blob: 3eded8c7cf532864db76a88ac05463512f59a4a2 [file] [log] [blame] [view]
svaldez72b40a32016-04-26 16:54:381# Debugging SSL on Linux
andybons3322f762015-08-24 21:37:092
3To help anyone looking at the SSL code, here are a few tips I've found handy.
4
andybonsad92aa32015-08-31 02:27:445[TOC]
andybons3322f762015-08-24 21:37:096
andybonsad92aa32015-08-31 02:27:447## Logging
andybons3322f762015-08-24 21:37:098
9There are several flavors of logging you can turn on.
10
svaldez72b40a32016-04-26 16:54:3811* `SSLClientSocketImpl` can log its state transitions and function calls
12 using `base/logging.cc`. To enable this, edit
13 `net/socket/ssl_client_socket_impl.cc` and change `#if 1` to `#if 0`. See
14 `base/logging.cc` for where the output goes (on Linux, usually stderr).
15
andybonsad92aa32015-08-31 02:27:4416* `HttpNetworkTransaction` and friends can log its state transitions using
17 `base/trace_event.cc`. To enable this, arrange for your app to call
18 `base::TraceLog::StartTracing()`. The output goes to a file named
19 `trace...pid.log` in the same directory as the executable (e.g.
20 `Hammer/trace_15323.log`).
andybons3322f762015-08-24 21:37:0921
andybonsad92aa32015-08-31 02:27:4422## Network Traces
andybons3322f762015-08-24 21:37:0923
andybonsad92aa32015-08-31 02:27:4424http://wiki.wireshark.org/SSL describes how to decode SSL traffic. Chromium SSL
25unit tests that use `net/base/ssl_test_util.cc` to set up their servers always
26use port 9443 with `net/data/ssl/certificates/ok_cert.pem`, and port 9666 with
27`net/data/ssl/certificates/expired_cert.pem` This makes it easy to configure
28Wireshark to decode the traffic: do
29
andybons3322f762015-08-24 21:37:0930Edit / Preferences / Protocols / SSL, and in the "RSA Keys List" box, enter
andybonsad92aa32015-08-31 02:27:4431
32 127.0.0.1,9443,http,<path to ok_cert.pem>;127.0.0.1,9666,http,<path to expired_cert.pem>
33
andybons3322f762015-08-24 21:37:0934e.g.
andybonsad92aa32015-08-31 02:27:4435
36 127.0.0.1,9443,http,/home/dank/chromium/src/net/data/ssl/certificates/ok_cert.pem;127.0.0.1,9666,http,/home/dank/chromium/src/net/data/ssl/certificates/expired_cert.pem
37
andybons3322f762015-08-24 21:37:0938Then capture all tcp traffic on interface lo, and run your test.