# Accessing streams via HTTPS not working

**URL:** <https://community.wowza.com/t/accessing-streams-via-https-not-working/43907>\
**Category:** Wowza Streaming Engine\
**Tags:** server-administration\
**Created:** [October 13, 2014, 9:46pm UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907 "2014-10-13T21:46:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Collins](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@Dave\_Collins](https://community.wowza.com/u/Dave_Collins)\
**Post date:** [October 13, 2014, 9:46pm UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/1 "2014-10-13T21:46:10Z")

</div>

Hello,

Using Wowza streaming engine on AWS and streaming via regular HTTP is working with a DASH player. need to get it working via HTTPS.

I followed the instructions in the “[How to request an SSL certificate from a certificate authority](https://www.wowza.com/docs/how-to-request-an-ssl-certificate-from-a-certificate-authority)” article, obtained and installed a cert and adjusted the VHost.xml file to uncomment the section. Ensured that our DNS had [sentryvidserv.us](http://sentryvidserv.us) pointing at our AWS instance.

Test player still works when using HTTP and the old port. Also works if I use http and the domain name:

```auto
http://sentryvidserv.us:1935/mps/my-stream-name/manifest.f4m

```

Also works if I use http and port 443 (which seems odd to me)

```auto
http://sentryvidserv.us:443/mps/my-stream-name/manifest.f4m

```

However, I cannot get any form of httpS to play a stream. I’ve tried 443 and 1935. MPEG-DASH and Adobe HDS. I feel like there must be a configuration step that was missed.

Here are the commands I used:

```auto
sudo keytool -genkey -keysize 2048 -alias wowza -keyalg RSA -keystore sentryvidserv.us.jks

```

(gave it [sentryvidserv.us](http://sentryvidserv.us) as the first and last name)

```auto
sudo keytool -certreq -file sentryvidserv.us.csr -alias wowza -keyalg RSA -keystore sentryvidserv.us.jks

```

When I received the certs, I installed them:

```auto
sudo keytool -import -alias root -trustcacerts -file DigiCertCA.crt -keystore sentryvidserv.us.jks
sudo keytool -import -alias wowza -trustcacerts -file sentryvidserv_us.crt -keystore ssl.mycompany.com.jks

```

Here is the result of keytool -list -keystore sentryvidserv.us.jks

```auto
Enter keystore password:  
Keystore type: JKS
Keystore provider: SUN
Your keystore contains 2 entries
root, Oct 10, 2014, trustedCertEntry, 
Certificate fingerprint (SHA1): 1F:B8:6B:11:68:........:71:A4:B7:CC:B4
wowza, Oct 10, 2014, PrivateKeyEntry, 
Certificate fingerprint (SHA1): 43:AF:E0:BC:26:.......:A8:CB:CA:54:02:2B:AE:70

```

Here is the section of VHost.xml:

```auto
<HostPort>
				<Name>Default SSL Streaming</Name>
				<Type>Streaming</Type>
				<ProcessorCount>${com.wowza.wms.TuningAuto}</ProcessorCount>
				<IpAddress>*</IpAddress>
				<Port>443</Port>
				<HTTPIdent2Response></HTTPIdent2Response>
				<SSLConfig>
					<KeyStorePath>${com.wowza.wms.context.VHostConfigHome}/conf/sentryvidserv.us.jks</KeyStorePath>
					<KeyStorePassword>S3ntryK3ySt0re</KeyStorePassword>
					<KeyStoreType>JKS</KeyStoreType>
					<SSLProtocol>TLS</SSLProtocol>
					<Algorithm>SunX509</Algorithm>
					<CipherSuites></CipherSuites>
					<Protocols></Protocols>
				</SSLConfig>
				<SocketConfiguration>
					<ReuseAddress>true</ReuseAddress>
					<ReceiveBufferSize>65000</ReceiveBufferSize>
					<ReadBufferSize>65000</ReadBufferSize>
					<SendBufferSize>65000</SendBufferSize>
					<KeepAlive>true</KeepAlive>
					<AcceptorBackLog>100</AcceptorBackLog>
				</SocketConfiguration>
				<HTTPStreamerAdapterIDs>cupertinostreaming,smoothstreaming,sanjosestreaming,dvrchunkstreaming,mpegdashstreaming</HTTPStreamerAdapterIDs>
				<HTTPProviders>
					<HTTPProvider>
						<BaseClass>com.wowza.wms.http.HTTPCrossdomain</BaseClass>
						<RequestFilters>*crossdomain.xml</RequestFilters>
						<AuthenticationMethod>none</AuthenticationMethod>
					</HTTPProvider>
					<HTTPProvider>
						<BaseClass>com.wowza.wms.http.HTTPClientAccessPolicy</BaseClass>
						<RequestFilters>*clientaccesspolicy.xml</RequestFilters>
						<AuthenticationMethod>none</AuthenticationMethod>
					</HTTPProvider>
					<HTTPProvider>
						<BaseClass>com.wowza.wms.http.HTTPProviderMediaList</BaseClass>
						<RequestFilters>*jwplayer.rss|*jwplayer.smil|*medialist.smil|*manifest-rtmp.f4m</RequestFilters>
						<AuthenticationMethod>none</AuthenticationMethod>
					</HTTPProvider>
					<HTTPProvider>
						<BaseClass>com.wowza.wms.http.HTTPServerVersion</BaseClass>
						<RequestFilters>*</RequestFilters>
						<AuthenticationMethod>none</AuthenticationMethod>
					</HTTPProvider>
				</HTTPProviders>
			</HostPort>

```

What else needs to be done to enable streaming over HTTPS??

Many thanks,

Dave

---

<div class="post-metadata">

**Author:** ![sal\_jefferson](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@sal\_jefferson](https://community.wowza.com/u/sal_jefferson)\
**Post date:** [October 15, 2014, 3:23pm UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/2 "2014-10-15T15:23:20Z")

</div>

Hello there and welcome to the Wowza support forum.

I am sorry I dont have much to offer here as I have not set this up myself. But looking closely at the guide and what you have shown, all I can see that is different is the “ssl” in the command lines.

What you have:

```auto
sudo keytool -genkey -keysize 2048 -alias wowza -keyalg RSA -keystore sentryvidserv.us.jks

```

What the guide shows:

```auto
keytool -certreq -file ssl.mycompany.com.csr -alias wowza -keyalg RSA -keystore [B]ssl[/B].mycompany.com.jks

```

I notice you omitted the “ssl” part in most of the command lines, and included it on one.

Also, in the VHost you have:

```auto
<KeyStorePath>${com.wowza.wms.context.VHostConfigHome}/conf/sentryvidserv.us.jks</KeyStorePath>

```

And the guide mentions:

```auto
${com.wowza.wms.context.VHostConfigHome}/conf/[B]ssl[/B].mycompany.com.jks

```

Lastly, the guide provides a link to a troubleshooting guide:

_A bug in the Oracle Java Development Kit (JDK) affects connections that use Secure Sockets Layer (SSL) certificates. Occasionally the SSL handshake fails during Diffie-Hellman key exchange and the connection hangs. For more information, see [How to fix intermittent HTTP/SSL failure (padding exception)](https://www.wowza.com/docs/how-to-fix-intermittent-http-ssl-failure-padding-exception%28padding-exception%29)._

Again, I apologize for not having more to offer. If you still need help and no one from support has replied you could open a support ticket by zipping the following directories and sending them to support@wowza.com

**[install-dir]/conf**

**[install-dir]/logs**

**[install-dir]/transcoder**

**[install-dir]/manager/logs**

Kind regards,

Salvadore

---

<div class="post-metadata">

**Author:** ![Paul\_Shields](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/paul_shields/32/390_2.png) [@Paul\_Shields](https://community.wowza.com/u/Paul_Shields)\
**Post date:** [June 13, 2016, 3:44pm UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/3 "2016-06-13T15:44:41Z")

</div>

Hi,

This is a rather old ticket and may or may not be relevant to the issue you are experiencing. I would suggest that you [open a support ticket](https://www.wowza.com/support/open-ticket) with us and include the steps you’ve taken and we can look at your specific workflow. Include a zip of your /conf and /logs too.

Paul

---

<div class="post-metadata">

**Author:** ![Dave\_Collins](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@Dave\_Collins](https://community.wowza.com/u/Dave_Collins)\
**Post date:** [October 16, 2014, 5:53pm UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/4 "2014-10-16T17:53:45Z")

</div>

You are very observant Savadore!

Thanks much for your input. I do believe that [sentryvid.serv.us](http://sentryvid.serv.us) (_without_ the SSL) is correct for us, but I am not 100% sure. I have a support ticket open. Looking through my command history you might be right that I included the ssl. in front of the keystore on the import of the “wowza” cert. I will re-try and see if it helps.

Thanks,

Dave

---

<div class="post-metadata">

**Author:** ![Vincent\_Drouin](https://avatars.discourse-cdn.com/v4/letter/v/d78d45/32.png) [@Vincent\_Drouin](https://community.wowza.com/u/Vincent_Drouin)\
**Post date:** [June 1, 2016, 11:52am UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/5 "2016-06-01T11:52:22Z")

</div>

How do you have resolve this? I have the same probs

Thanks

---

<div class="post-metadata">

**Author:** ![Luis\_Molina\_Martinez](https://avatars.discourse-cdn.com/v4/letter/l/ecd19e/32.png) [@Luis\_Molina\_Martinez](https://community.wowza.com/u/Luis_Molina_Martinez)\
**Post date:** [June 28, 2018, 7:39am UTC](https://community.wowza.com/t/accessing-streams-via-https-not-working/43907/6 "2018-06-28T07:39:27Z")

</div>

the same is happening to me, any solution?
