March 31, 2023In VoIP, VoIP Troubleshooting

UPDATED JUNE 2025

Summary

  • This guide walks VoIP admins through decrypting encrypted TLS SIP and SRTP packets using Wireshark and srtp-decrypt.
  • Step 1 is loading the server’s private key and capturing the full TLS handshake to allow decryption of encrypted packets.
  • Once decrypted, the inline SRTP key is extracted from the SIP INVITE (or OK) packet for audio stream access.
  • The audio stream is filtered, exported, decrypted on a Linux machine, and re-imported into Wireshark for playback.
  • These advanced steps allow you to recover raw call audio and troubleshoot complex VoIP issues with precision. For more help, contact Atcom Systems.

How to Decrypt TLS SIP & SRTP in 8 Steps

When your business relies on VoIP for your telephone systems, clarity isn’t optional—it’s everything. But when things go wrong, you need more than basic diagnostics. You need the ability to dig deep into encrypted TLS SIP and SRTP traffic to understand what’s really happening during a call.

How to Decrypt Encrypted VoIP Traffic

In this guide, we walk you through how to decrypt and analyze encrypted VoIP packets using tools like Wireshark and srtp-decrypt on Linux. Whether you’re a network admin trying to pinpoint call degradation or a telecom engineer tracking a deeper issue, this process can help you recover the raw audio behind a problematic call.

Related: Local Service and Support for My Business Telephone System

 

 

 

 

 

 

 

 

 

 

1) Load the Server’s Private Key into Wireshark

The first thing you need to do is ensure Wireshark has the private key for the “server” side of the TLS conversation.

This is under Edit > Preferences > RSA Keys, and the private key should be PEM formatted with an extension of .pem or .key.

After you have the key file loaded, open the PCAP you are working with.

IMPORTANT: Your packet capture must contain the TLS negotiation for the port numbers in question that shows “Client Hello”, “Server Hello”, etc.

Without this information Wireshark cannot decode any subsequent TLS packets. Therefore, you should probably have a capture that begins 15 minutes before the call you’re looking at.

2) Capture the Full TLS Handshake

Once your TLS SIP packets are decrypted, go to the INVITE for the call you’d like to decrypt.

NOTE: If Wireshark displays “Linux Cooked Capture” or SLL on the line underneath “Frame” (instead of Ethernet II) then you’ll need to do some additional work to decrypt the packets.

Linux Cooked Capture usually means the PCAP is for multiple interfaces and srtp-decrypt will not be able to decode them as-is. Tracewrangler may be able to help you.

The SDP will contain the inline key we need.

In this case, the key is:

2U9eiAwx0eg0jkjf0X1idOmqBlO7H9lokrrUsnEO

At this point, we have the info we need to decrypt the audio from the INVITE side of the call. If you need to decrypt audio in the other direction, simply grab the inline key from the SDP of the OK packet instead of the INVITE packet.

3) Extract the SRTP Inline Key from the SIP INVITE or OK Packet

The next step is to filter the audio packet from the INVITE side of the call. In Wireshark you can do this with a filter like:

udp.port == 11314 and ip.src == 34.0.0.1

4) Filter and Export the SRTP Audio Stream

Now save using File > Export Specified Packets and check that only “Displayed” packets will be saved.

Save as a .pcap type file and transfer it over to a Linux PC.

5) Decrypt the SRTP Audio Using srtp-decrypt on Linux

On the Linux machine, go to /usr/src and run the following commands:

git clone https://github.com/gteissier/srtp-decrypt.git

cd srtp-decrypt/

make

cd srtp-decrypt

./srtp-decrypt -k 2U9eiAwx0eg0jkjf0X1idOmqBlO7H9lokrrUsnEO < /path/to/audio-srtp.pcap > /path/to/audio-decrypted.txt

Obviously you want to replace the text after -k with the inline key we retrieved from the SIP packet, and modify the paths to the input and output files as needed.

6) Import the Decrypted Data Back into Wireshark

Transfer the .txt output file back to your Windows PC and import it to Wireshark using File > Import HEX Dump.

Choose UDP as the protocol and input some fake port numbers.

7) Decode the Stream as RTP

Next, right-click on one of the lines and choose “Decode As”, then pick RTP for the “Current” column.

8) Play the Audio Using Wireshark’s RTP Player

Finally, go to Telephony > RTP > RTP Player, and the audio will be available!

VoIP Troubleshooting Is Easier with Professional Help from Atcom

Decrypting TLS SIP and SRTP streams is an advanced but powerful method for resolving complex VoIP issues. When you need to confirm call quality, verify encryption behavior, or troubleshoot failed call paths, this method provides unmatched insight into what’s really going on behind the scenes.

Need help troubleshooting a critical VoIP issue? Atcom Systems specializes in business telecom solutions and advanced diagnostics. Contact us for expert support—whether you’re running a cloud phone system, a SIP trunk, or a hybrid VoIP environment.

Get a Quote

Talk to a VoIP Expert

Get a No-Pressure Online Quote from an Expert

Proudly serving British Columbia, Alberta, Saskatchewan, & more

Headquartered in Calgary, supporting Canadian businesses

Atcom Systems is a Canadian leader in modern, efficient, and user-friendly solutions that meet the needs of clients in diverse industries and solve key communication challenges.

About us

Privacy Preference Center