Jitsi Meet is an open-source, WebRTC-based video conferencing platform that runs in the browser and in the Jitsi mobile apps. In this guide you will install Jitsi Meet on Ubuntu 24.04 from the official Jitsi repository, secure it with a Let's Encrypt certificate, open the required firewall ports, and restrict meeting creation to users with a password while guests can still join.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS with a public IP address, for example a CubePath VPS. Plan for at least 2 vCPUs and 4 GB of RAM; 8 GB is recommended for regular meetings with many participants.
  • A non-root user with sudo privileges.
  • A domain name with a DNS A record for the subdomain you will use, for example meet.your_domain, pointing to your server's public IP. Let's Encrypt needs this record to issue the certificate.
  • No other web server listening on ports 80 and 443. The Jitsi installer configures Nginx for you.

In this guide, replace meet.your_domain with your own host name and your_server_ip with the server's public IP.

Step 1 - Setting the host name

Jitsi uses the server's fully qualified domain name (FQDN) for its internal XMPP domains and web configuration. Set it before installing:

sudo hostnamectl set-hostname meet.your_domain

Then map the name to the server's public IP in /etc/hosts:

sudo nano /etc/hosts

Add this line below the 127.0.0.1 localhost entry:

your_server_ip meet.your_domain

Check that the name resolves locally:

ping -c 1 "$(hostname)"
PING meet.your_domain (your_server_ip) 56(84) bytes of data.
64 bytes from meet.your_domain (your_server_ip): icmp_seq=1 ttl=64 time=0.030 ms

Step 2 - Opening the firewall

Jitsi needs HTTP for the Let's Encrypt challenge, HTTPS for the web app and signaling, and UDP 10000 for the audio and video streams handled by the Jitsi Videobridge. The installer also sets up a coturn TURN server on 5349/TCP (and STUN on 3478/UDP) for participants on networks that block UDP.

Allow SSH first so you keep access to the server, then the Jitsi ports:

sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 10000/udp
sudo ufw allow 3478/udp
sudo ufw allow 5349/tcp
sudo ufw enable

Verify the rules:

sudo ufw status
Status: active

To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
80/tcp                     ALLOW       Anywhere
443/tcp                    ALLOW       Anywhere
10000/udp                  ALLOW       Anywhere
3478/udp                   ALLOW       Anywhere
5349/tcp                   ALLOW       Anywhere
...

Step 3 - Adding the Prosody and Jitsi repositories

Jitsi Meet uses Prosody as its XMPP signaling server. The Jitsi project recommends installing Prosody from the upstream Prosody repository so you get a version that supports features such as the lobby. Both repositories are signed, and you will store their keys in /etc/apt/keyrings.

Install the tools needed to add the repositories:

sudo apt update
sudo apt install curl gnupg apt-transport-https
sudo install -m 0755 -d /etc/apt/keyrings

Add the Prosody repository. Its key is already in binary format, so it can be saved directly:

sudo curl -fsSL https://prosody.im/files/prosody-debian-packages.key -o /etc/apt/keyrings/prosody.gpg
echo "deb [signed-by=/etc/apt/keyrings/prosody.gpg] http://packages.prosody.im/debian $(lsb_release -sc) main" | sudo tee /etc/apt/sources.list.d/prosody.list

Add the Jitsi repository. Its key is ASCII-armored, so convert it with gpg --dearmor:

curl -fsSL https://download.jitsi.org/jitsi-key.gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/jitsi.gpg
echo "deb [signed-by=/etc/apt/keyrings/jitsi.gpg] https://download.jitsi.org stable/" | sudo tee /etc/apt/sources.list.d/jitsi-stable.list

Refresh the package index and install lua5.2, which the Jitsi Prosody plugins require:

sudo apt update
sudo apt install lua5.2

Confirm that apt now sees the Jitsi package:

apt-cache policy jitsi-meet
jitsi-meet:
  Installed: (none)
  Candidate: 2.0.xxxx-1
  Version table:
     2.0.xxxx-1 500
        500 https://download.jitsi.org stable/ Packages

Step 4 - Installing Jitsi Meet

Install the jitsi-meet meta package. It pulls in Prosody, Jicofo (the conference focus), Jitsi Videobridge, the web app, Nginx and coturn:

sudo apt install jitsi-meet

The installer asks a few questions:

  1. Host name: enter meet.your_domain.
  2. SSL certificate: choose Let's Encrypt certificates and enter an email address for expiry notices. The installer requests the certificate and configures automatic renewal. Avoid the self-signed option: browsers show warnings and the Jitsi mobile apps refuse to connect to servers with self-signed certificates.
  3. If you are asked about optional extras such as telephony access, you can decline them for now.

When the installation finishes, check that the four core services are running:

sudo systemctl status prosody jicofo jitsi-videobridge2 nginx --no-pager | grep -E '●|Active'
● prosody.service - Prosody XMPP Server
     Active: active (running) since ...
● jicofo.service - Jitsi Conference Focus
     Active: active (running) since ...
● jitsi-videobridge2.service - Jitsi Videobridge
     Active: active (running) since ...
● nginx.service - A high performance web server and a reverse proxy server
     Active: active (running) since ...

Confirm that the Videobridge is listening for media on UDP 10000:

sudo ss -ulpn | grep 10000
UNCONN 0      0        *:10000      *:*    users:(("java",pid=2345,fd=180))

Step 5 - Testing your first meeting

Open https://meet.your_domain in a browser. You should see the Jitsi welcome page with a valid certificate. Enter a room name and click Start meeting, allow access to your camera and microphone, and join.

A meeting with a single participant does not prove that media relaying works, because nothing is being routed yet. Join the same room from a second device, ideally on a different network such as a phone on mobile data, and make sure both participants can see and hear each other. With three or more participants all streams go through the Videobridge on UDP 10000, so test with three if you can.

Step 6 - Restricting who can create meetings

By default anyone who reaches your server can create rooms. To stop your server being used by strangers, enable the "secure domain" setup: users must log in with a username and password to create a room, while guests join existing rooms anonymously.

Configuring Prosody

Open the Prosody configuration for your domain:

sudo nano /etc/prosody/conf.avail/meet.your_domain.cfg.lua

Find the VirtualHost "meet.your_domain" block and change its authentication line (currently jitsi-anonymous or anonymous) to use hashed passwords:

VirtualHost "meet.your_domain"
    authentication = "internal_hashed"

Leave the rest of that block unchanged. Then, after the end of that VirtualHost block, add a new virtual host for guests:

VirtualHost "guest.meet.your_domain"
    authentication = "jitsi-anonymous"
    c2s_require_encryption = false

The guest. domain is internal to Jitsi: you do not need a DNS record or a certificate for it.

Configuring the web app

Open the client configuration:

sudo nano /etc/jitsi/meet/meet.your_domain-config.js

Inside the hosts object, add the anonymousdomain line after domain:

    hosts: {
        domain: 'meet.your_domain',
        anonymousdomain: 'guest.meet.your_domain',
        // keep the other existing entries
    },

Watch the commas: a syntax error in this file breaks the web app.

Configuring Jicofo

Jicofo must only accept new conferences from authenticated users. Open its configuration:

sudo nano /etc/jitsi/jicofo/jicofo.conf

Add an authentication section inside the existing jicofo { ... } block. Do not create a second jicofo block:

jicofo {
  authentication: {
    enabled: true
    type: XMPP
    login-url: meet.your_domain
  }
  // existing xmpp { ... } section stays here
}

Creating users and restarting

Create an account for each person who should be able to start meetings. The command prompts for the password twice:

sudo prosodyctl adduser [email protected]_domain

Restart the services to apply the changes:

sudo systemctl restart prosody jicofo jitsi-videobridge2

Open https://meet.your_domain in a private browser window and start a meeting. Jitsi now shows a Waiting for the host message with a Log in button. After you log in as alice, the room is created, and anyone with the link can join as a guest.

To remove a user later:

sudo prosodyctl deluser [email protected]_domain

Step 7 - Adjusting common client options

Most user-facing behavior is controlled from /etc/jitsi/meet/meet.your_domain-config.js. The file is well commented, and most options are already present but commented out. A few that are often changed:

    // Join with microphone and camera off
    startWithAudioMuted: true,
    startWithVideoMuted: true,

    // Show the pre-join screen to test camera and microphone
    prejoinConfig: {
        enabled: true,
    },

    // Require participants to enter a name
    requireDisplayName: true,

This file is loaded by the browser, so no service restart is needed: reload the meeting page to see the change. Keep a copy of your changes, because package upgrades may ask whether to replace the file with the new default.

Troubleshooting

Participants can join but cannot see or hear each other, especially with three or more people. UDP 10000 is almost always the cause. Check the UFW rule and any external firewall, then look at the Videobridge log:

sudo tail -n 50 /var/log/jitsi/jvb.log

If the server has a private IP behind NAT, the Videobridge needs a static mapping between its private and public address in /etc/jitsi/videobridge/jvb.conf under ice4j.harvest.mapping.static-mappings.

The Let's Encrypt step failed during installation. Make sure the A record points to the server and that port 80 is open, then run the certificate script shipped with Jitsi:

sudo /usr/share/jitsi-meet/scripts/install-letsencrypt-cert.sh

Login prompt does not appear or always fails. Check Prosody and Jicofo logs for configuration errors:

sudo tail -n 50 /var/log/prosody/prosody.log
sudo tail -n 50 /var/log/jitsi/jicofo.log

Also confirm that the user was created on the main domain ([email protected]_domain), not on the guest. domain.

Conclusion

You now have a self-hosted Jitsi Meet server on Ubuntu 24.04 with a trusted certificate, the right firewall rules and password-protected room creation. As next steps, you can raise the systemd process and file limits described in the Jitsi handbook before hosting meetings with more than 100 participants, add recording with Jibri on a separate server, or add more Videobridge nodes to spread the media load.