Jitsi Meet is an open-source, WebRTC-based video conferencing platform that runs in the browser and in the Jitsi mobile apps. In this guide you will install Jitsi Meet on Ubuntu 24.04 from the official Jitsi repository, secure it with a Let's Encrypt certificate, open the required firewall ports, and restrict meeting creation to users with a password while guests can still join.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS with a public IP address, for example a CubePath VPS. Plan for at least 2 vCPUs and 4 GB of RAM; 8 GB is recommended for regular meetings with many participants.
- A non-root user with
sudoprivileges. - A domain name with a DNS
Arecord for the subdomain you will use, for examplemeet.your_domain, pointing to your server's public IP. Let's Encrypt needs this record to issue the certificate. - No other web server listening on ports 80 and 443. The Jitsi installer configures Nginx for you.
In this guide, replace meet.your_domain with your own host name and your_server_ip with the server's public IP.
Step 1 - Setting the host name
Jitsi uses the server's fully qualified domain name (FQDN) for its internal XMPP domains and web configuration. Set it before installing:
sudo hostnamectl set-hostname meet.your_domain
Then map the name to the server's public IP in /etc/hosts:
sudo nano /etc/hosts
Add this line below the 127.0.0.1 localhost entry:
your_server_ip meet.your_domain
Check that the name resolves locally:
ping -c 1 "$(hostname)"
PING meet.your_domain (your_server_ip) 56(84) bytes of data.
64 bytes from meet.your_domain (your_server_ip): icmp_seq=1 ttl=64 time=0.030 ms
Step 2 - Opening the firewall
Jitsi needs HTTP for the Let's Encrypt challenge, HTTPS for the web app and signaling, and UDP 10000 for the audio and video streams handled by the Jitsi Videobridge. The installer also sets up a coturn TURN server on 5349/TCP (and STUN on 3478/UDP) for participants on networks that block UDP.
Allow SSH first so you keep access to the server, then the Jitsi ports:
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 10000/udp
sudo ufw allow 3478/udp
sudo ufw allow 5349/tcp
sudo ufw enable
Verify the rules:
sudo ufw status
Status: active
To Action From
-- ------ ----
OpenSSH ALLOW Anywhere
80/tcp ALLOW Anywhere
443/tcp ALLOW Anywhere
10000/udp ALLOW Anywhere
3478/udp ALLOW Anywhere
5349/tcp ALLOW Anywhere
...
Step 3 - Adding the Prosody and Jitsi repositories
Jitsi Meet uses Prosody as its XMPP signaling server. The Jitsi project recommends installing Prosody from the upstream Prosody repository so you get a version that supports features such as the lobby. Both repositories are signed, and you will store their keys in /etc/apt/keyrings.
Install the tools needed to add the repositories:
sudo apt update
sudo apt install curl gnupg apt-transport-https
sudo install -m 0755 -d /etc/apt/keyrings
Add the Prosody repository. Its key is already in binary format, so it can be saved directly:
sudo curl -fsSL https://prosody.im/files/prosody-debian-packages.key -o /etc/apt/keyrings/prosody.gpg
echo "deb [signed-by=/etc/apt/keyrings/prosody.gpg] http://packages.prosody.im/debian $(lsb_release -sc) main" | sudo tee /etc/apt/sources.list.d/prosody.list
Add the Jitsi repository. Its key is ASCII-armored, so convert it with gpg --dearmor:
curl -fsSL https://download.jitsi.org/jitsi-key.gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/jitsi.gpg
echo "deb [signed-by=/etc/apt/keyrings/jitsi.gpg] https://download.jitsi.org stable/" | sudo tee /etc/apt/sources.list.d/jitsi-stable.list
Refresh the package index and install lua5.2, which the Jitsi Prosody plugins require:
sudo apt update
sudo apt install lua5.2
Confirm that apt now sees the Jitsi package:
apt-cache policy jitsi-meet
jitsi-meet:
Installed: (none)
Candidate: 2.0.xxxx-1
Version table:
2.0.xxxx-1 500
500 https://download.jitsi.org stable/ Packages
Step 4 - Installing Jitsi Meet
Install the jitsi-meet meta package. It pulls in Prosody, Jicofo (the conference focus), Jitsi Videobridge, the web app, Nginx and coturn:
sudo apt install jitsi-meet
The installer asks a few questions:
- Host name: enter
meet.your_domain. - SSL certificate: choose Let's Encrypt certificates and enter an email address for expiry notices. The installer requests the certificate and configures automatic renewal. Avoid the self-signed option: browsers show warnings and the Jitsi mobile apps refuse to connect to servers with self-signed certificates.
- If you are asked about optional extras such as telephony access, you can decline them for now.
When the installation finishes, check that the four core services are running:
sudo systemctl status prosody jicofo jitsi-videobridge2 nginx --no-pager | grep -E '●|Active'
● prosody.service - Prosody XMPP Server
Active: active (running) since ...
● jicofo.service - Jitsi Conference Focus
Active: active (running) since ...
● jitsi-videobridge2.service - Jitsi Videobridge
Active: active (running) since ...
● nginx.service - A high performance web server and a reverse proxy server
Active: active (running) since ...
Confirm that the Videobridge is listening for media on UDP 10000:
sudo ss -ulpn | grep 10000
UNCONN 0 0 *:10000 *:* users:(("java",pid=2345,fd=180))
Step 5 - Testing your first meeting
Open https://meet.your_domain in a browser. You should see the Jitsi welcome page with a valid certificate. Enter a room name and click Start meeting, allow access to your camera and microphone, and join.
A meeting with a single participant does not prove that media relaying works, because nothing is being routed yet. Join the same room from a second device, ideally on a different network such as a phone on mobile data, and make sure both participants can see and hear each other. With three or more participants all streams go through the Videobridge on UDP 10000, so test with three if you can.
Step 6 - Restricting who can create meetings
By default anyone who reaches your server can create rooms. To stop your server being used by strangers, enable the "secure domain" setup: users must log in with a username and password to create a room, while guests join existing rooms anonymously.
NoteThe Jitsi project now recommends JWT authentication for new integrations with external identity systems. The username and password setup below still works and is the simplest option for a small team.
Configuring Prosody
Open the Prosody configuration for your domain:
sudo nano /etc/prosody/conf.avail/meet.your_domain.cfg.lua
Find the VirtualHost "meet.your_domain" block and change its authentication line (currently jitsi-anonymous or anonymous) to use hashed passwords:
VirtualHost "meet.your_domain"
authentication = "internal_hashed"
Leave the rest of that block unchanged. Then, after the end of that VirtualHost block, add a new virtual host for guests:
VirtualHost "guest.meet.your_domain"
authentication = "jitsi-anonymous"
c2s_require_encryption = false
The guest. domain is internal to Jitsi: you do not need a DNS record or a certificate for it.
Configuring the web app
Open the client configuration:
sudo nano /etc/jitsi/meet/meet.your_domain-config.js
Inside the hosts object, add the anonymousdomain line after domain:
hosts: {
domain: 'meet.your_domain',
anonymousdomain: 'guest.meet.your_domain',
// keep the other existing entries
},
Watch the commas: a syntax error in this file breaks the web app.
Configuring Jicofo
Jicofo must only accept new conferences from authenticated users. Open its configuration:
sudo nano /etc/jitsi/jicofo/jicofo.conf
Add an authentication section inside the existing jicofo { ... } block. Do not create a second jicofo block:
jicofo {
authentication: {
enabled: true
type: XMPP
login-url: meet.your_domain
}
// existing xmpp { ... } section stays here
}
Creating users and restarting
Create an account for each person who should be able to start meetings. The command prompts for the password twice:
sudo prosodyctl adduser [email protected]_domain
Restart the services to apply the changes:
sudo systemctl restart prosody jicofo jitsi-videobridge2
Open https://meet.your_domain in a private browser window and start a meeting. Jitsi now shows a Waiting for the host message with a Log in button. After you log in as alice, the room is created, and anyone with the link can join as a guest.
To remove a user later:
sudo prosodyctl deluser [email protected]_domain
Step 7 - Adjusting common client options
Most user-facing behavior is controlled from /etc/jitsi/meet/meet.your_domain-config.js. The file is well commented, and most options are already present but commented out. A few that are often changed:
// Join with microphone and camera off
startWithAudioMuted: true,
startWithVideoMuted: true,
// Show the pre-join screen to test camera and microphone
prejoinConfig: {
enabled: true,
},
// Require participants to enter a name
requireDisplayName: true,
This file is loaded by the browser, so no service restart is needed: reload the meeting page to see the change. Keep a copy of your changes, because package upgrades may ask whether to replace the file with the new default.
Troubleshooting
Participants can join but cannot see or hear each other, especially with three or more people. UDP 10000 is almost always the cause. Check the UFW rule and any external firewall, then look at the Videobridge log:
sudo tail -n 50 /var/log/jitsi/jvb.log
If the server has a private IP behind NAT, the Videobridge needs a static mapping between its private and public address in /etc/jitsi/videobridge/jvb.conf under ice4j.harvest.mapping.static-mappings.
The Let's Encrypt step failed during installation. Make sure the A record points to the server and that port 80 is open, then run the certificate script shipped with Jitsi:
sudo /usr/share/jitsi-meet/scripts/install-letsencrypt-cert.sh
Login prompt does not appear or always fails. Check Prosody and Jicofo logs for configuration errors:
sudo tail -n 50 /var/log/prosody/prosody.log
sudo tail -n 50 /var/log/jitsi/jicofo.log
Also confirm that the user was created on the main domain ([email protected]_domain), not on the guest. domain.
Conclusion
You now have a self-hosted Jitsi Meet server on Ubuntu 24.04 with a trusted certificate, the right firewall rules and password-protected room creation. As next steps, you can raise the systemd process and file limits described in the Jitsi handbook before hosting meetings with more than 100 participants, add recording with Jibri on a separate server, or add more Videobridge nodes to spread the media load.
