RFC 5763 allows the DTLS certificates to be self-signed. Authentication comes from matching the handshake certificate against the a=fingerprint value carried in signalling, not from a certificate authority.

Checked 2026-09-23

If self-signed certificates are used, the content of the subjectAltName attribute inside the certificate MAY use the uniform resource identifier (URI) of the user. / The certificate presented during the DTLS handshake MUST match the fingerprint exchanged via the signaling path in the SDP.
Vendor
IETF
Product
DTLS-SRTP with SIP
Subsystem
certificates
Deployment
any
Region
not restricted
Release range
RFC 5763
Checked
2026-09-23

Sources

Cite this note

APA

WarmTransfer. (2026, September 23). SRTP and media encryption negotiation: source note srtp-media-security-rfc5763-self-signed. WarmTransfer. https://warmtransfer.net/knowledge/claims/srtp-media-security-rfc5763-self-signed

BibTeX

@misc{warmtransfer-claim-srtp-media-security-rfc5763-self-signed,
  title  = {SRTP and media encryption negotiation: source note srtp-media-security-rfc5763-self-signed},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/srtp-media-security-rfc5763-self-signed},
  note   = {Source note srtp-media-security-rfc5763-self-signed, checked 2026-09-23}
}

Read in context