Cross-reference
Where it enters the lineage
This concept is first developed in § m4-l6 — Securing the Call: How DTLS-SRTP Won. The historical problem there matters: WebRTC components are not arbitrary layers; each is a repair for a specific limit in the system before it.
Mandatory media encryption: the DTLS handshake on the media path, fingerprint binding through SDP, SRTP key export and cipher suites — and the SDES plaintext-key flaw it replaced.
The SDP fingerprint authenticates the certificate presented on the media path. DTLS exports keying material for SRTP, keeping keys out of SDP and replacing the insecure SDES practice of sending media keys through signaling.
The operational claim is precise: Mandatory media encryption: the DTLS handshake on the media path, fingerprint binding through SDP, SRTP key export and cipher suites — and the SDES plaintext-key flaw it replaced. Treat it as an observable contract. Record the state transition or counter that proves it, test the failure path as well as the happy path, and keep units and clock domains explicit. That discipline is what separates a plausible WebRTC explanation from a production diagnosis.
Separate the control plane from the data plane, then name the clock, identifier, and unit attached to each observation. Ask what is negotiated, what is measured live, and what is merely configured. A robust explanation predicts both a successful trace and the characteristic failure trace.
In an application, this concept does not stand alone. It participates in a chain of negotiation, transport, media processing, and feedback. The practical boundary is the API, SDP attribute, RTP/RTCP field, or stats record where the browser exposes it. Use that boundary in tests: feed controlled input, observe the named output, and verify fallback behavior when the preferred path is unavailable.
A useful study method is to draw three columns: configured, negotiated, and observed. Put application preferences and constraints in the first, the answer's accepted parameters in the second, and live packet, state, or stats evidence in the third. Disagreements between columns are diagnostic information. They reveal fallback, unsupported capability, stale state, or a mistaken assumption about which endpoint controls the behavior. This method scales from a single codec preference to an ICE restart or a multi-layer SFU route.
Diagnostic discipline
Do not infer success from configuration alone. A codec in capabilities is not necessarily negotiated; a candidate in SDP is not necessarily selected; a connected peer connection is not necessarily receiving decodable frames. Prefer the narrowest live evidence.
| Question | Evidence |
|---|---|
| Was it negotiated or selected? | Inspect the answer and the live stats graph. |
| Did the state transition complete? | Record ordered events with timestamps. |
| Are counters moving in the expected direction? | Compute deltas; never compare unrelated cumulative samples. |
| What happens beyond the latency or capacity budget? | Inject delay, loss, reordering, or constrained bandwidth. |
WebRTC: From First Principles · Concept reference