DTLS 1.2 / 1.3 implementation for Go
See the codeNative DTLS 1.2 and DTLS 1.3 implementation in the Go programming language.
A long term goal is a professional security review, and maybe an inclusion in stdlib.
Pion DTLS supports DTLS 1.2 and DTLS 1.3. We welcome contributions and bug fixes.
psk_ke and psk_dhe_ke, supporting SHA-256 and SHA-384ResumeConn.AddPath, Path.Probe, and Path.SwitchConn.UpdateKeysFor a DTLS 1.2 Server that listens on 127.0.0.1:4444
go run examples/listen/selfsign/main.go
For a DTLS 1.2 Client that connects to 127.0.0.1:4444
go run examples/dial/selfsign/main.go
Pion DTLS can connect to itself and OpenSSL.
// Generate a certificate
openssl ecparam -out key.pem -name prime256v1 -genkey
openssl req -new -sha256 -key key.pem -out server.csr
openssl x509 -req -sha256 -days 365 -in server.csr -signkey key.pem -out cert.pem
// Use with examples/dial/selfsign/main.go
openssl s_server -dtls1_2 -cert cert.pem -key key.pem -accept 4444
// Use with examples/listen/selfsign/main.go
openssl s_client -dtls1_2 -connect 127.0.0.1:4444 -debug -cert cert.pem -key key.pem
DTLS 1.3 supports session ticket resumption with optional 0-RTT early data.
Resumption only allows psk_dhe_ke (PSK with ephemeral ECDHE).
The resumption example demonstrate a certificate-authenticated
first connection, encrypted session storage, and subsequent connections with resumption
and optional early data. See its README for run instructions and the session store's
single-use Claim requirement for 0-RTT.
The State/Resume API also supports restoring established DTLS 1.3
connections without a new handshake. See Resume.
DTLS 1.3 supports external PSKs with psk_ke (PSK-only) and psk_dhe_ke
(PSK with ephemeral ECDHE), using SHA-256 or SHA-384. Clients can offer multiple
PSK identities per handshake for the server to select from.
Pion DTLS also comes with examples that do key exchange via DTLS 1.2 PSK.
go run examples/listen/psk/main.go
go run examples/dial/psk/main.go
// Use with examples/dial/psk/main.go
openssl s_server -dtls1_2 -accept 4444 -nocert -psk abc123 -cipher PSK-AES128-CCM8
// Use with examples/listen/psk/main.go
openssl s_client -dtls1_2 -connect 127.0.0.1:4444 -psk abc123 -cipher PSK-AES128-CCM8
Pion has an active community on the Discord.
Follow the Pion Bluesky or Pion Twitter for project updates and important WebRTC news.
We are always looking to support your projects. Please reach out if you have something to build! If you need commercial support or don't want to use public methods you can contact us at team@pion.ly
Check out the contributing wiki to join the group of amazing people making this project possible
The DTLS 1.3 implementation in this project is funded through the NGI0 Commons Fund, a fund established by NLnet with financial support from the European Commission's Next Generation Internet programme, under the aegis of DG Communications Networks, Content and Technology under grant agreement No 101135429. Additional funding is made available by the Swiss State Secretariat for Education, Research and Innovation (SERI). Learn more on the NLnet project page.
MIT License - see LICENSE for full text
627 followers · starred Sep 2025
41 followers · starred Sep 2020
19 followers · starred May 2022
113 followers · starred Dec 2022
DTLS 1.2 / 1.3 implementation for Go
See the codeNative DTLS 1.2 and DTLS 1.3 implementation in the Go programming language.
A long term goal is a professional security review, and maybe an inclusion in stdlib.
Pion DTLS supports DTLS 1.2 and DTLS 1.3. We welcome contributions and bug fixes.
psk_ke and psk_dhe_ke, supporting SHA-256 and SHA-384ResumeConn.AddPath, Path.Probe, and Path.SwitchConn.UpdateKeysFor a DTLS 1.2 Server that listens on 127.0.0.1:4444
go run examples/listen/selfsign/main.go
For a DTLS 1.2 Client that connects to 127.0.0.1:4444
go run examples/dial/selfsign/main.go
Pion DTLS can connect to itself and OpenSSL.
// Generate a certificate
openssl ecparam -out key.pem -name prime256v1 -genkey
openssl req -new -sha256 -key key.pem -out server.csr
openssl x509 -req -sha256 -days 365 -in server.csr -signkey key.pem -out cert.pem
// Use with examples/dial/selfsign/main.go
openssl s_server -dtls1_2 -cert cert.pem -key key.pem -accept 4444
// Use with examples/listen/selfsign/main.go
openssl s_client -dtls1_2 -connect 127.0.0.1:4444 -debug -cert cert.pem -key key.pem
DTLS 1.3 supports session ticket resumption with optional 0-RTT early data.
Resumption only allows psk_dhe_ke (PSK with ephemeral ECDHE).
The resumption example demonstrate a certificate-authenticated
first connection, encrypted session storage, and subsequent connections with resumption
and optional early data. See its README for run instructions and the session store's
single-use Claim requirement for 0-RTT.
The State/Resume API also supports restoring established DTLS 1.3
connections without a new handshake. See Resume.
DTLS 1.3 supports external PSKs with psk_ke (PSK-only) and psk_dhe_ke
(PSK with ephemeral ECDHE), using SHA-256 or SHA-384. Clients can offer multiple
PSK identities per handshake for the server to select from.
Pion DTLS also comes with examples that do key exchange via DTLS 1.2 PSK.
go run examples/listen/psk/main.go
go run examples/dial/psk/main.go
// Use with examples/dial/psk/main.go
openssl s_server -dtls1_2 -accept 4444 -nocert -psk abc123 -cipher PSK-AES128-CCM8
// Use with examples/listen/psk/main.go
openssl s_client -dtls1_2 -connect 127.0.0.1:4444 -psk abc123 -cipher PSK-AES128-CCM8
Pion has an active community on the Discord.
Follow the Pion Bluesky or Pion Twitter for project updates and important WebRTC news.
We are always looking to support your projects. Please reach out if you have something to build! If you need commercial support or don't want to use public methods you can contact us at team@pion.ly
Check out the contributing wiki to join the group of amazing people making this project possible
The DTLS 1.3 implementation in this project is funded through the NGI0 Commons Fund, a fund established by NLnet with financial support from the European Commission's Next Generation Internet programme, under the aegis of DG Communications Networks, Content and Technology under grant agreement No 101135429. Additional funding is made available by the Swiss State Secretariat for Education, Research and Innovation (SERI). Learn more on the NLnet project page.
MIT License - see LICENSE for full text
627 followers · starred Sep 2025
41 followers · starred Sep 2020
19 followers · starred May 2022
113 followers · starred Dec 2022