# custom rtsp authentication module

**URL:** https://community.wowza.com/t/custom-rtsp-authentication-module/46963
**Category:** Wowza Streaming Engine
**Created:** [April 27, 2016, 3:33pm UTC](https://community.wowza.com/t/custom-rtsp-authentication-module/46963 "2016-04-27T15:33:32Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Hyungjoo\_Kim](https://avatars.discourse-cdn.com/v4/letter/h/db5fbb/32.png) [@Hyungjoo\_Kim](https://community.wowza.com/u/Hyungjoo_Kim)
#### Post date: [April 27, 2016, 3:33pm UTC](https://community.wowza.com/t/custom-rtsp-authentication-module/46963/1 "2016-04-27T15:33:32Z")

</div>

Hello,

To our knowledge, Wowza supports ‘http digest’ when rtsp session established.

But you know, MD5 hash alg. is broken security function.

So, we want to customize rtsp authentication to use sha-2 in wowza.

Is it possible in inbound??

If it’s not possible, can we add our authentication module and use it before rtsp session established?

Please, help us to resolve this problem! Thank you!

---

<div class="post-metadata">

### Author: ![Nick\_ten\_Cate](https://avatars.discourse-cdn.com/v4/letter/n/71e660/32.png) [@Nick\_ten\_Cate](https://community.wowza.com/u/Nick_ten_Cate)
#### Post date: [May 1, 2016, 4:16pm UTC](https://community.wowza.com/t/custom-rtsp-authentication-module/46963/2 "2016-05-01T16:16:42Z")

</div>

You can “create” your own authentication module if you extend the EventEngine.

Wowza Docs: [https://www.wowza.com/docs/wowza-streaming-engine-java-api](https://www.wowza.com/docs/wowza-streaming-engine-java-api)

Like so:

```auto
public class EventEngine extends ModuleBase {
...
	public void onRTPSessionCreate(RTPSession rtpSession) {
		
		boolean allowStream = <YOUR-CUSTOM-JAVA>.checkAccessForUri(rtpSession.getIp(), rtpSession.getUri(), rtpSession.getQueryStr());
		
		if (!allowStream) {
			rtpSession.rejectSession();
		}
	}
...
}

```
