# Article: How to protect streaming using SecureToken in Wowza Streaming Engine

**URL:** <https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065>\
**Category:** Wowza Streaming Engine\
**Tags:** server-administration\
**Created:** [September 11, 2014, 10:42am UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065 "2014-09-11T10:42:32Z")\
**Posts on this page:** 9\
**Page:** 2

<div class="post-metadata">

**Author:** ![Tom\_Harris1](https://avatars.discourse-cdn.com/v4/letter/t/ed655f/32.png) [@Tom\_Harris1](https://community.wowza.com/u/Tom_Harris1)\
**Post date:** [February 5, 2015, 2:36pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/23 "2015-02-05T14:36:42Z")

</div>

From turning on the debug logs, it seems to me that ModuleCoreSecurity is stripping off everything after and including the “=” sign so the hashes don’t match. Is this a bug?

**\_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI=** hash sent

> INFO session connect-pending 192.168.5.56 -
> 
> INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: isPublisher:false FlashVer: LNX 16,0,0,305
> 
> INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: Initiate SecureToken Authorization.
> 
> INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: All security checks passed.
> 
> INFO session connect 192.168.5.56 -
> 
> INFO stream create - -
> 
> INFO server comment - ModuleCoreSecurity.play[live/streamer-1/stream]: Check SecureToken Authorization.
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:current time stamp: 1423146360
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:clientId: 23217498
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:hashReceived: \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:creating RTMP token for ClientId:23217498 uri:rtmp://192.168.5.56:1935/live/streamer-1/stream
> 
> WARN server comment - ModuleCoreSecurity[live/streamer-1] Invalid value for token start time: null
> 
> WARN server comment - ModuleCoreSecurity[live/streamer-1] Invalid value for token end time: null
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:client IP: 192.168.5.56
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:hashCalculated: \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI=
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:string hashed: live/streamer-1/stream?secret
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:token start time stamp: 0
> 
> INFO server comment - [live/streamer-1]ModuleCoreSecurity:token end time stamp: 0
> 
> INFO server comment - [live/streamer-1]SecureTokenDef:Hash \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI, doesn’t match hash calculated, \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI=
> 
> INFO session comment 23217498 ModuleCoreSecurity.play[live/streamer-1/stream]: SecureToken failed. clientId: 23217498 play denied: clientId:23217498
> 
> INFO stream destroy - -
> 
> INFO session disconnect 23217498 -
> 
> And again with **\_JVK=1234** hash sent
> 
> > INFO session connect-pending 192.168.5.56 -
> > 
> > INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: isPublisher:false FlashVer: LNX 16,0,0,305
> > 
> > INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: Initiate SecureToken Authorization.
> > 
> > INFO server comment - ModuleCoreSecurity.onConnect[live/streamer-1/]: All security checks passed.
> > 
> > INFO session connect 192.168.5.56 -
> > 
> > INFO stream create - -
> > 
> > INFO server comment - ModuleCoreSecurity.play[live/streamer-1/stream]: Check SecureToken Authorization.
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:current time stamp: 1423146740
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:clientId: 452295755
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:hashReceived: \_JVK
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:creating RTMP token for ClientId:452295755 uri:rtmp://192.168.5.56:1935/live/streamer-1/stream
> > 
> > WARN server comment - ModuleCoreSecurity[live/streamer-1] Invalid value for token start time: null
> > 
> > WARN server comment - ModuleCoreSecurity[live/streamer-1] Invalid value for token end time: null
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:client IP: 192.168.5.56
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:hashCalculated: \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI=
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:string hashed: live/streamer-1/stream?secret
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:token start time stamp: 0
> > 
> > INFO server comment - [live/streamer-1]ModuleCoreSecurity:token end time stamp: 0
> > 
> > INFO server comment - [live/streamer-1]SecureTokenDef:Hash \_JVK, doesn’t match hash calculated, \_JVKyN33KaexRqoTo2LAbwICidR22K3msulK0pBcWZI=
> > 
> > INFO session comment 452295755 ModuleCoreSecurity.play[live/streamer-1/stream]: SecureToken failed. clientId: 452295755 play denied: clientId:452295755
> > 
> > INFO stream destroy - -
> > 
> > INFO session disconnect 452295755 -

---

<div class="post-metadata">

**Author:** ![Tom\_Harris1](https://avatars.discourse-cdn.com/v4/letter/t/ed655f/32.png) [@Tom\_Harris1](https://community.wowza.com/u/Tom_Harris1)\
**Post date:** [February 5, 2015, 6:21pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/24 "2015-02-05T18:21:24Z")

</div>

This is fixed in 4.1.1

There appeared to be a bug that would strip off the trailing “=” from the received hash meaning it would never match the wowza calculated hash.

Update fixed it.

---

<div class="post-metadata">

**Author:** ![GukChan\_Jeon](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@GukChan\_Jeon](https://community.wowza.com/u/GukChan_Jeon)\
**Post date:** [January 28, 2015, 6:01pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/25 "2015-01-28T18:01:42Z")

</div>

> From your example you need to adjust your hash paramiter to the following
> 
> $string = “vod/sample.mp4?192.168.1.2&mySharedSecret&myTokenPrefixCustomParameter=abcdef&myTokenPrefixendtime=1500000000&myTokenPrefixstarttime=1395230400”;
> 
> $hash = hash(‘sha256’, $string, 1);
> 
> this will generate the SHA-256 string and output as a BASE64 encoded string.
> 
> you then need to sanitise or URL Safe the string.
> 
> hop that helps
> 
> **[@Wowza](https://community.wowza.com/groups/wowza):** I agree with these guys the documentation regarding hashing really could use some examples on the acctual generation of the hash
> 
> e.g Showing a code example of how to generate the correctly formatted hash in php, classic asp and [asp.net](http://asp.net) would be a good idea.

? question

**Important: The client web server should generate the hash when it generates the client webpage. You shouldn’t use JavaScript code in the client webpage to generate the hash as the code is visible in the webpage source and would pose a potential security risk.**

as I talked about above, If you do not create hash from a web page, how do I generate from where?

---

<div class="post-metadata">

**Author:** ![GukChan\_Jeon](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@GukChan\_Jeon](https://community.wowza.com/u/GukChan_Jeon)\
**Post date:** [February 25, 2015, 1:53pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/26 "2015-02-25T13:53:20Z")

</div>

Hash value is corrected…

> Are the hashes used in this guide accurate?
> 
> Using the quoted string above I get a URL safe base64 encoded SHA256 hash as follows:
> 
> kJ591xB2lT-X0OA9UdoRx61uwp6A\_IoSc\_jCx\_9h1l8=
> 
> This might seem a pedantic question, but if a guide is there to follow then I need a working example.

---

<div class="post-metadata">

**Author:** ![Tahir\_Khalil](https://avatars.discourse-cdn.com/v4/letter/t/b3f665/32.png) [@Tahir\_Khalil](https://community.wowza.com/u/Tahir_Khalil)\
**Post date:** [May 26, 2015, 11:23am UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/27 "2015-05-26T11:23:03Z")

</div>

Patrickz’s post was very useful. Here’s how I tackled this in a .Net 4.5 web app:

```auto
using System;
using System.Net;
using System.Security.Cryptography;
using System.Text;
namespace MyMediaServer
{
    public class MyMediaStream
    {
        public static string Get()
        {
            var wowzaContentURL = "http://example.com:1935/MyVodApp/mp4:sample.mp4/playlist.m3u8";
            var wowzaContentPath = "MyVodApp/mp4:sample.mp4";
            var wowzaSecureToken = "abc123";
            var wowzaTokenPrefix = "MyToken";
            var wowzaCustomParameter = wowzaTokenPrefix + "CustomParameter=myParameter";
            var wowzaSecureTokenStartTime = wowzaTokenPrefix + "starttime=" + DateTimeToUnixTimeStamp(DateTime.Now);
            var wowzaSecureTokenEndTime = wowzaTokenPrefix + "endtime=" + DateTimeToUnixTimeStamp(DateTime.Now.AddHours(2));
            // hashstr should = "MyVodApp/mp4:sample.mp4?abc123&MyTokenCustomParameter=myParameter&MyTokenendtime=1432676901.3294&MyTokenstarttime=1432669696.2954"
            var hashstr = wowzaContentPath + "?" + wowzaSecureToken + "&" + wowzaCustomParameter + "&" + wowzaSecureTokenEndTime + "&" + wowzaSecureTokenStartTime;
            SHA256 sha256 = new SHA256Managed();
            var sha256Bytes = Encoding.Default.GetBytes(hashstr);
            var cryString = sha256.ComputeHash(sha256Bytes);
            var usableHash = Convert.ToBase64String(cryString).Replace("+", "-").Replace("/", "_");
            // I got "d1b-2bc4Sd86k2OwKp0c8fYFzyvCNjReModi_IyVHw8="
            // which means url should = "http://example.com:1935/MyVodApp/mp4:sample.mp4/playlist.m3u8?MyTokenstarttime=1432669696.2954&MyTokenendtime=1432676901.3294&MyTokenCustomParameter=myParameter&MyTokenhash=d1b-2bc4Sd86k2OwKp0c8fYFzyvCNjReModi_IyVHw8="
            var url = wowzaContentURL + "?" + wowzaSecureTokenStartTime + "&" + wowzaSecureTokenEndTime + "&" + wowzaCustomParameter + "&" + wowzaTokenPrefix + "hash=" + usableHash;
            WebRequest request = WebRequest.Create(url);
            request.Method = "POST";
            request.ContentType = "application/x-www-form-urlencoded";
            WebResponse response = request.GetResponse();
            Uri uri = response.ResponseUri;
            response.Close();
            // Wowza Media Server returns uri.AbsoluteUri:
            // http://example.com:1935/MyVodApp/mp4:sample.mp4/playlist.m3u8?MyTokenstarttime=1432669696.2954&MyTokenendtime=1432676901.3294&MyTokenCustomParameter=myParameter&MyTokenhash=d1b-2bc4Sd86k2OwKp0c8fYFzyvCNjReModi_IyVHw8=
            return uri.AbsoluteUri;
        }
        private static double DateTimeToUnixTimeStamp(DateTime dateTime)
        {
            return (dateTime - new DateTime(1970, 1, 1).ToLocalTime()).TotalSeconds;
        }
    }
}

```

I’ve tested this (using my domain and shared secret) and it works. The next step for me is JW Player integration.

---

<div class="post-metadata">

**Author:** ![vikas\_kumar1](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@vikas\_kumar1](https://community.wowza.com/u/vikas_kumar1)\
**Post date:** [October 4, 2018, 1:21pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/28 "2018-10-04T13:21:00Z")

</div>

can any one tell me

# How to protect streaming using SecureToken in Wowza Streaming Engine using java

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [October 4, 2018, 4:19pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/30 "2018-10-04T16:19:24Z")

</div>

@vikas kumar This workflow is updated and will provide you with the most current steps.

[https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine)

---

<div class="post-metadata">

**Author:** ![Haung\_Dio](https://avatars.discourse-cdn.com/v4/letter/h/f04885/32.png) [@Haung\_Dio](https://community.wowza.com/u/Haung_Dio)\
**Post date:** [April 17, 2020, 10:03am UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/31 "2020-04-17T10:03:26Z")

</div>

thanks， I can work 🙂

---

<div class="post-metadata">

**Author:** ![Le\_Son1](https://avatars.discourse-cdn.com/v4/letter/l/3bc359/32.png) [@Le\_Son1](https://community.wowza.com/u/Le_Son1)\
**Post date:** [May 17, 2020, 4:10pm UTC](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065/32 "2020-05-17T16:10:48Z")

</div>

i add ip in hash it not working. pls help me

[Previous page](https://community.wowza.com/t/article-how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine/39065.md?page=1)
