Sametime: coturn does not support wildcard certificates

A customer of mine ran into an issue when using his Sametime server for meetings with external companies. The participants could not see any video neither hear audio.

Since internally everything works perfectly and he is using a TURN server, we started looking into its configuration and logs. We didn’t find anything wrong and the logs reported no errors. Then, after finding that until circa one month ago everything was working fine, he remembered that since then, he changed the coturn certificate from a single LetsEncrypt certificate to a wildcard one he gets from a CA for his company.

So he switched back to the LetsEncypt certificate, and everything started working again.
Upon looking in the coturn GitHub repository he found this
https://github.com/coturn/coturn/issues/352
Turns out that coturn does not support wildcard certificates, and looking at the thread on GitHub is likely it will not do it in a foreseeable future.

I have suggested HCL to improve their documentation, mentioning this; even if I understand this is not a HCL issue, adding a warning not to use wildcard certs could be useful.

New HCL whitepaper on Sametime chat server on Windows
Sametime Chat server for Windows SSO with Domino

Leave a Reply

Your email address will not be published / Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.