Skip to content

feat(transport/udp): DTLS, for Zephyr's SMP-over-UDP DTLS mode #141

Description

@JPHutchins

Warning

LLM Disclosure

This issue was authored by claude-opus-5-5[1m] on behalf of @JPHutchins. While surveying Zephyr main's SMP server transports for the #58 design, @JPHutchins asked for a tracking issue for each server transport smpclient lacks. See also #139 (SPI).

Zephyr's UDP SMP transport has a DTLS mode, added in zephyrproject-rtos/zephyr#97526 (merged 2025-10-17) to resolve zephyrproject-rtos/zephyr#91754, with sample documentation in zephyrproject-rtos/zephyr#102201 (CONFIG_MCUMGR_TRANSPORT_UDP_DTLS, Kconfig.udp). It uses DTLS 1.2 with the device as the DTLS server, and while it is enabled the device does not serve plain UDP. smpclient's SMPUDPTransport speaks plain UDP only, so it cannot reach such a device.

Python's stdlib ssl has no DTLS, so this needs a third-party library; which one is open.

With #58, the security mode would be a constructor option on SMPUDPTransport.connected(...), e.g. a Plain | DTLS(...) sum type. That is the per-transport options work (#90/#103).

The server's side (Zephyr main @ 70be2ff0)
  • Socket. Opens NET_IPPROTO_DTLS_1_2, sets TLS_SEC_TAG_LIST to CONFIG_MCUMGR_TRANSPORT_UDP_DTLS_TLS_TAG (default 1) and TLS_DTLS_ROLE to server (smp_udp.c). It sets no peer-verification option.
  • Credentials. smp_udp_open() refuses to start without a public certificate and private key under that tag (smp_udp.c). The transport does not start automatically at boot: UDP_AUTOMATIC_INIT depends on !UDP_DTLS.
  • The sample (udp-dtls.conf, with DER certificates in certificates/):
    • ciphersuites ECDHE-ECDSA-AES128-GCM-SHA256 and ECDHE-RSA-AES128-CBC-SHA256
    • NET_SOCKETS_DTLS_MAX_FRAGMENT_LENGTH=2048
    • NET_SOCKETS_DTLS_TIMEOUT=30000
  • Sizing. DTLS records add per-datagram overhead, so the MSS arithmetic in udp.py would need to account for it. Not worked out.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions