# Adding SecureToken protection to JW player

**URL:** <https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74>\
**Category:** Wowza Streaming Engine\
**Created:** [July 16, 2008, 1:38pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74 "2008-07-16T13:38:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [July 16, 2008, 1:38pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/1 "2008-07-16T13:38:11Z")

</div>

**Attention:** You must use the secure RTMPE protocol along with SecureToken when connecting to Wowza to fully protect content from the latest “leech” program:

> **RTMPE** ://[wowza-ip-address]/secureApplication.

Below are the instruction to add **SecureToken** protection to **JW player**. As of JW Player 4.1 **SecureToken** is now built into the player (thank you Jeroen!!!).

- Download and install [Wowza Pro 1.7.2](https://www.wowza.com/store.html) or greater

- Install the Wowza Pro **SecureToken** example by double clicking on **[wowza-pro-install-dir]/examples/SecureToken/install.sh** (this will setup the Wowza Pro application **securetoken** with a **secureTokenSharedSecret** of **#ed%h0#w@1** )

- Start Wowza Pro

- Download the **JW player 4 for Flash** source code from here: [JW Player for Flash](http://code.longtailvideo.com/trac/) (JW Player is commercial software).

- Edit **[jw-source-code]/com/jeroenwijering/models/RTMPModel.as** and enter the secure token value (around line 186):

- Open **[jw-source-code]/player.fla** in Flash CS3 and select **File: Publish** to generate a new **[jw-source-code]/player.swf** file

- Edit **[jw-source-code]/readme.html** and change the flashvars param in the script section (around line 60):

_- Edit **[wowza-pro-install-dir]/conf/securetoken/Application.xml** and change the **secureTokenSharedSecret** property to the new value and restart Wowza Pro_\_- Edit **[jw-source-code]/com/jeroenwijering/models/RTMPModel.as** and change the string passed to the **secureTokenResponse** callback to the same value as above and use Flash CS to re-publish the **player.swf** file\__-_

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 27, 2008, 9:28am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/2 "2008-08-27T09:28:20Z")

</div>

I didn’t go back and try the instructions. I did tweak them a little based on the new FlashVars in the new 4.1 player. Let me know if they now work.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 27, 2008, 10:59am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/3 "2008-08-27T10:59:47Z")

</div>

Thanks for the kind words. I need to update these instructions now that JW Player 4.1 is out.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 28, 2008, 2:59am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/4 "2008-08-28T02:59:03Z")

</div>

When I get a chance I will update the instruction. The performance effect of rtmpe is documented in our performance results here:

[https://www.wowza.com/forums/showthread.php?t=239](https://www.wowza.com/forums/showthread.php?t=239)

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 29, 2008, 4:33am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/5 "2008-08-29T04:33:46Z")

</div>

I have updated the instructions for JW Player 4.1. Much simpler now since it is built in. Send a big thank you email to Jeroen ([mail@jeroenwijering.com](mailto:mail@jeroenwijering.com)). It does require that you get the latest source code from subversion.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [October 6, 2008, 7:34am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/6 "2008-10-06T07:34:42Z")

</div>

I just tried your exact code against the 4.1 source code (I did download the 4.1 zip archive at [http://code.jeroenwijering.com/trac/browser/tags](http://code.jeroenwijering.com/trac/browser/tags)) and it worked perfectly. No errors. Not sure what is wrong.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [October 6, 2008, 12:45pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/7 "2008-10-06T12:45:40Z")

</div>

You will need to download and install Wowza Pro locally to get all the examples. You can get the most recent security package here:

[http://community.wowza.com/t/-/45](http://community.wowza.com/t/-/45)

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [October 18, 2008, 3:47am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/8 "2008-10-18T03:47:49Z")

</div>

Which player is that?

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [December 19, 2008, 6:23am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/9 "2008-12-19T06:23:37Z")

</div>

I just download the most recent Replay Media Catch 3.0.1 (with all the new plugins) and SecureToken blocks it for me. The file does show up in the list but it is not populated with any data and in the Wowza Pro logs I can see the Replay Media Catcher connection being blocked:

> INFO application app-start _definst_ securetoken/_definst_
> 
> INFO session connect-pending 192.168.1.2 -
> 
> INFO server comment - SecureTokenTarget: create:true play:false publish:false
> 
> INFO session connect 192.168.1.2 -
> 
> INFO stream create - -
> 
> INFO session connect-pending 192.168.1.2 -
> 
> INFO server comment - SecureTokenTarget: create:true play:false publish:false
> 
> INFO session connect 192.168.1.2 -
> 
> ERROR server comment - Error: SecureToken: Challenge does not equal response: kill connection
> 
> ERROR server comment - Error: SecureToken: Action before response received: kill connection
> 
> INFO stream create - -
> 
> INFO stream destroy - -
> 
> INFO session disconnect 2072201024 -
> 
> INFO stream play Extremists -
> 
> INFO stream stop Extremists -
> 
> INFO stream destroy Extremists -
> 
> INFO session disconnect 692588433 -
> 
> If you still can’t sort out why it is not protecting your content zip up and send me your conf and logs folders so I can have a look ([charlie@wowza.com](mailto:charlie@wowza.com)).
> 
> Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [December 19, 2008, 1:56pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/10 "2008-12-19T13:56:41Z")

</div>

Take a look at AllowDomain in the User’s Guide. It is what it is designed to do.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [September 17, 2009, 2:41am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/11 "2009-09-17T02:41:30Z")

</div>

It is here:

[http://community.wowza.com/t/-/45](http://community.wowza.com/t/-/45)

Charlie

---

<div class="post-metadata">

**Author:** ![Riki\_Babington](https://avatars.discourse-cdn.com/v4/letter/r/0ea827/32.png) [@Riki\_Babington](https://community.wowza.com/u/Riki_Babington)\
**Post date:** [August 26, 2008, 2:49am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/12 "2008-08-26T02:49:02Z")

</div>

Could you please verify how to get the securetoken with the latest version of the JW player (4.1). I tried it with this well written documentation but it didnt work.

Thanks!

- Riki

---

<div class="post-metadata">

**Author:** ![Martin\_Bay](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@Martin\_Bay](https://community.wowza.com/u/Martin_Bay)\
**Post date:** [September 17, 2009, 9:17am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/13 "2009-09-17T09:17:19Z")

</div>

> 

- Edit **[wowza-pro-install-dir]/conf/securetoken/Application.xml** and change the **secureTokenSharedSecret** property to the new value and restart Wowza Pro

- Charlie

---

<div class="post-metadata">

**Author:** ![Chris\_Herdt](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@Chris\_Herdt](https://community.wowza.com/u/Chris_Herdt)\
**Post date:** [September 8, 2009, 12:31pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/14 "2009-09-08T12:31:37Z")

</div>

I’m not sure I understand the level of security this provides.

If the secure token shared secret is embedded in the player, then anyone who downloads the modified player.swf file could then play the protected videos.

If that means restricting access to the modified player.swf file, then that also means that to create different access control lists, I would need to have numerous customized player.swf files.

---

<div class="post-metadata">

**Author:** ![Jed\_Barish](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jed\_Barish](https://community.wowza.com/u/Jed_Barish)\
**Post date:** [August 30, 2008, 7:03am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/15 "2008-08-30T07:03:08Z")

</div>

4.1.60 is the latest so far so can I use it to integrate with secure token now?

---

<div class="post-metadata">

**Author:** ![Jed\_Barish](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jed\_Barish](https://community.wowza.com/u/Jed_Barish)\
**Post date:** [December 19, 2008, 9:37pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/16 "2008-12-19T21:37:28Z")

</div>

None of any recorder apps could do the job but I still couldnt prevent anyone to embed player from our page through source. Someone took the html code and embed from our site onto theirs. It seems that SecureToken is not a solution to prevent that way. A guy mentioned about Secure URL so anyone has an idea to secure even I added our domain on a xml file under wms that it shouldnt stream anywhere except a specific domain but still it does.

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [April 8, 2009, 3:24am UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/17 "2009-04-08T03:24:49Z")

</div>

The above instructions are for the current version. I have not tried them lately but they should work. That being said, I know there was a problem with the initial release of JW Player 4.4 and SecureToken. I suggest you check the JW Player site. They were suppose to have fixed it.

Charlie

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 6, 2008, 7:31pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/18 "2008-10-06T19:31:40Z")

</div>

Yes, SecureToken works on EC2. I am using it.

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 6, 2008, 8:40pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/19 "2008-10-06T20:40:41Z")

</div>

There should be this jar file in /usr/local/WowzaMediaServerPro/lib :

wms-plugin-security.jar

Then you have to have Application.xml with Module that references that. See the secureToken example in [wowza-install-dir]/examples/secureToken

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [December 19, 2008, 2:52pm UTC](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74/20 "2008-12-19T14:52:32Z")

</div>

I also tested the latest demo version of this software. It listed the swf, then listed the flv I played, but downloaded 0 bytes.

Richard

[Next page](https://community.wowza.com/t/adding-securetoken-protection-to-jw-player/74.md?page=2)
