TsgcUDPServer › Properties › DTLS
Enables Datagram TLS (DTLS) to encrypt the UDP traffic received and sent by this server.
property DTLS: Boolean read FDTLS write FDTLS;
—
When True, every datagram received by the server is decrypted through a DTLS handshake, and WriteData encrypts outbound datagrams before they leave the socket; when False the server handles raw UDP. DTLS support requires OpenSSL API 1.1 or 3.0 (configured through DTLSOptions.OpenSSL_Options.APIVersion) and our custom Indy build, and is only available in the Enterprise edition. The OnDTLSVerifyPeer event is fired during each handshake so the application can validate the client certificate, and this only happens when DTLSOptions.VerifyCertificate is True. The verification is now enforced. Previously the chain validation result was computed and then discarded, so any client certificate was accepted, including one issued by an untrusted authority. A failing chain now terminates the handshake. VerifyCertificate is False by default, so the default configuration is unchanged. Call ClearDTLS to discard the cached DTLS sessions (for example, after modifying DTLSOptions).
oServer.DTLS := True;
oServer.DTLSOptions.CertFile := 'server.pem';
oServer.DTLSOptions.KeyFile := 'server.key';