• Forums
    • Public Forums
      • Community Connect
      • Dynatrace
        • Dynatrace Open Q&A
      • Application Monitoring & UEM
        • AppMon & UEM Open Q&A
      • Network Application Monitoring
        • NAM Open Q&A
  • Home /
  • Public Forums /
  • Network Application Monitoring /
  • NAM Open Q&A /
  • Home /
  • .. /
  • NAM Open Q&A /
avatar image
Article by Chuan W. · Jul 22, 2016 at 03:09 AM

Decoding MS SQL TDS over SSL

  • Export to PDF
1

Hi Guys,

Any one have experience with decoding MS SQL over SSL successfully ?

I am over at customer site doing a PoC and Gigamon HB-1 was used to decrypting the SSL but I discover that it is not decrypting it. How I know it is not decrypting is that any non successfuly decrypt SSL will still be forward to AMD.

Hence, over at the AMD, doing a `show ssldecr servers`, i can see that the encrypted DB traffic is there. I did try to load the ssl key into AMD and it seem that it is not decrypting too.

Anyone have experience on this area ?

thub.nodes.view.add-new-comment
Martin V.

People who like this

1 Show 4
10 |2000000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Toggle Comment visibility. Current Visibility: Viewable by all users

Up to 10 attachments (including images) can be used with a maximum of 50.0 MiB each and 250.0 MiB total.

avatar image Erik S. · Jul 22, 2016 at 01:38 PM 1
Share

The normal TDS decode should work fine for both encrypted and non-encrypted MS SQL as long as the correct key is present. I've done this many times. When there are issues, I've usually found it is not the correct key for the certificate the SQL server is presenting.

-- Erik

avatar image Martin V. · Mar 09, 2017 at 06:51 PM 0
Share

Experiencing the same at our site. Would love to know how to address this as well.

avatar image Babar Q. Martin V. · Mar 10, 2017 at 07:17 AM 0
Share

Hello Martin,

Check the similar post, might be helpful in your case:

https://answers.dynatrace.com/questions/160903/how-to-decrypt-symmetric-sql-encrypted-traffic.html

Regards,

Babar

avatar image Erik S. · Mar 15, 2017 at 11:35 PM 0
Share

In working on this in the past, the default install of MS SQL will create a default SSL certificate that will be used should the server allow and client requests encryption or the server simply requires it. Microsoft provides no supported way to export the private key for this default certificate.

The only way forward I have found in this scenario is to get/create a certificate externally and import that certificate for the SQL server to use, also putting the private key for this certificate on the AMD. In my experience, as long as the SQL server uses a certificate the AMD has a matching private key for, the AMD can decrypt and analyze the SQL sessions without issue.

-- Erik

How to get started

First steps in the forum
Read Community User Guide
Best practices of using forum

NAM 2019 SP5 is available


Check the RHEL support added in the latest NAM service pack.

Learn more

LIVE WEBINAR

"Performance Clinic - Monitoring as a Self Service with Dynatrace"


JANUARY 15, 3:00 PM GMT / 10:00 AM ET

Register here

Article

Contributors

avatar image

Follow this article

12 People are following this article.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Navigation

Decoding MS SQL TDS over SSL

Related Articles

  • Forums
  • Public Forums
    • Community Connect
    • Dynatrace
      • Dynatrace Open Q&A
    • Application Monitoring & UEM
      • AppMon & UEM Open Q&A
    • Network Application Monitoring
      • NAM Open Q&A