How to decrypt RADIUS traffic using Wireshark with RSA Authentication Manager
Originally Published: 2017-05-19
Article Number
Applies To
RSA Product/ Service Type: Authentication Manager
RSA Version/Condition: 7.x, 8.1, 8.0, 8.1
Issue
Resolution
You must know the RADIUS shared secret used in order to decrypt the packets.
You can follow the below steps to be able to decrypt the Radius Packets:
- Capture RADIUS authentication traffic. See Using tcpdump to troubleshoot authentication issues with RSA Authentication Manager 8.x for more information.
- Launch the Wireshark app.
- Open the capture of of the RADIUS traffic, typically in .pcap format.
- Go to Edit > Preferences.
- Click the + next to Protocols to expand the tree.
- Scroll down and select RADIUS.
- Key in the RADIUS shared secret and click Apply.
- The passcode in clear text.
The packet capture before entering the RADIUS shared secret:
The packet capture after entering the RADIUS shared secret:
Related Articles
Error "System was modified beyond the allowed threshold, cannot decrypt" on RSA Authentication Manager 8.x 337Number of Views RADIUS shared secret limitations of RADIUS clients configured with RSA Authentication Manager 753Number of Views RSA Authentication Manager 8.4 Patch 11 Readme 14Number of Views RSA Authentication Manager 8.x fails to process RADIUS authentication requests from NPS 44Number of Views gpg: no valid OpenPGP data found. gpg: decrypt_message failed eof 15Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process Workflows stuck in AFX fulfillment and/or Provisioning nodes in RSA Identity Governance & Lifecycle Change Requests stuck in the AFX Fulfillment Handler Workflow Node and Workflows Stalled in RSA Identity Governance & Life… Collector Stuck in Data Collection Phase with "Sent Request to Agent Hosting the Collector" RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?