Lilith Metaverse · Reference & analysis

V3 Transport Security

The scan evidence is V3/security/transport-security-scan.json.

1section1 minread1table

On this page

Manifest version: v3-transport-security.v1

This release gate locks the §68 transport-security posture. Every public or internal realtime surface must pass a green TLS scan and must use the secure transport expected for that protocol.

Surface Matrix#

Surface Transport Required security
Web shell + Tier-2 HTTPS TLS 1.3
Realtime WebTransport QUIC / HTTP3 TLS 1.3, RFC9000 QUIC, h3 ALPN
Realtime WebSocket WSS TLS 1.3
Realtime WebRTC fallback SCTP data channel TLS 1.3 signalling, DTLS
Voice SFU WebRTC media TLS 1.3 signalling, DTLS-SRTP, SRTP replay
Pixel Streaming WebRTC media WSS signalling, DTLS-SRTP, SRTP replay
UE asset CDN HTTPS signed assets TLS 1.3
UE tenant pak CDN HTTPS signed chunks TLS 1.3

The scan evidence is V3/security/transport-security-scan.json. The gate also checks the concrete production defaults: the Pixel Streaming worker now defaults to wss://lilith-pxstream-signaller.internal/ws, rejects non-local ws:// signalling, and requires an explicit local development opt-in for localhost signallers. V3 voice requires a LiveKit-compatible SFU profile with dtls-srtp-aead-aes-128-gcm media security and SRTP replay protection.

The verifier is pnpm verify:v3 transport-security. It fails closed for missing surfaces, red scans, insecure endpoints, TLS downgrades, missing QUIC / h3, missing WebRTC DTLS, missing SRTP, Pixel Streaming ws:// defaults, or missing certificate automation traceability.