Serverless DTLS
20 days ago
- DTLS Listeners add TLS-style encryption and authentication to UDP applications while preserving datagram boundaries.
- They support DTLS 1.2 and DTLS 1.3 sessions, decrypting authenticated data and delivering plaintext to configured Destinations.
- Ideal for protocols that already support DTLS (e.g., RADIUS, IoT, real-time telemetry) or need encrypted UDP without stream TLS.
- Key features include pre-shared key (PSK) authentication, cookie exchange for amplification protection, DTLS 1.3 0-RTT with anti-replay, and DTLS 1.2 Connection IDs for session continuity.
- Server certificates are managed by Proxylity and exposed via CloudFormation; certificate rotation requires coordinated trust updates.
- DTLS Listeners are created using CloudFormation custom resources with properties like RequireCookies, AllowEarlyData, Psks, and ClientRestrictions.