# HTTPS Decryption

**URL:** <https://community.zeek.org/t/https-decryption/4890>\
**Category:** Zeek\
**Created:** [June 10, 2017, 2:23am UTC](https://community.zeek.org/t/https-decryption/4890 "2017-06-10T02:23:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Osama\_Elnaggar](https://avatars.discourse-cdn.com/v4/letter/o/ba8739/32.png) [@Osama\_Elnaggar](https://community.zeek.org/u/Osama_Elnaggar)\
**Post date:** [June 10, 2017, 2:23am UTC](https://community.zeek.org/t/https-decryption/4890/1 "2017-06-10T02:23:53Z")

</div>

Hi,

I noticed the issue of decrypting HTTPS was mentioned several times over the years (with the last time back in 2015 I think - [http://mailman.icsi.berkeley.edu/pipermail/bro/2015-June/008568.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2015-June/008568.html)) and was wondering if this feature was ever added or if anyone was able to successfully implement it.

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [June 10, 2017, 3:04am UTC](https://community.zeek.org/t/https-decryption/4890/2 "2017-06-10T03:04:03Z")

</div>

No, not to my knowledge. There were several people who wanted to implement  
it over the years - if someone did it, they never open-sourced it.

That being said - due to the prevalence of perfectly forward secure  
ciphers, TLS decryption is not really an option anymore in most use-cases.

Johanna

---

<div class="post-metadata">

**Author:** ![Osama\_Elnaggar](https://avatars.discourse-cdn.com/v4/letter/o/ba8739/32.png) [@Osama\_Elnaggar](https://community.zeek.org/u/Osama_Elnaggar)\
**Post date:** [June 10, 2017, 3:15am UTC](https://community.zeek.org/t/https-decryption/4890/3 "2017-06-10T03:15:28Z")

</div>

Thanks Johanna. But I was actually looking at the use case where you terminated PFS at a load balancer (or other device at the perimeter) and used upstream SSL (non PFS) to the backend servers.

Would it be possible to forward SSL packets to viewssld - [https://github.com/plashchynski/viewssld](https://github.com/plashchynski/viewssld) - and then back to Bro?

Thanks.

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [June 13, 2017, 5:05pm UTC](https://community.zeek.org/t/https-decryption/4890/4 "2017-06-13T17:05:57Z")

</div>

Oh - sorry, I misunderstood the question. In any case - no, as far as I  
know, no one has done exactly what I said in the original thread  
(stripping encryption while keeping the framing intact). That would need  
modifications to Bro; nothing changed since the thread you linked to.

I don't jnow viewssld; if it outputs just a decrypted HTTP stream, Bro  
will pick it up by itself. There are a number of people that just use Bro  
behind a SSL terminator, which is kind of similar conceptually. If it  
outputs some other format, you will have to adjust the Bro protocol  
parsers.

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/https-decryption/4890/5 "2022-05-06T15:45:02Z")

</div>


