Decrypting TLS would be possible in two scenarios:
- You have access to the server’s private key and you constrain the negotiated cipher suites to ensure the key exchange does not use (EC)DHE, or
- You write the master secret for the session you want to decode to a file
This last option can work both on the server side (if you control the server) or on the client side (using Erlang’s :ssl.connection_information(socket, [:client_random, :master_secret]).
But there is an easier way: use Erlang’s tracing functionality, e.g. using :dbg or some higher level abstraction such as recon:
iex(1)> :dbg.tracer()
{:ok, #PID<0.258.0>}
iex(2)> :dbg.p(:all, :call)
{:ok, [{:matched, :nonode@nohost, 119}]}
iex(3)> :dbg.tp({Mint.Core.Transport.SSL, :send, :_}, :cx)
{:ok, [{:matched, :nonode@nohost, 1}, {:saved, :cx}]}
iex(4)> {:ok, response} = Mojito.request(method: :get, url: "https://github.com")
(<0.269.0>) call 'Elixir.Mint.Core.Transport.SSL':send({sslsocket,{gen_tcp,#Port<0.6>,tls_connection,undefined},
[<0.303.0>,<0.302.0>]},[[<<"GET">>,32,<<"/">>,<<" HTTP/1.1\r\n">>],
[[[<<>>,<<"content-length">>,<<": ">>,<<"0">>,<<"\r\n">>],
<<"host">>,<<": ">>,<<"github.com">>,<<"\r\n">>],
<<"user-agent">>,<<": ">>,<<"mint/1.0.0">>,<<"\r\n">>],
<<"\r\n">>,<<>>]) ({'Elixir.Mint.HTTP1',request,5})
(<0.269.0>) returned from 'Elixir.Mint.Core.Transport.SSL':send/2 -> ok
{:ok,
%Mojito.Response{...}
It takes a second to spot the actual request data in the output and perhaps reformat it, but it is much easier than setting up TLS decoding ![]()






















