sngrep's TLS decryption supports only TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA and TLS_RSA_WITH_AES_256_GCM_SHA384, using a server private key given with -k (--keyfile), and needs the initial handshake in the capture.
Checked 2026-09-24
- Vendor
- Irontec
- Product
- sngrep
- Subsystem
- TLS decryption
- Deployment
- on-premises
- Region
- not restricted
- Release range
- 1.8.x as of 2026-09-24
- Checked
- 2026-09-24
Sources
- sngrep Wiki: Home — Irontec (GitHub wiki) · tier 3 vendor-maintained repositories · Wiki home, TLS support section
Cite this note
APA
WarmTransfer. (2026, September 24). SIP capture and analysis with Wireshark and sngrep and HOMER: source note sip-capture-analysis-sngrep-tls-ciphers. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-capture-analysis-sngrep-tls-ciphers
BibTeX
@misc{warmtransfer-claim-sip-capture-analysis-sngrep-tls-ciphers,
title = {SIP capture and analysis with Wireshark and sngrep and HOMER: source note sip-capture-analysis-sngrep-tls-ciphers},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-capture-analysis-sngrep-tls-ciphers},
note = {Source note sip-capture-analysis-sngrep-tls-ciphers, checked 2026-09-24}
}