2 ms·
We cover this issue in a separate blog here https://blog.rainway.io/encryption-for-all-3383217e4194 https://blog.rainway.io/encryption-for-all-3383217e4194 To
by andrewmd5 8y ago
We cover this issue in a separate blog here https://blog.rainway.io/encryption-for-all-3383217e4194 https://blog.rainway.io/encryption-for-all-3383217e4194
To summarize, you are correct WebRTC is end-to-end encrypted via DTLS and WebRTC handles setting all of this up. WebSockets, however, are not encrypted by default, and when attempting to connect to a WebSocket server from a secure origin, a valid TLS certificate is required. Because each user has their WebSocket server running from their Rainway instance, we need to create unique and valid certificates for each user to avoid having a shared private key. This is how we avoid needing a TURN server and maintain low latency.
I apologize that it wasn't clear in the blog I was describing how we handle WebRTC failing.
- vijaybritto 8y agoSo the TLS certificate for websocket users are stored in the server? And its generated by letsencrypt?
- cjbprime 8y agoAh! Thanks for the explanation!