Nextcloud, Talk, TURN-Server, coTurn, Ports, Strato

Ich denke, da herrscht eine gewisse Verwirrung. Das sollte man mal kÀren:

Also Du hast einen Strato-Server ‘XXX.stratoserver.net’ als physikalische (virtuelle) Maschine.
Darauf lĂ€uft Dein Apache od. Nginx-Server mit einem vhost ‘yournextcloud.stratoserver.net’. Außerdem lĂ€uft darauf noch Dein turnserver. Falls Deine Umgebung so ist, wie eben beschrieben muß zumindest der Port 443 oder auch 80 frei sein, sonst könntest Du nicht auf Deine Nextcloud-Instanz. Das sehe ich aber nicht bei dem was Du gepostet hast.

Ich habe einen shared host (bei Strato), auf dem u.a. die Nextcloud installiert ist.

Und ich habe einen separaten Linux-Server (Ubuntu 18.04) auch bei Strato, auf dem aktuell nur der TURN-Server lĂ€uft. Bei diesem Linux-Server ist nur der Port22 / ssh frei. Mit Strato-Server meinte ich in der bisherigen Konversation ausschließlich den Linux-Server.

Diese Konfiguration geht natĂŒrlich auch, aber dann mußt Du Dir von Strato den Port 3478 fĂŒr den turnserver freischalten lassen.
Was die Konfiguration des turnservers angeht, mußt Du bei ‘realm’ Deine Nextcloud-Instanz eintragen, also das, was Du im Browser eingibst um auf Deine Nextcloud zu kommen.

ufw status | grep 3478

3478/tcp                   ALLOW       Anywhere
3478/udp                   ALLOW       Anywhere
3478/tcp (v6)              ALLOW       Anywhere (v6)
3478/udp (v6)              ALLOW       Anywhere (v6)

Das TURN-secret stimmt mit static-auth-secret in /etc/turnserver.conf ĂŒberein?

Nimm dir doch einen Cloud-Server bei Hetzner um nicht mal 3 €/Monat!

Ich hatte schon 2x Kontakt mit der Strato-Hotline:
Ergebnis 1: Lt. Strato ist der Linux-Server ist ein root-Server, Strato hat keinen Zugriff, d.h. man muss sich um alles selbst kĂŒmmern.
-> Hatte ich so erwartet und ist ok.

Ergebnis 2: Freigabe eines Ports mit <sudo ufw allow port ** tcp> oder ohne ufw mit <sudo allow port ** tcp>
-> Da ich aktuell ufw nicht einsetze, sollte der Port auch nicht durch ufw freigegeben werden mĂŒssen. Ich hatte es trotzdem probiert und es hat erwartungsgemĂ€ĂŸ nicht funktioniert. Der zweite Befehl ist m.E. nicht brauchbar.

@Sanook: ufw ist nicht installiert, sollte also auch den Port nicht blockieren. Siehst du das auch so?
@Sanook: Das TURN-secret stimmt mit static-auth-secret in /etc/turnserver.conf ĂŒberein. Habe erstmal ein einfaches Wort genommen, um sicher zu sein: static-auth-secret=test
@Sanook: Danke fĂŒr den Hetzner-Tipp. Bleibt noch, falls ich es nicht zum Laufen kriege.

@peteman52: realm ist korrekt, ohne https, ohne www
@peteman52: Strato öffnet m.W. keinen Port. Ich werde es aber auch nochmal bei der Hotline probieren. Aller guten Dinge sind Drei :wink:

Was wird bei euch angezeigt bei:
sudo systemctl status coturn

● coturn.service - LSB: coturn TURN Server
Loaded: loaded (/etc/init.d/coturn; generated)
Active: active (exited) since Mon 2020-05-11 22:56:16 CEST; 16min ago
Docs: man:systemd-sysv-generator(8)
Process: 715 ExecStop=/etc/init.d/coturn stop (code=exited, status=0/SUCCESS)
Process: 721 ExecStart=/etc/init.d/coturn start (code=exited, status=0/SUCCESS)

Mai 11 22:56:16 XXX.stratoserver.net turnserver[726]: 0: Total General servers: 48
Mai 11 22:56:16 XXX.stratoserver.net turnserver[726]: 0: IO method (auth thread): epoll (with changelist)
Mai 11 22:56:16 XXX.stratoserver.net turnserver[726]: 0: IO method (auth thread): epoll (with changelist)
Mai 11 22:56:16 XXX.stratoserver.net turnserver[726]: 0: IO method (auth thread): epoll (with changelist)



Steh eh da warums nicht geht :wink:

Es soll so aussehen:

Snipaste_2020-05-11_23-45-34

Gib mal ein

iptables -L -n | grep 3478

da muß kommen

ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:3478
ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:3478

<iptables -L -n | grep 3478> brachte kein Ergebnis

Habe den Port manuell geöffnet mit:
sudo iptables -A INPUT -p upd --dport 3478 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 3478 -j ACCEPT

Ergebnis ist jetzt wie bei dir.

Danach coturn gestoppt und wieder gestartet,

Ergebnis jetzt:
sudo systemctl status coturn

● coturn.service - LSB: coturn TURN Server
Loaded: loaded (/etc/init.d/coturn; generated)
Active: active (exited) since Tue 2020-05-12 07:46:50 CEST; 8s ago
Docs: man:systemd-sysv-generator(8)
Process: 5686 ExecStop=/etc/init.d/coturn stop (code=exited, status=0/SUCCESS)
Process: 5701 ExecStart=/etc/init.d/coturn start (code=exited, status=0/SUCCESS)

Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv6. TCP listener opened on : ::2:347
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv4. UDP listener opened on: 127.0.0.
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv4. UDP listener opened on: 127.0.0.
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv4. UDP listener opened on: XX.XXX.1
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv4. UDP listener opened on: XX.XXX.1
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv6. UDP listener opened on: ::1:3478
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv6. UDP listener opened on: ::1:3479
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv6. UDP listener opened on: ::2:3478
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: IPv6. UDP listener opened on: ::2:3479
Mai 12 07:46:51 XXX.stratoserver.net turnserver[5706]: 0: Total General servers: 48

Kannst Du mal den Output von

sudo systemctl edit --full coturn

posten?

Und mach auch mal ein

sudo systemctl restart coturn

statt stop und start.

sudo systemctl edit --full coturn

#Automatically generated by systemd-sysv-generator

[Unit]
Documentation=man:systemd-sysv-generator(8)
SourcePath=/etc/init.d/coturn
Description=LSB: coturn TURN Server
Before=multi-user.target
Before=multi-user.target
Before=multi-user.target
Before=graphical.target
After=network-online.target
After=remote-fs.target
Wants=network-online.target

[Service]
Type=forking
Restart=no
TimeoutSec=5min
IgnoreSIGPIPE=no
KillMode=process
GuessMainPID=no
RemainAfterExit=yes
SuccessExitStatus=5 6
ExecStart=/etc/init.d/coturn start
ExecStop=/etc/init.d/coturn stop

Das sieht richtig aus, d.h. so wie bei mir :slightly_smiling_face:

Hat der restart die status-anzeige verÀndert? Es gibt da noch einen Befehl, den man direkt nach dem restart absetzen kann, dann sieht man vielleicht mehr. Irgendwie

journalctl -xe

oder zumindest so Àhnlich.

Und Du könntest auch mal die EintrĂ€ge in ‘/var/log/syslog’ fĂŒr den turnserver posten.

Die Anzeige hat sich durch restart nicht geÀndert.

/var/log/syslog:
May 12 17:02:48 XXXX systemd[1]: Stopping LSB: coturn TURN Server

May 12 17:02:48 XXXX coturn[11773]: * Stopping coturn turnserver
May 12 17:02:48 XXXX coturn[11773]: 
done.
May 12 17:02:48 XXXX systemd[1]: Stopped LSB: coturn TURN Server.
May 12 17:02:48 XXXX systemd[1]: Starting LSB: coturn TURN Server

May 12 17:02:48 XXXX coturn[11779]: * Starting coturn turnserver
May 12 17:02:49 XXXX turnserver: 0: Domain name:
May 12 17:02:49 XXXX turnserver: 0: Default realm: XXX.net/cloud
May 12 17:02:49 XXXX systemd[1]: Started LSB: coturn TURN Server.
May 12 17:02:49 XXXX coturn[11779]: 
done.
May 12 17:02:49 XXXX turnserver: 0: #012CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password!
May 12 17:02:49 XXXX turnserver: 0: WARNING: cannot find certificate file: turn_server_cert.pem (1)
May 12 17:02:49 XXXX turnserver: 0: WARNING: cannot start TLS and DTLS listeners because certificate file is not set properly
May 12 17:02:49 XXXX turnserver: 0: WARNING: cannot find private key file: turn_server_pkey.pem (1)
May 12 17:02:49 XXXX turnserver: 0: WARNING: cannot start TLS and DTLS listeners because private key file is not set properly
May 12 17:02:49 XXXX turnserver: 0: NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED
May 12 17:02:49 XXXX turnserver: 0: ===========Discovering listener addresses: =========
May 12 17:02:49 XXXX turnserver: 0: Listener address to use: 127.0.0.1
May 12 17:02:49 XXXX turnserver: 0: Listener address to use: XX.XXX.XXX.XXX
May 12 17:02:49 XXXX turnserver: 0: Listener address to use: ::1
May 12 17:02:49 XXXX turnserver: 0: Listener address to use: ::2
May 12 17:02:49 XXXX turnserver: 0: =====================================================
May 12 17:02:49 XXXX turnserver: 0: Total: 3 ‘real’ addresses discovered
May 12 17:02:49 XXXX turnserver: 0: =====================================================
May 12 17:02:49 XXXX turnserver: 0: NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED
May 12 17:02:49 XXXX turnserver: 0: ===========Discovering relay addresses: =============
May 12 17:02:49 XXXX turnserver: 0: Relay address to use: 127.0.0.1
May 12 17:02:49 XXXX turnserver: 0: Relay address to use: XX.XXX.XXX.XXX
May 12 17:02:49 XXXX turnserver: 0: Relay address to use: ::2
May 12 17:02:49 XXXX turnserver: 0: =====================================================
May 12 17:02:49 XXXX turnserver: 0: Total: 3 relay addresses discovered
May 12 17:02:49 XXXX turnserver: 0: =====================================================
May 12 17:02:49 XXXX turnserver: 0: pid file created: /var/run/turnserver.pid
May 12 17:02:49 XXXX turnserver: 0: IO method (main listener thread): epoll (with changelist)
May 12 17:02:49 XXXX turnserver: 0: Wait for relay ports initialization

May 12 17:02:49 XXXX turnserver: 0: relay 127.0.0.1 initialization

May 12 17:02:49 XXXX turnserver: 0: relay 127.0.0.1 initialization done
May 12 17:02:49 XXXX turnserver: 0: relay XX.XXX.XXX.XXX initialization

May 12 17:02:49 XXXX turnserver: 0: relay XX.XXX.XXX.XXX initialization done
May 12 17:02:49 XXXX turnserver: 0: relay ::2 initialization

May 12 17:02:49 XXXX turnserver: 0: relay ::2 initialization done
May 12 17:02:49 XXXX turnserver: 0: Relay ports initialization done
May 12 17:02:49 XXXX turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 17:02:49 XXXX turnserver: 0: turn server id=6 created
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3479
May 12 17:02:49 XXXX turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 17:02:49 XXXX turnserver: 0: turn server id=7 created
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3479
May 12 17:02:49 XXXX turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 17:02:49 XXXX turnserver: 0: turn server id=8 created
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : 127.0.0.1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3478
May 12 17:02:49 XXXX turnserver: 0: IPv4. TCP listener opened on : XX.XXX.XXX.XXX:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::1:3479
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3478
May 12 17:02:49 XXXX turnserver: 0: IPv6. TCP listener opened on : ::2:3479
May 12 17:02:49 XXXX turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 17:02:49 XXXX turnserver: 0: turn server id=9 created

journalctl liefert keine zusÀtzlichen Infos, hebt nur das cli-Thema hervor:
CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password!

Bei mir kommt beim Neustart von Coturn:

May 12 22:09:33 XXXXX systemd[1]: Stopping LSB: coturn TURN Server...
May 12 22:09:33 XXXXX coturn[31642]:  * Stopping coturn turnserver
May 12 22:09:33 XXXXX coturn[31642]:    ...done.
May 12 22:09:33 XXXXX systemd[1]: Stopped LSB: coturn TURN Server.
May 12 22:09:33 XXXXX systemd[1]: Starting LSB: coturn TURN Server...
May 12 22:09:33 XXXXX coturn[31651]:  * Starting coturn  turnserver
May 12 22:09:33 XXXXX coturn[31651]: 0: log file opened: /var/log/turn_31670_2020-05-12.log
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: RFC 3489/5389/5766/5780/6062/6156 STUN/TURN Server
May 12 22:09:33 XXXXX coturn[31651]: Version Coturn-4.5.0.7 'dan Eider'
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: Max number of open files/sockets allowed for this process: 4096
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: Due to the open files/sockets limitation,
May 12 22:09:33 XXXXX coturn[31651]: max supported number of TURN Sessions possible is: 2000 (approximately)
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: ==== Show him the instruments, Practical Frost: ====
May 12 22:09:33 XXXXX coturn[31651]: 0: TLS supported
May 12 22:09:33 XXXXX coturn[31651]: 0: DTLS supported
May 12 22:09:33 XXXXX coturn[31651]: 0: DTLS 1.2 supported
May 12 22:09:33 XXXXX coturn[31651]: 0: TURN/STUN ALPN supported
May 12 22:09:33 XXXXX coturn[31651]: 0: Third-party authorization (oAuth) supported
May 12 22:09:33 XXXXX coturn[31651]: 0: GCM (AEAD) supported
May 12 22:09:33 XXXXX coturn[31651]: 0: OpenSSL compile-time version: OpenSSL X.X.X.y
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: 0: SQLite supported, default database location is /var/lib/turn/turndb
May 12 22:09:33 XXXXX coturn[31651]: 0: Redis supported
May 12 22:09:33 XXXXX coturn[31651]: 0: PostgreSQL supported
May 12 22:09:33 XXXXX coturn[31651]: 0: MySQL supported
May 12 22:09:33 XXXXX coturn[31651]: 0: MongoDB is not supported
May 12 22:09:33 XXXXX coturn[31651]: 0:
May 12 22:09:33 XXXXX coturn[31651]: 0: Default Net Engine version: 3 (UDP thread per CPU core)
May 12 22:09:33 XXXXX coturn[31651]: =====================================================
May 12 22:09:33 XXXXX coturn[31651]: 0: Listener address to use: XX.XX.XX.XXX
May 12 22:09:33 XXXXX coturn[31651]: 0: Domain name:
May 12 22:09:33 XXXXX turnserver: 0: Default realm: domain.xx
May 12 22:09:33 XXXXX turnserver: 0: SSL23: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: SSL23: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.0: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.0: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.1: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.1: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.2: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS1.2: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: TLS cipher suite: DEFAULT
May 12 22:09:33 XXXXX turnserver: 0: DTLS1.2: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: DTLS1.2: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: DTLS: Certificate file found: /etc/letsencrypt/live/domain.xx/cert.pem
May 12 22:09:33 XXXXX turnserver: 0: DTLS: Private key file found: /etc/letsencrypt/live/domain.xx/privkey.pem
May 12 22:09:33 XXXXX turnserver: 0: DTLS cipher suite: DEFAULT
May 12 22:09:33 XXXXX turnserver: 0: Relay address to use: XX.XX.XX.XXX
May 12 22:09:33 XXXXX coturn[31651]:    ...done.
May 12 22:09:33 XXXXX systemd[1]: Started LSB: coturn TURN Server.
May 12 22:09:34 XXXXX turnserver: 1: pid file created: /var/run/turnserver.pid
May 12 22:09:34 XXXXX turnserver: 1: IO method (main listener thread): epoll (with changelist)
May 12 22:09:34 XXXXX turnserver: 1: WARNING: I cannot support STUN CHANGE_REQUEST functionality because only one IP address is provided
May 12 22:09:34 XXXXX turnserver: 1: Wait for relay ports initialization...
May 12 22:09:34 XXXXX turnserver: 1:   relay XX.XX.XX.XXX initialization...
May 12 22:09:34 XXXXX turnserver: 1:   relay XX.XX.XX.XXX initialization done
May 12 22:09:34 XXXXX turnserver: 1: Relay ports initialization done
May 12 22:09:34 XXXXX turnserver: 1: IO method (general relay thread): epoll (with changelist)
May 12 22:09:34 XXXXX turnserver: 1: turn server id=0 created
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/SCTP listener opened on : XX.XX.XX.XXX:3478
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/TCP listener opened on : XX.XX.XX.XXX:3478
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/SCTP listener opened on : XX.XX.XX.XXX:5349
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/TCP listener opened on : XX.XX.XX.XXX:5349
May 12 22:09:34 XXXXX turnserver: 1: IO method (general relay thread): epoll (with changelist)
May 12 22:09:34 XXXXX turnserver: 1: turn server id=1 created
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/TCP listener opened on : XX.XX.XX.XXX:3478
May 12 22:09:34 XXXXX turnserver: 1: IPv4. TLS/TCP listener opened on : XX.XX.XX.XXX:5349
May 12 22:09:34 XXXXX turnserver: 1: IPv4. DTLS/UDP listener opened on: XX.XX.XX.XXX:3478
May 12 22:09:34 XXXXX turnserver: 1: IPv4. DTLS/UDP listener opened on: XX.XX.XX.XXX:5349
May 12 22:09:34 XXXXX turnserver: 1: Total General servers: 2
May 12 22:09:34 XXXXX turnserver: 1: SQLite DB connection success: /var/lib/turn/turndb
May 12 22:09:34 XXXXX turnserver: 1: IO method (admin thread): epoll (with changelist)
May 12 22:09:34 XXXXX turnserver: 1: IPv4. CLI listener opened on : 127.0.0.1:5766
May 12 22:09:34 XXXXX turnserver: 1: IO method (auth thread): epoll (with changelist)
May 12 22:09:34 XXXXX turnserver: 1: IO method (auth thread): epoll (with changelist)

Bei mir sieht das syslog so aus, meiner Ansicht nach ziemlich Àhnlich:

May 12 12:34:51 mpeUbuntuserver coturn[25454]: * Starting coturn turnserver
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Domain name:
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Default realm:nextcloud.mydomain.de
May 12 12:34:51 mpeUbuntuserver turnserver: 0: #012CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password!
May 12 12:34:51 mpeUbuntuserver turnserver: 0: SSL23: Certificate file found: /etc/letsencrypt/live/xxx/fullchain.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: SSL23: Private key file found: /etc/letsencrypt/live/xxx/privkey.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: TLS1.2: Certificate file found: /etc/letsencrypt/live/xxx/fullchain.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: TLS1.2: Private key file found: /etc/letsencrypt/live/xxx/privkey.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: TLS cipher suite: xxx
May 12 12:34:51 mpeUbuntuserver turnserver: 0: DTLS1.2: Certificate file found: /etc/letsencrypt/live/xxx/fullchain.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: DTLS1.2: Private key file found: /etc/letsencrypt/live/xxx/privkey.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: DTLS: Certificate file found: /etc/letsencrypt/live/xxx/fullchain.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: DTLS: Private key file found: /etc/letsencrypt/live/xxx/privkey.pem
May 12 12:34:51 mpeUbuntuserver turnserver: 0: DTLS cipher suite: xxx
May 12 12:34:51 mpeUbuntuserver turnserver: 0: NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED
May 12 12:34:51 mpeUbuntuserver turnserver: 0: ===========Discovering listener addresses: =========
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Listener address to use: 127.0.0.1
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Listener address to use: 192.168.178.37
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Listener address to use: ::1
May 12 12:34:51 mpeUbuntuserver turnserver: 0: =====================================================
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Total: 1 ‘real’ addresses discovered
May 12 12:34:51 mpeUbuntuserver turnserver: 0: =====================================================
May 12 12:34:51 mpeUbuntuserver turnserver: 0: NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED
May 12 12:34:51 mpeUbuntuserver turnserver: 0: ===========Discovering relay addresses: =============
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Relay address to use: 192.168.178.37
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Relay address to use: ::1
May 12 12:34:51 mpeUbuntuserver turnserver: 0: =====================================================
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Total: 2 relay addresses discovered
May 12 12:34:51 mpeUbuntuserver turnserver: 0: =====================================================
May 12 12:34:51 mpeUbuntuserver turnserver: 0: pid file created: /var/run/turnserver.pid
May 12 12:34:51 mpeUbuntuserver coturn[25454]: 
done.
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (main listener thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Wait for relay ports initialization

May 12 12:34:51 mpeUbuntuserver systemd[1]: Started LSB: coturn TURN Server.
May 12 12:34:51 mpeUbuntuserver turnserver: 0: relay 192.168.178.37 initialization

May 12 12:34:51 mpeUbuntuserver turnserver: 0: relay 192.168.178.37 initialization done
May 12 12:34:51 mpeUbuntuserver turnserver: 0: relay ::1 initialization

May 12 12:34:51 mpeUbuntuserver turnserver: 0: relay ::1 initialization done
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Relay ports initialization done
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: message repeated 2 times: [ 0: IO method (general relay thread): epoll (with changelist)]
May 12 12:34:51 mpeUbuntuserver turnserver: 0: turn server id=2 created
May 12 12:34:51 mpeUbuntuserver turnserver: 0: turn server id=0 created
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/SCTP listener opened on : 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/SCTP listener opened on : ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/SCTP listener opened on : ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/SCTP listener opened on : ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/SCTP listener opened on : ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: turn server id=1 created
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (general relay thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: turn server id=3 created
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 127.0.0.1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 127.0.0.1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 127.0.0.1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. TLS/TCP listener opened on : 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 127.0.0.1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. TLS/TCP listener opened on : ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 192.168.178.37:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 192.168.178.37:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 192.168.178.37:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv4. DTLS/UDP listener opened on: 192.168.178.37:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. DTLS/UDP listener opened on: ::1:3478
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. DTLS/UDP listener opened on: ::1:3479
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. DTLS/UDP listener opened on: ::1:5349
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IPv6. DTLS/UDP listener opened on: ::1:5350
May 12 12:34:51 mpeUbuntuserver turnserver: 0: Total General servers: 4
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (auth thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (auth thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: 0: IO method (admin thread): epoll (with changelist)
May 12 12:34:51 mpeUbuntuserver turnserver: 0: SQLite DB connection success: /var/lib/turn/turndb

Bei mir steht dort die WAN IP

Einen Unterschied sehe ich zwischen:

May 12 17:02:49 XXXX turnserver: 0: WARNING: cannot find certificate file: turn_server_cert.pem (1)
bei mir

und

May 12 12:34:51 mpeUbuntuserver turnserver: 0: SSL23: Certificate file found: /etc/letsencrypt/live/xxx/fullchain.pem
bei peteman52 und Sannok

Ich nehme mal an, Du hast eine feste IP-Adresse und die auch in der turnserver-Konfiguration angegeben?

Genau.  

Da Du ohne VerschlĂŒsselung arbeitest sollte das egal sein. Ist ja auch nur eine ‘Warning’. Aber ehrlich gesagt bin ich mir da nicht sicher.