部署coturn TURN服务器遇认证失败:无法找到用户凭证
Hey there, let's work through this authentication failed issue you're hitting with your coturn server. The error ERROR: check_stun_auth: Cannot find credentials of user makes it clear that the server can't match the credentials Trickle ICE is sending with what's configured on your end. Let's break down the fixes step by step.
首先,补全并确认你的coturn配置
From what you shared, your static-auth-secret line looks truncated (static-auth-se...). First, make sure this line is complete and uses a strong, random secret. For example:
external-ip=39.108.74.114/XXX.XXX.XXX.XXX # 替换成正确的内网IP fingerprint lt-cred-mech use-auth-secret static-auth-secret=your_strong_random_secret_here # 这里要写完整的密钥,别用简单字符串
The lt-cred-mech flag you've enabled uses timestamp-based temporary credentials paired with your static secret—this means you can't use a plain static username/password in Trickle ICE directly.
生成Trickle ICE所需的临时凭证
Since you're using the long-term credential mechanism (lt-cred-mech) with a static secret, you need to generate a time-bound username and corresponding HMAC-SHA1 password:
- Generate a valid timestamp (we'll use a timestamp 5 minutes in the future to avoid immediate expiration):
timestamp=$(($(date +%s) + 300)) - Generate the password using your static secret (replace
your_strong_random_secret_herewith your actual secret, andwebrtcwith your desired username):echo -n "${timestamp}:webrtc" | openssl dgst -sha1 -hmac "your_strong_random_secret_here" | awk '{print $2}'
在Trickle ICE中正确填写参数
In the Trickle ICE tool, input these values exactly:
- TURN server:
turn:rtc.jackxujh.me:3478 - Username: The full timestamp+username string you generated (e.g.,
1718000000:webrtc) - Password: The HMAC-SHA1 hash output from the previous command
额外检查项
- Double-check that your
external-ipline uses the correct public/private IP pair—no typos in your internal IP address. - Add the
verboseflag to yourturnserver.confand restart the server; this will give you more detailed logs to spot any other misconfigurations. - Verify that your server's firewall/security group allows incoming traffic on port 3478 (both UDP and TCP), since TURN uses both protocols.
After updating your config, restarting coturn, and using the generated temporary credentials in Trickle ICE, the authentication should succeed.
内容的提问来源于stack exchange,提问作者jackxujh

