coturn TURN server project
  • C 91.8%
  • CMake 3.9%
  • Shell 1.7%
  • C++ 1.3%
  • Makefile 0.8%
  • Other 0.4%
Find a file
Pavel Punsky d8107aff80
build: pin openssl@3 on macOS CI and reject mixed OpenSSL majors (#2095)
## Problem

Every macOS job in CI currently fails: `turnserver` segfaults on the
first TLS client in `examples/run_tests.sh` (e.g. run 37231739523 on
#2093, which only touches `dbd_sqlite.c`).

Cause: Homebrew's `openssl` formula now resolves to `openssl@4` (4.0.3),
but the libevent bottle's `libevent_openssl` still links `openssl@3`.
coturn builds against OpenSSL 4 and passes its `SSL*` to libevent
running on OpenSSL 3 via `bufferevent_openssl_socket_new`, which crashes
in `SSL_set_bio`. macOS two-level namespaces keep both copies loaded.

## Changes

- `.github/workflows/macos.yml`: install `openssl@3` and export
`OPENSSL_ROOT_DIR` / `PKG_CONFIG_PATH` for both the autotools and CMake
jobs.
- `cmake/CheckLibeventOpenSSL.cmake` (new), used from
`src/apps/common/CMakeLists.txt`: on macOS, fail configure when
`libevent_openssl` links a different OpenSSL major than the one found.
- `configure`: same check for the autotools build (Darwin only).
- `TURN_ALLOW_OPENSSL_MISMATCH` (CMake option / env var) overrides the
check.

## Testing

On macOS (both `openssl@3` 3.6.5 and `openssl@4` 4.0.3 installed):
- CMake configure with the default OpenSSL (`openssl@4`) fails with the
new error. With `-DOPENSSL_ROOT_DIR=$(brew --prefix openssl@3)` it
passes, and `-DTURN_ALLOW_OPENSSL_MISMATCH=ON` also passes.
- `./configure` with `openssl@4` first on `PKG_CONFIG_PATH` aborts; with
`openssl@3` first it passes, and the override also passes.
- With the `openssl@3` build: `ctest` 21/21, and `run_tests.sh`
(TCP/TLS/UDP/DTLS), `run_tests_conf`, `dtls_default`, `ipv6_relay`,
`mobility_quota`, `mobility_resume_flood`, `stateless_binding`,
`stateless_nonce` all pass with no FAIL or segfault.

On Linux (Docker): CMake configure, build and `ctest` (20/20) pass; the
check is a no-op there. I did not complete the Linux `run_tests*.sh`
pass.

The PR's own macOS CI jobs are the real end-to-end check.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-04 13:59:16 -07:00
.github build: pin openssl@3 on macOS CI and reject mixed OpenSSL majors (#2095) 2026-10-04 13:59:16 -07:00
.vscode Fixes: run_tests.sh and no db (#1834) 2026-03-12 22:01:28 -07:00
cmake build: pin openssl@3 on macOS CI and reject mixed OpenSSL majors (#2095) 2026-10-04 13:59:16 -07:00
docker docker: Upgrade Coturn to 4.18.0 version 2026-09-08 13:15:43 +02:00
docs Deprecate option drop-invalid-packets (#2078) 2026-09-07 13:44:29 -07:00
examples Update help with missing arguments (#2079) 2026-09-07 15:43:30 -07:00
filc Filc harness and pointer typedefs (#1896) 2026-05-04 18:49:18 -07:00
fuzzing Add --stateless-nonce: bound memory under valid-structure STUN floods (#1999) (#2002) 2026-07-25 16:16:01 -07:00
man/man1 Advertise IPv6 allocations under their real relayed transport address (#2058) 2026-08-23 13:52:18 -07:00
patches/openssl-1.1.1 Add out-of-tree patch to restore deprecated OpenSSL 1.1.1 support (#1952) 2026-06-20 14:34:29 -07:00
rpm Update version to 4.8.0 (#1791) 2026-01-05 17:35:27 -08:00
scripts Update config and Readme files about deprecated TLSv1/1.1 (#1848) 2026-04-05 20:49:46 -07:00
src build: pin openssl@3 on macOS CI and reject mixed OpenSSL majors (#2095) 2026-10-04 13:59:16 -07:00
tests reject a mismatched realm on connection-bind in check_stun_auth (#2087) 2026-10-01 22:18:53 -07:00
turndb Add hash algorithm for key value to redis userdb schema 2021-01-14 09:57:10 -06:00
.clang-format Improve const correctness in coturn (#1424) 2025-09-08 21:14:56 -07:00
.clang-tidy Improve const correctness in coturn (#1424) 2025-09-08 21:14:56 -07:00
.dockerignore Avoid duplication via common rootfs/ dir 2021-04-20 10:36:52 +03:00
.gitignore Adapt .gitignore to allow files already in repo (#1935) (#1936) 2026-06-09 22:58:29 -07:00
AUTHORS.md Update version to 4.18.0 2026-09-07 15:45:21 -07:00
authors.sh Update version to 4.16.0 2026-07-26 23:27:56 -07:00
ChangeLog Update version to 4.18.0 2026-09-07 15:45:21 -07:00
CLAUDE.md Update help with missing arguments (#2079) 2026-09-07 15:43:30 -07:00
CMakeLists.txt Update version to 4.18.0 2026-09-07 15:45:21 -07:00
configure build: pin openssl@3 on macOS CI and reject mixed OpenSSL majors (#2095) 2026-10-04 13:59:16 -07:00
CONTRIBUTING.md Update CONTRIBUTING.md 2023-01-09 19:27:00 +01:00
INSTALL Move and split documentation files (#1096) 2022-12-22 11:13:24 -08:00
iwyu-ubuntu.imp Add clang-tidy, include-what-you-use, and msvc-analyzer github actions (#1363) 2024-01-16 19:49:30 -08:00
LICENSE initial code import 2014-04-20 21:10:18 +00:00
make-man.sh man pages util fixed 2017-02-20 01:10:38 -08:00
Makefile.in multiplex-peer: bound the shared per-thread peer demux table (#2017) 2026-07-26 19:56:41 -07:00
postinstall.txt Move and split documentation files (#1096) 2022-12-22 11:13:24 -08:00
README.md Document RFC 8489 and RFC 8656 instead of only the specs they obsolete (#2049) 2026-08-11 20:32:04 -07:00
README.turnadmin Regenerate manual pages from README files (#1117) 2022-12-06 17:04:13 -08:00
README.turnserver Update help with missing arguments (#2079) 2026-09-07 15:43:30 -07:00
README.turnutils Add continuous latency mode to stunclient (#1937) 2026-06-09 23:21:14 -07:00
release.sh Update version to 4.7.0 (#1691) 2025-05-30 14:13:59 -07:00
STATUS.md Document RFC 8489 and RFC 8656 instead of only the specs they obsolete (#2049) 2026-08-11 20:32:04 -07:00
vcpkg.json Build Prometheus exporter from vendored local sources (#1955) 2026-06-20 18:58:30 -07:00

Docker CI Docker Hub Fuzzing Status Ask DeepWiki

Docker Hub | GitHub Container Registry | Quay.io

Coturn TURN server

coturn is a free open source implementation of TURN and STUN Server. The TURN Server is a VoIP media traffic NAT traversal server and gateway.

Installing / Getting started

Linux distros may have a version of coturn which you can install by

apt install coturn
turnserver --log-file stdout

Or run coturn using docker container:

docker run -d -p 3478:3478 -p 3478:3478/udp -p 5349:5349 -p 5349:5349/udp -p 49152-65535:49152-65535/udp coturn/coturn

See more details about using docker container Docker Readme

Developing

Dependencies

coturn requires following dependencies to be installed first

  • libevent2
  • libmicrohttpd (Prometheus metrics interface)

Optional

  • openssl 3.0 or newer (to support TLS and DTLS, authorized STUN and TURN); older OpenSSL versions are not supported
  • MariaDB/MySQL (user database)
  • Hiredis (user database, monitoring)
  • SQLite (user database)
  • PostgreSQL (user database)

Building

git clone git@github.com:coturn/coturn.git
cd coturn
./configure
make

Features

STUN specs:

  • RFC 3489 - "classic" STUN (DEPRECATED, opt-in via --rfc3489-compatibility; scheduled for removal in the next major release — see docs/rfc3489-deprecation.md)
  • RFC 5389 - base "new" STUN specs (obsoleted by RFC 8489)
  • RFC 8489 - STUN, obsoleting RFC 5389. Its message-processing rules are implemented: attributes following MESSAGE-INTEGRITY are ignored, repeated attributes are first-wins, and ERROR-CODE reason phrases are declared without their padding. Its authentication additions are not implemented - MESSAGE-INTEGRITY-SHA256, PASSWORD-ALGORITHMS, PASSWORD-ALGORITHM, USERHASH and the nonce cookie are all absent, so an RFC 8489 client falls back to that spec's MD5 key derivation with SHA-1 MESSAGE-INTEGRITY, which RFC 8489 permits.
  • RFC 5769 - test vectors for STUN protocol testing
  • RFC 5780 - NAT behavior discovery support
  • RFC 7350 - DTLS as transport for STUN & TURN
  • RFC 7443 - ALPN support for STUN & TURN
  • RFC 7635 - oAuth third-party TURN/STUN authorization

TURN specs:

ICE and related specs:

The implementation fully supports the following client-to-TURN-server protocols:

  • UDP (per RFC 8656)
  • TCP (per RFC 8656 and RFC 6062)
  • TLS (per RFC 8656 and RFC 6062): including TLS1.3; ECDHE is supported.
  • DTLS1.0 and DTLS1.2 (per RFC 7350): the DTLS listeners are not started unless --dtls is given.
  • SCTP (experimental implementation).

Relay protocols:

User databases (for user repository, with passwords or keys, if authentication is required):

  • SQLite
  • MariaDB/MySQL
  • PostgreSQL
  • Redis
  • MongoDB

Management interfaces:

  • telnet cli
  • HTTPS interface

Monitoring:

  • Redis can be used for status and statistics storage and notification
  • prometheus interface (unavailable on apt package)

Message integrity digest algorithms:

  • HMAC-SHA1, with MD5-hashed keys (as required by STUN and TURN standards)

TURN authentication mechanisms:

  • 'classic' long-term credentials mechanism;
  • TURN REST API (a modification of the long-term mechanism, for time-limited secret-based authentication, for WebRTC applications: http://tools.ietf.org/html/draft-uberti-behave-turn-rest-00);
  • experimental third-party oAuth-based client authorization option;

Performance and Load Balancing:

When used as a part of an ICE solution, for VoIP connectivity, this TURN server can handle thousands simultaneous calls per CPU (when TURN protocol is used) or tens of thousands calls when only STUN protocol is used. For virtually unlimited scalability a load balancing scheme can be used. The load balancing can be implemented with the following tools (either one or a combination of them):

  • DNS SRV based load balancing;
  • built-in 300 ALTERNATE-SERVER mechanism (requires 300 response support by the TURN client);
  • network load-balancer server.

Traffic bandwidth limitation and congestion avoidance algorithms implemented.

Target platforms:

  • Linux (Debian, Ubuntu, Mint, CentOS, Fedora, Redhat, Amazon Linux, Arch Linux, OpenSUSE)
  • BSD (FreeBSD, NetBSD, OpenBSD, DragonFlyBSD)
  • Solaris 11
  • Mac OS X
  • Cygwin (for non-production R&D purposes)
  • Windows (native with, e.g., MSVC toolchain)

This project can be successfully used on other *NIX platforms, too, but that is not officially supported.

The implementation is supposed to be simple, easy to install and configure. The project focuses on performance, scalability and simplicity. The aim is to provide an enterprise-grade TURN solution.

To achieve high performance and scalability, the TURN server is implemented with the following features:

  • On linux platform, where available, UDP high throughput is achieved through recvmmsg/sendmmsg/GSO combination
  • High-performance industrial-strength Network IO engine libevent2 in other cases
  • Multiple listening and relay addresses can be configured
  • Efficient per-thread memory allocation model is used
  • The TURN project code can be used in a custom proprietary networking environment. In the TURN server code, an abstract networking API is used. Only couple files in the project have to be re-written to plug-in the TURN server into a proprietary environment. With this project, only implementation for standard UNIX Networking/IO API is provided, but the user can implement any other environment. The TURN server code was originally developed for a high-performance proprietary corporate environment, then adopted for UNIX Networking API
  • The TURN server works as a user space process, without imposing any special requirements on the system