Proxylity says that DTLS Listeners are now available for clients with native DTLS support and add encryption and authentication to UDP applications without changing the datagram transport model.

DTLS is a protocol for encrypting and authenticating UDP traffic.

Clients establish a DTLS 1.2 or 1.3 session, after which Proxylity decrypts authenticated application data and delivers the plaintext payload to configured destinations. The service encrypts application responses and sends them through the same session.

With RequireCookies enabled, the Listener requires a DTLS cookie exchange before the full handshake. Cookies help confirm that a client can receive packets at its claimed source address and reduce amplification and resource-exhaustion risk, but add one round trip to a new session.

Claim check:

  • Proxylity says that DTLS Listeners are now available for clients with native DTLS support. (confirmed by the publication itself: evidence; «DTLS Listeners are available today for native DTLS clients; SCTP and WebRTC signaling are separate layers and are not provided by a DTLS Listener.»)
  • DTLS Listeners add encryption and authentication to UDP applications without changing the datagram transport model. (confirmed by the publication itself: evidence; «DTLS Listeners add TLS-style encryption and authentication to UDP applications without changing the datagram transport model.»)
  • Clients establish a DTLS 1.2 or 1.3 session, after which Proxylity decrypts authenticated application data and delivers the plaintext payload to configured destinations, while encrypting and sending application responses through the same session. (confirmed by the publication itself: evidence; «Clients establish a DTLS 1.2 or DTLS 1.3 session with the Listener’s assigned domain and port. Proxylity decrypts authenticated application data and delivers the plaintext payload to your configured Destinations. Responses from your application are encrypted and sent back through the same DTLS session.»)
  • With RequireCookies enabled, the Listener requires a DTLS cookie exchange before the full handshake: cookies help confirm that a client can receive packets at its claimed source address and reduce amplification and resource-exhaustion risk, but add one round trip to a new session. (confirmed by the publication itself: evidence; «Set RequireCookies to require the DTLS cookie exchange before the Listener performs the full handshake. Cookies help confirm that a client can receive packets at its claimed source address and reduce amplification and resource-exhaustion risk. Enabling cookies adds one round trip to a new session.»)

Primary sources:

score 69.1 out of 100 · kind: announcement