# handshake ssl

**URL:** <https://community.zeek.org/t/handshake-ssl/5585>\
**Category:** Zeek\
**Created:** [January 17, 2019, 11:03am UTC](https://community.zeek.org/t/handshake-ssl/5585 "2019-01-17T11:03:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rober\_Fernandez](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@Rober\_Fernandez](https://community.zeek.org/u/Rober_Fernandez)\
**Post date:** [January 17, 2019, 11:03am UTC](https://community.zeek.org/t/handshake-ssl/5585/1 "2019-01-17T11:03:16Z")

</div>

1. Question

i would like obtain the bytes related with the field certificates, but i don’t see any event to get it.

Attach a wireshark image with the field underlined.

1. Question

There is a way to extract exclusively the payload generate in each packet of the ssl handshake?  
for example

```auto
      struct {
          ProtocolVersion client_version;
          Random random;
          SessionID session_id;
          CipherSuite cipher_suites<2..2^16-2>;
          CompressionMethod compression_methods<1..2^8-1>;
          select (extensions_present) {
              case false:
                  struct {};
              case true:
                  Extension extensions<0..2^16-1>;
          };
      } ClientHello;

```

```auto
all bytes of this struct of Client Hello.

```

![certificate.png](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/d41560e21257d3d873c6d937d07a49bcf7e5fd5b.png)

---

<div class="post-metadata">

**Author:** ![Rober\_Fernandez](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@Rober\_Fernandez](https://community.zeek.org/u/Rober_Fernandez)\
**Post date:** [January 17, 2019, 11:04am UTC](https://community.zeek.org/t/handshake-ssl/5585/2 "2019-01-17T11:04:07Z")

</div>

1. Question

i would like obtain the bytes related with the field certificates, but i don’t see any event to get it.

Attach a wireshark image with the field underlined.

1. Question

There is a way to extract exclusively the payload generate in each packet of the ssl handshake?  
for example

```auto
      struct {
          ProtocolVersion client_version;
          Random random;
          SessionID session_id;
          CipherSuite cipher_suites<2..2^16-2>;
          CompressionMethod compression_methods<1..2^8-1>;
          select (extensions_present) {
              case false:
                  struct {};
              case true:
                  Extension extensions<0..2^16-1>;
          };
      } ClientHello;

```

```auto
all bytes of this struct of Client Hello.

```

![certificate.png](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/d41560e21257d3d873c6d937d07a49bcf7e5fd5b.png)

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [January 17, 2019, 3:35pm UTC](https://community.zeek.org/t/handshake-ssl/5585/3 "2019-01-17T15:35:21Z")

</div>

Hi Rober,

> 1. Question  
> i would like obtain the bytes related with the field certificates, but i  
> don't see any event to get it.
> 
> Attach a wireshark image with the field underlined.

You cannot get at the data for the field certificated directly; however you can get all of the individual certificates. The easiest way to get to them is through the event x509\_certificate - [https://www.zeek.org/sphinx/scripts/base/bif/plugins/Bro\_X509.events.bif.bro.html#id-x509\_certificate](https://www.zeek.org/sphinx/scripts/base/bif/plugins/Bro_X509.events.bif.bro.html#id-x509_certificate). That event gets the parsed out certificate data + an opaque of type x509. You can use the x509\_get\_certificate\_string function to get the ASN.1 representation of the individual certificates out of that,

> 2. Question  
> There is a way to extract exclusively the payload generate in each packet  
> of the ssl handshake?  
> for example
> 
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;struct {  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ProtocolVersion client\_version;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Random random;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;SessionID session\_id;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;CipherSuite cipher\_suites\<2..2^16-2\>;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;CompressionMethod compression\_methods\<1..2^8-1\>;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;select (extensions\_present) {  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;case false:  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;struct {};  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;case true:  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Extension extensions\<0..2^16-1\>;  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;};  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;} ClientHello;
> 
> all bytes of this struct of Client Hello.

No, there is no way to get the payload for each packet in the handshake. That being said, there is an different event for I think every single event in the handshake that gets the parsed out information; in this case it would be ssl\_client\_hello and the different extension events.

Is there a reason why you want the raw data and not access to the parsed information?

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/handshake-ssl/5585/4 "2022-05-06T15:46:17Z")

</div>


