Skip to main content
kwcheng__FTNT
Staff
Staff
August 6, 2024

Technical Tip: Extracting SSL Server certificate from PCAP file

  • August 6, 2024
  • 0 replies
  • 2276 views
Description

This article describes how to extract an SSL server certificate from a PCAP file.

Scope FortiGate.
Solution

Notes:

  1. The PCAP file must include the 'packet data'. Crosscheck the 'verbose' filter option when capturing the SSL handshake connection so that it includes the 'packet data'. In this example, verbose 6 is used.
  2. TLS 1.3 is not supported because it is by designed that TLS 1.3 will encrypt the server certificate. For more information, you can refer to the following link: TLS 1.3: An Overview of Benefits and Risks.
  3. The sample website used here will be 'https://badssl.com/'.
  4. Make sure Wireshark software is installed.

 

The following are the steps to extract the SSL server certificate from a PCAP file:

  1. Locate the 'Server Hello' or the data packet which has the 'certificate'. 

Locating the server certificate.png

  

  1. 'Right-click' and select 'Export packet bytes'.

     

    Export.png

     

     

  2. Select type as 'All Files' and rename as 'YourCertName.der'.

    cert name.png

     

     

  3. Once it is successful, just open the .der file to check.

    Successful.png

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!