PSA: TURN server ports - intent to limit

552 views
Skip to first unread message

Harald Alvestrand

unread,
Feb 25, 2021, 4:14:50 AMFeb 25
to discuss...@googlegroups.com
In investigating some situations, we've come to realize that configuring TURN server ports ought to be somewhat restricted.

Starting in Chrome 91, and possibly backporting into earlier versions as we verify that it doesn't break things, we intend to only permit connecting to port 443 and port numbers above 1024.


Harald

basar....@gmail.com

unread,
Feb 25, 2021, 5:32:45 AMFeb 25
to discuss-webrtc
This is only for the TURN interface right, not for the relay ports?

Harald Alvestrand

unread,
Feb 25, 2021, 5:34:12 AMFeb 25
to discuss...@googlegroups.com
It only affects the port number that is part of the turn: URL, yes.
There is no influence on the port numbers (local or remote) that can be relayed using TURN.

--

---
You received this message because you are subscribed to the Google Groups "discuss-webrtc" group.
To unsubscribe from this group and stop receiving emails from it, send an email to discuss-webrt...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/discuss-webrtc/38aecbae-667f-4a05-a1a4-67b29419ae38n%40googlegroups.com.

PhistucK

unread,
Feb 25, 2021, 7:42:47 AMFeb 25
to WebRTC-discuss
Even though it is not in Blink, this is a web facing change, so it should be posted (even as just an announcement) to blink-dev as well, I think...

PhistucK


--

---
You received this message because you are subscribed to the Google Groups "discuss-webrtc" group.
To unsubscribe from this group and stop receiving emails from it, send an email to discuss-webrt...@googlegroups.com.

PhistucK

unread,
Feb 25, 2021, 7:43:23 AMFeb 25
to WebRTC-discuss
And a ChromeStatus entry would be nice...

PhistucK

Harald Alvestrand

unread,
Feb 25, 2021, 8:48:29 AMFeb 25
to discuss...@googlegroups.com
Done, although the process steps don't seem to make much sense in this case.


PhistucK

unread,
Feb 25, 2021, 11:19:28 AMFeb 25
to WebRTC-discuss
Thank you, I agree an announcement is sufficient.

PhistucK


Reply all
Reply to author
Forward
0 new messages