according to “BG95&BG77&BG600L Series CoAP Application Note” version 1.1 only PSK-Based DTLS contexts can be configured. PSK is not sufficient for our use-case, as the backend is restricted to Certificate-Mode.
I see. Im still experimenting in that direction. Might come back when i got new observations.
For the record. What would be required for COAP is to setup a DTLS Context with CA-Certificate, Client-Certificate and Client Key, similar as it is possible to configure a SSL-Context for HTTPS (Quectel_BG95_BG77_BG600L_Series_HTTP(S)_Application_Note_V1.1.pdf):