Because SDES puts the master key in cleartext SDP, RFC 4568 requires the signalling to be protected with message authentication and encryption, for example TLS, IPsec or S/MIME.

Checked 2026-09-23

Vendor
IETF
Product
SDES
Subsystem
security considerations
Deployment
any
Region
not restricted
Release range
RFC 4568
Checked
2026-09-23

Sources

Cite this note

APA

WarmTransfer. (2026, September 23). SRTP and media encryption negotiation: source note srtp-media-security-sdes-requires-signalling-protection. WarmTransfer. https://warmtransfer.net/knowledge/claims/srtp-media-security-sdes-requires-signalling-protection

BibTeX

@misc{warmtransfer-claim-srtp-media-security-sdes-requires-signalling-protection,
  title  = {SRTP and media encryption negotiation: source note srtp-media-security-sdes-requires-signalling-protection},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/srtp-media-security-sdes-requires-signalling-protection},
  note   = {Source note srtp-media-security-sdes-requires-signalling-protection, checked 2026-09-23}
}

Read in context