Created on
‎11-12-2023
10:14 PM
Edited on
‎01-05-2026
02:31 AM
By
Jean-Philippe_P
| Description | This article describes how to decrypt the HTTPS traffic on the client using Wireshark. While using virtual servers on FortiGate, it is sometimes necessary to decrypt the traffic on the client end to isolate the issue further. |
| Scope | Windows Client, FortiGate. |
| Solution |
Variable name: SSLKEYLOGFILE.
The steps may change when Windows or Chrome gets updated. The same steps should be valid for other internet browsers like Firefox.
Setting SSLKEYLOGFILE as a User Environment Variable causes all applications that support SSLKEYLOGFILE to log TLS keys if they are started after the variable is set, regardless of whether they are launched via GUI or CLI. This caused unnecessary SSL key logging and may be a security concern.
An alternative to this is the CLI-scoped method. Logs TLS session keys only for applications started from a particular CMD CLI.
Go to Windows CMD CLI :
> mkdir C:\chromeTLS
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.