this post was submitted on 30 Jan 2024
9 points (90.9% liked)

Jellyfin: The Free Software Media System

5750 readers
19 users here now

Current stable release: 10.10.2

Community Standards

Website

Forum

GitHub

Documentation

Feature Requests

Matrix (General Information & Help)

Matrix (Announcements)

Matrix (General Development)

Matrix (Off-Topic) - Come get to know the team and blow off steam!

Matrix Space - List of all the available rooms on Matrix.

Discord - Bridged to our Matrix rooms

founded 4 years ago
MODERATORS
 

I have my JellyFin on a dedicated server outside my home. I use a domain, with and SSH certificate. Before I moved to the domain and the cert I just had an IP:Port setup. At that time JellyFin worked perfectly fine with the windows app, but after moving to the domain and adding an SSH cert, it no longer wants to connect. It works perfectly fine in FIreFox though, so I'm curious if it's worth trying to figure out why it won't work in the app, or is using FireFox just as good.

you are viewing a single comment's thread
view the rest of the comments
[–] stom@lemmy.world 1 points 8 months ago (1 children)

What's the issue? I've run mine exposed for several years...

[–] possiblylinux127@lemmy.zip 1 points 8 months ago* (last edited 8 months ago) (1 children)

That's not a good idea as the internet if full of bots trying to compromise you. It might be fine for a while but when they find a weakness they strike.

You may of already been compromised.

[–] stom@lemmy.world 1 points 8 months ago* (last edited 8 months ago) (1 children)

Does jellyfin have known vulnerabilities for bots to exploit? It's been up for several years with, afaik, no problems.

System has usual steps taken to harden it, JF is behind an apache proxy, letsencrypt handles ssl certs, fail2ban is running, and users are required to have strong passwords with no option to reset or self-register.

[–] possiblylinux127@lemmy.zip 1 points 8 months ago (1 children)

It sounds like you've at least taken some steps to harden. For me it is trivial to use a VPN so that's what I do.

[–] stom@lemmy.world 1 points 8 months ago (1 children)

A VPN would not be practical for my situation, as the instance is used by various family members and friends. I'm happy for them to use my JF instance but I'm not providing VPN services as well.

If you're not referring to any specific vulnerabilities in JF then I feel confident there are no exceptional risks from allowing web access to JF? Just the usual ones?

[–] possiblylinux127@lemmy.zip 1 points 8 months ago (1 children)

You don't need to give them access to a internet connection, just the local device. There are many options for this including Netbird, Tailscale, and just plain old wireguard.

[–] stom@lemmy.world 1 points 8 months ago

That's overly complicated for some of the users - most of them aren't very tech savvy, and they're watching via all kinds of devices - TV's, iOS, Kindle, etc.

I don't see any major security reason for access requiring a VPN. Are there particular vulnerabilities that you're concerned about, or just those that generally come from having a web-facing service?