DTLS Listeners
DTLS Listeners add TLS-style encryption and authentication to UDP applications without changing the datagram transport model. Clients establish a DTLS 1.2 or DTLS 1.3 session with the Listener's assigned domain and port. Proxylity decrypts authenticated application data and delivers the plaintext payload to your configured Destinations. Responses from your application are encrypted and sent back through the same DTLS session.
When to Use DTLS
Choose a DTLS Listener when your application already supports DTLS or needs encrypted UDP transport while preserving datagram boundaries. Common examples include RADIUS, IoT protocols, real-time telemetry, and custom request-response protocols that cannot use a stream-oriented TLS connection.
DTLS is also the first transport layer on Proxylity's roadmap to WebRTC Data Channels. DTLS Listeners are available today for native DTLS clients; SCTP and WebRTC signaling are separate layers and are not provided by a DTLS Listener.
DTLS, UDP, and WireGuard
Feature UDP Listener DTLS Listener WireGuard Listener Transport Plain UDP DTLS 1.2 or DTLS 1.3 WireGuard tunnel Encryption Application responsibility TLS-style authenticated encryption WireGuard authenticated encryption Client authentication Client Restrictions Certificate handshake or configured PSK identity Registered peer key or open-peer policy Payload delivered to Destinations UDP payload Decrypted application data WireGuard payload; optionally decapsulated Typical fit Simple or already-encrypted protocols Applications with native DTLS support VPN clients and IP tunneling
Authentication Options
Server Certificate
Every DTLS Listener receives a server certificate and private key managed by Proxylity. The certificate identifies the Listener's assigned endpoint and is returned through the DtlsServerCertificate CloudFormation attribute. Distribute that certificate or its trust anchor according to your client application's trust model.
... continue reading