4c184a73f81089e1e762
server_hs_secret=b6b85e5880197d86fcebff2d42423583212f9300335a82bf449a476b9880187b
+ server_pp_key=71bbfa039e008104acd5bbfd61f66144
+ server_pp_iv=8c7ef203e5c761d2cb19554d

client_1rtt_secret=21b00ac3b0864de4d47c6c502ba31d827eef0fc12fff3233ed9f0d6843cf2ec34f9b56c487171f6c3ec2d69ccd7cd83a
+
client_pp_key=9dcb09d17c9244f04aafdd647d46e202182d98e7d7758641b71b3240dd03fd9d
+ client_pp_iv=5ab08ab06c219b5061753579
server_1rtt_secret=c25b38de0fe0bce0dc492b9ea1360c3eef80a4c7ac851425af8a509606714daa4482d682324affb4fc037d32da8b3f7e
+
server_pp_key=59277236f9ff006a69d20795a7fd33bdd09a3bbf1f22c4db106b9de464838996
+ server_pp_iv=4c7e34ce2784f11fdaaebd61


TLS key log file:
SERVER_HANDSHAKE_TRAFFIC_SECRET
e1a95b892115502107fa47c21e734c3856578563f020b228f04355e3cf7daa66
6fcaa2b57cfba88dad14c3ead27dab01d915ab071637eb030a49f7dd86623ed22413854d4523483e9bbfb508817114e4
EXPORTER_SECRET
e1a95b892115502107fa47c21e734c3856578563f020b228f04355e3cf7daa66
7304b4e438f6087d5f48b7c0e55d79b18c870a7b2b2a38fde53c086785741ae3880b48e429e73d20590d37cead08a353
SERVER_TRAFFIC_SECRET_0
e1a95b892115502107fa47c21e734c3856578563f020b228f04355e3cf7daa66
1da1ac04bdfa20e7cb48fb93471d12a0717aca022d60f1a93d4a0c0354fce5c7a097b183089e4857f2c2737d6cf873ea
CLIENT_HANDSHAKE_TRAFFIC_SECRET
e1a95b892115502107fa47c21e734c3856578563f020b228f04355e3cf7daa66
02aecb2a1388a35cc35e26e2c4c7e213cc08184e58808569184613f494824adc823252190c6f45f8f25f9fb8bdb00f98
CLIENT_TRAFFIC_SECRET_0
e1a95b892115502107fa47c21e734c3856578563f020b228f04355e3cf7daa66
cb3799ed3e213517c135d7096dd18e26a76404d0ec4b54b55367f80aa98a00c83b0d5ca7b3ce8ed70283f8175d5c2305

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #92 from Gerrit Code Review  ---
Change 26992 had a related patch set uploaded by Peter Wu:
QUIC: initial draft-10 decryption support

https://code.wireshark.org/review/26992

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

Peter Wu  changed:

   What|Removed |Added

  Attachment #16267|QUIC draft-09 (ngtcp2   |QUIC draft-10 (ngtcp2
description|client and server) - keys   |client and server) - keys
   |in comment 89   |in comment 89

--- Comment #91 from Peter Wu  ---
Comment on attachment 16267
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=16267
QUIC draft-10 (ngtcp2 client and server) - keys in comment 89

Yes it was a copy/paste typo, the capture is really draft 10.

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #90 from Alexis La Goutte  ---
(In reply to Peter Wu from comment #89)
> Created attachment 16267 [details]
> QUIC draft-09 (ngtcp2 client and server) - keys in comment 89
> 
Typo ? Draft-10?

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 13881] Add (IETF) QUIC Dissector

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13881

--- Comment #89 from Peter Wu  ---
Created attachment 16267
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=16267=edit
QUIC draft-09 (ngtcp2 client and server) - keys in comment 89

client and server commands are similar to comment 61 and comment 77:

./server '*' 4433 server.pem server.pem
SSLKEYLOGFILE=ngtcp2-10.keys ./client 10.9.0.2 443 -s

ngtcp2 master: a9dedc2afcb33987c57bf4ead72685c84c1ea7c4
OpenSSL master: OpenSSL_1_1_1-pre3-79-ga73d990e2b

TLS cipher for ngtcp2-10.pcap: AES256-GCM-SHA384

handshake_secret=71987b0f7211f4702ea88f7675888b9647bce85593d6cef5eab28b619210f985
client_hs_secret=2dfa646f82760e0eeaf6b1ca788929a11782a7677b43a1498e459ea20af77387
+ client_pp_key=a6a022292d67a2ee2bc2d3409d9ee850
+ client_pp_iv=34f53c346f98c67d3aeb1aa5
server_hs_secret=652ac916acdc2c8e20568f6a32c8cb4aec4ad855992d64dcade7b5c62ef0
+ server_pp_key=e3780f2a97005a7e7a6d8ef612058678
+ server_pp_iv=40f98b289bc4b1c4af1b9a16

client_1rtt_secret=cbdd9eb3329ef051095d5d8d2353bc0de2c454cb3d39d6c989c6c33b9ec579e80c67deef2c453a65b0af7acd152ec3b4
+
client_pp_key=ecb90a5ba141122eabbe2920208a5a5f2b35935f0ad098f31bc64c32d5e72017
+ client_pp_iv=1d5612efbe36ba9ffdf4c74d
server_1rtt_secret=ec772b7d3a4a2c7b0a03d53a417e3defd8f62d9b989147d546bf9d9fcaedaeb405bd373b7727ceeeb17047e7dbfc9bd9
+
server_pp_key=9bfbf5ebe3c597710637a95d5b6161bb389c4475de6225c32f8ab80adbaebf4b
+ server_pp_iv=16d5feef24472cbe90f7db41


TLS key log file:
SERVER_HANDSHAKE_TRAFFIC_SECRET
cb49a83ed8e5d439bb09cd0fa864f5ff82c84f0f61c5078ee3d09f4a34c19a6c
981f32c74f9b0e90d483086f9a2252e649e862be27d404e91ff005ea94d713f625afff32d797cb8f0b6fa2e970e67967
SERVER_TRAFFIC_SECRET_0
cb49a83ed8e5d439bb09cd0fa864f5ff82c84f0f61c5078ee3d09f4a34c19a6c
6496de10b0403f13060b9c7c36ba3f6550e259ff6ab7b58aba3232e8c13d8cbb3bd70ee41ebed3aa3e586c941429bc6d
CLIENT_HANDSHAKE_TRAFFIC_SECRET
cb49a83ed8e5d439bb09cd0fa864f5ff82c84f0f61c5078ee3d09f4a34c19a6c
b456c2f15b4509c52bfb0e75d536e35a1ed1ca2635b4b0e3c842d2c3c7c7730596987459a0b8c374135f031cac092f02
CLIENT_TRAFFIC_SECRET_0
cb49a83ed8e5d439bb09cd0fa864f5ff82c84f0f61c5078ee3d09f4a34c19a6c
1de531f55fc22eeb8a4ead6c0da004e5870ae208cbd299f57bb34ed4639fc3f3d1b60813b34527c2beafead5c296d614

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #17 from Pascal Quantin  ---
Harald,

can we close the bug despite the Ping-Bug tag in Git commit message instead of
Bug? Or do you want to keep it open for a long term solution?

Thanks,
Pascal.

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #16 from Gerrit Code Review  ---
Change 26984 had a related patch set uploaded by Pascal Quantin:
lapdm: Hand B4 frames into a dissector supporting L2 pseudo-length

https://code.wireshark.org/review/26984

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #15 from Gerrit Code Review  ---
Change 26983 had a related patch set uploaded by Pascal Quantin:
lapdm: Hand B4 frames into a dissector supporting L2 pseudo-length

https://code.wireshark.org/review/26983

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #14 from Gerrit Code Review  ---
Change 26982 had a related patch set uploaded by Pascal Quantin:
rsl: Fix treatment of SACCH FILL / SACCH INFO MODIFY

https://code.wireshark.org/review/26982

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #13 from Gerrit Code Review  ---
Change 26981 had a related patch set uploaded by Pascal Quantin:
rsl: Fix treatment of SACCH FILL / SACCH INFO MODIFY

https://code.wireshark.org/review/26981

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

[Wireshark-bugs] [Bug 14105] gsmtap: SACCH/SDCCH dissection has changed between 2.2.7 and 2.4.1

2018-04-17 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14105

--- Comment #12 from Harald Welte  ---
I presume everyone just has way too much work on their plate already and hence
patches haven't received any review so far.

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe