Installing BBB 2.3 on a private network

1,398 views
Skip to first unread message

Jewel Joseph

unread,
Jun 14, 2021, 6:09:12 AM6/14/21
to BigBlueButton-Setup
Hi,

I am new to BBB.

Can BBB be installed on a local server that does not have access to the internet (can provide access to the internet during installation )

Can I use a self-signed certificate for authentication?

Thanks and regards,
Jewel Joseph Aloor 

jamma.s...@googlemail.com

unread,
Jun 14, 2021, 6:31:00 AM6/14/21
to BigBlueButton-Setup
Hi Jewel,

yes, you can do that. We have such a setup. I wouldn't recommend a self-signed certificate, but your own PKI - your browsers need to trust the certificates or you'll get all kinds of strange problems (at least scary certificate warnings). There is also a small problem with node.js - it needs to accept the CA as well or your presentations won't show up - a little patch to systemd_start.sh adding "export NODE_EXTRA_CA_CERTS=..."

You should also disable STUN/TURN.

HTH,

Jamma

Jewel Joseph

unread,
Jun 15, 2021, 5:08:07 AM6/15/21
to BigBlueButton-Setup
Thank you, Jama .S, for your support.
Do you by any chance have documentation on how to set up like this or any link that might help?
I couldn't find documentation on how to install BBB 2.3 step by step . However, there is a step by step installation for 2.2 on the BBB website. 
2.3 only has the single line 30 minute script for installation where it uses lets-encrypt for SSL.

Thanks and regards,
Jewel Joseph Aloor 




Militades Sunfire

unread,
Jun 15, 2021, 5:30:02 AM6/15/21
to bigbluebu...@googlegroups.com
you can use the install script without using LE (omit the -e option)
Disclaimer: The information contained in this mail is for the intended addressee only and may be legally privileged. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution or taking action in reliance of the contents of this information is strictly prohibited and may be unlawful. Any opinions expressed, implied or presented are solely those of the author and do not necessarily represent those of SAAL Operating Systems (SAAL). SAAL shall in no circumstances be liable for any loss or damage caused due to error, delay, omission or inaccuracy during transmission. If you have received this mail by mistake, please delete the message and all the copies from your system and notify the sender immediately. All emails and file attachments sent to and received through the SAAL domain is scanned for viruses by SAAL's email virus scanning system. However it is recommended that attachments, if any, be scanned for viruses before launching. SAAL is not liable for any damages caused due to virus(es), trojans or any other form of malicious software transmitted over email.
--
You received this message because you are subscribed to the Google Groups "BigBlueButton-Setup" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bigbluebutton-s...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bigbluebutton-setup/66bebe5a-1360-4e30-9783-7c673dfdfbf5n%40googlegroups.com.


DWAYNE SANDALL

unread,
Jun 15, 2021, 11:37:45 AM6/15/21
to BigBlueButton-Setup
I have used a dns challenge letsencrypt installation then ran the bbb-install script and it works great.

for example:

certbot --manual certonly -d bbb-dev-local.domain.com --preferred-challenges dns

then run install script:



Jamma Tino Schwarze

unread,
Jun 15, 2021, 3:47:01 PM6/15/21
to bigbluebu...@googlegroups.com
Hi Jewel,

sorry, I don't have such a documentation, just some hints:
  1. ensure DNS lookup for your internal server name works
  2. create SSL certificates using your own PKi, put them into /local/certs/ as privkey.pem and fullkey.pem
  3. call bbb-install.sh with -d to make it use those certificates
  4. check  /etc/kurento/modules/kurento/WebRtcEndpoint.conf.ini - there should be NO STUN servers and externalIPv4= should be correct (bbb-install.sh tries to set that correctly)
  5. ensure that your server has full connectivity to all clients - no firewall blocking UDP or somesort (otherwise you'd need an additional internal STUN/TURN server)
HTH,

Jamma.

Disclaimer: The information contained in this mail is for the intended addressee only and may be legally privileged. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution or taking action in reliance of the contents of this information is strictly prohibited and may be unlawful. Any opinions expressed, implied or presented are solely those of the author and do not necessarily represent those of SAAL Operating Systems (SAAL). SAAL shall in no circumstances be liable for any loss or damage caused due to error, delay, omission or inaccuracy during transmission. If you have received this mail by mistake, please delete the message and all the copies from your system and notify the sender immediately. All emails and file attachments sent to and received through the SAAL domain is scanned for viruses by SAAL's email virus scanning system. However it is recommended that attachments, if any, be scanned for viruses before launching. SAAL is not liable for any damages caused due to virus(es), trojans or any other form of malicious software transmitted over email.

--
You received this message because you are subscribed to a topic in the Google Groups "BigBlueButton-Setup" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/bigbluebutton-setup/aBmsmRLrIHw/unsubscribe.
To unsubscribe from this group and all its topics, send an email to bigbluebutton-s...@googlegroups.com.
Reply all
Reply to author
Forward
Message has been deleted
0 new messages