Hi,

we are promoting usage of Kurento out of the box. We use HTTPS and wss.

That secures the transport layer.

As well as there might be something we can do with Content Security Policy
and same origin principle (although this may not really apply in a
clustered scenario).

But I don't quite understand if and how it would for instance prevent
somebody from another application connect to our Media Server. And using it
as an open relay. Kurento wouldn't block it would it?

I understand this would probably require some modifications on Kurento side
too, to block un-authorised users. Kurento Security just refers to
transport layer security again:
https://doc-kurento.readthedocs.io/en/stable/features/security.html

Which could be my misunderstanding, but it seems there is something missing.

Thanks,
Seb
-- 
Sebastian Wagner
https://twitter.com/#!/dead_lock
seba.wag...@gmail.com

Reply via email to