Debugging SSL on Linux
Posted Bigben
tags:
篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了Debugging SSL on Linux相关的知识,希望对你有一定的参考价值。
Debugging SSL on Linux
To help anyone looking at the SSL code, here are a few tips I‘ve found handy.
Contents
Logging
There are several flavors of logging you can turn on.
-
SSLClientSocketImpl
can log its state transitions and function calls usingbase/logging.cc
. To enable this, editnet/socket/ssl_client_socket_impl.cc
and change#if 1
to#if 0
. Seebase/logging.cc
for where the output goes (on Linux, usually stderr). -
HttpNetworkTransaction
and friends can log its state transitions usingbase/trace_event.cc
. To enable this, arrange for your app to callbase::TraceLog::StartTracing()
. The output goes to a file namedtrace...pid.log
in the same directory as the executable (e.g.Hammer/trace_15323.log
).
Network Traces
http://wiki.wireshark.org/SSL describes how to decode SSL traffic. Chromium SSL unit tests that use net/base/ssl_test_util.cc
to set up their servers always use port 9443 with net/data/ssl/certificates/ok_cert.pem
, and port 9666 with net/data/ssl/certificates/expired_cert.pem
This makes it easy to configure Wireshark to decode the traffic: do
Edit / Preferences / Protocols / SSL, and in the “RSA Keys List” box, enter
127.0.0.1,9443,http,<path to ok_cert.pem>;127.0.0.1,9666,http,<path to expired_cert.pem>
e.g.
127.0.0.1,9443,http,/home/dank/chromium/src/net/data/ssl/certificates/ok_cert.pem;127.0.0.1,9666,http,/home/dank/chromium/src/net/data/ssl/certificates/expired_cert.pem
Then capture all tcp traffic on interface lo, and run your test.
以上是关于Debugging SSL on Linux的主要内容,如果未能解决你的问题,请参考以下文章
linux device drivers - debugging之proc
setting up kernel debugging on a vmworkstation virtual machine
在windows上调试 | Debugging on Windows (Guides: Development) – Electron 中文开发手册 - Break易站
Linux Debugging 一次生产环境下的“内存泄露”
Unity中解决“SetDestination“ can only be called on an active agent that has been placed on a NavMesh(代码片