RustPBX Basics: TLS Everywhere — WebRTC, SIP, and Certificates That Renew Themselves

M
Miuda Team
Building conversational AI tooling

Browsers won’t touch your WebRTC endpoints without TLS. Carriers increasingly demand SIP over TLS. And certificates that expire on a Saturday are how outages are born. RustPBX bakes the whole story in.

What Needs a Certificate

SurfaceProtocolCertificate
Web console / REST API / WebSocketHTTPS / WSSYes
SIP trunking and extensionsSIP over TLS (5061)Yes
WebRTC mediaDTLS-SRTPSelf-negotiated (no cert management)

WebRTC media keys are exchanged via DTLS per call — the only certificates you manage are for HTTPS and SIP TLS, and they can be the same one.

The ACME Addon

Enable the acme addon and RustPBX issues and renews certificates from Let’s Encrypt (or any ACME CA) automatically:

[proxy]
addons = ["acme"]

Configure the ACME account and domains, and the addon handles issuance and renewal on a schedule — no certbot cron, no expired-Saturday incidents. The TLS reloader swaps new certificates into the running SIP TLS listener without a restart.

Bring Your Own Certificates

Already running an internal CA or a wildcard cert? Point the config at your files:

[proxy]
tls_cert = "/etc/rustpbx/tls/fullchain.pem"
tls_key  = "/etc/rustpbx/tls/privkey.pem"

Mixed deployments are common: a public ACME cert on the console/WSS surface, an internal CA cert on the carrier-facing TLS listener.

Encrypted Media Is Automatic

  • WebRTC legs: DTLS-SRTP always.
  • SIP legs: SDES-SRTP negotiated automatically when the offer carries RTP/SAVP + a=crypto — and mirrored to the other leg when media is anchored, so a carrier that demands encrypted transport interworks with browsers without extra config.
  • Plain RTP stays available for legacy trunks that can’t do encryption.

Verify

Settings console

Diagnostics → Connection probes the ICE/TLS setup from the browser, and openssl s_client -connect host:5061 confirms the SIP TLS listener presents the expected chain. If the ACME addon issued it, renewal is already scheduled — the ops runbook entry for certificates is “don’t have one.”

Deployment Notes

  • Certificate files need to be readable by the runtime user; watch file permissions after manual renewals.
  • Behind a load balancer that terminates TLS? The console can stay HTTP internally while the SIP TLS listener still uses your certs — decide per surface.
  • WSS (WebSocket over TLS) shares the HTTPS certificate; WebRTC clients fail loudly when it expires, which is one more reason the ACME addon exists.

More: Technical Specs and Basic Setup.

Get new posts by email

Deep dives on Rust telephony, contact centers and wholesale voice. No spam.

Thanks — you're on the list.

We use cookies for anonymous analytics to improve the site. Nothing is loaded until you accept. Privacy Policy