The first tcp packet is not encrypted, but afterwards connections are upgraded, using a security transport supported by both sides. I suspect wireshark does not detect the upgrades and keeps listing TCP traffic, but the payloads will be garbled when connections are upgraded.