ikeriri-tls-pic1

When your TLS server chooses Cipher Suite as  TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030), you can not decrypt Diffie-Hellman key exchange if you have the private key and certification.

ikeriri-tls-pic2

In this case, its good way to set SSLKEYLOGFILE from your Browser, Wireshark can decrypt TLS

ikeriri-tls-pic3