# how to secure the ciphers?

**URL:** <https://community.wowza.com/t/how-to-secure-the-ciphers/35871>\
**Category:** Wowza Streaming Engine\
**Created:** [August 2, 2011, 4:40pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871 "2011-08-02T16:40:39Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaushik\_kunal](https://avatars.discourse-cdn.com/v4/letter/k/898d66/32.png) [@kaushik\_kunal](https://community.wowza.com/u/kaushik_kunal)\
**Post date:** [August 2, 2011, 4:40pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/1 "2011-08-02T16:40:39Z")

</div>

Hi Guys,

Is there any help regarding securing the ciphers since wowza uses it’s own version of SSL.

Actually, we have a security requirment wherein we need to disable the Low encryption ciphers.

Thanks,

Kunal

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [August 3, 2011, 9:14pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/2 "2011-08-03T21:14:03Z")

</div>

Kunal,

Wowza uses RTMPE, and I don’t think there is any way to configure a lower encryption level. You can use SSL with Wowza, but there is not a Wowza SSL, so you can use whatever level you want.

Richard

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 3, 2011, 4:47pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/3 "2011-08-03T16:47:33Z")

</div>

I do not know of any way to do this. We are using the Java SSL implementation. I do not know if this is possible.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 5, 2011, 4:11am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/4 "2011-08-05T04:11:45Z")

</div>

Take a look at this article to see if it helps:

[http://download.oracle.com/docs/cd/E19566-01/819-4428/bgbbj/index.html](http://download.oracle.com/docs/cd/E19566-01/819-4428/bgbbj/index.html)

It seems to suggest that you might be able to modify your SSL cert to only allow certain ciphers.

Again, we don’t have any experience with selecting SSL ciphers.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 5, 2011, 12:22pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/5 "2011-08-05T12:22:46Z")

</div>

Is this the list you are interested in trimming?

```auto
ciperSuites[0]: SSL_RSA_WITH_RC4_128_MD5
ciperSuites[1]: SSL_RSA_WITH_RC4_128_SHA
ciperSuites[2]: TLS_RSA_WITH_AES_128_CBC_SHA
ciperSuites[3]: TLS_DHE_RSA_WITH_AES_128_CBC_SHA
ciperSuites[4]: TLS_DHE_DSS_WITH_AES_128_CBC_SHA
ciperSuites[5]: SSL_RSA_WITH_3DES_EDE_CBC_SHA
ciperSuites[6]: SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA
ciperSuites[7]: SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA
ciperSuites[8]: SSL_RSA_WITH_DES_CBC_SHA
ciperSuites[9]: SSL_DHE_RSA_WITH_DES_CBC_SHA
ciperSuites[10]: SSL_DHE_DSS_WITH_DES_CBC_SHA
ciperSuites[11]: SSL_RSA_EXPORT_WITH_RC4_40_MD5
ciperSuites[12]: SSL_RSA_EXPORT_WITH_DES40_CBC_SHA
ciperSuites[13]: SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA
ciperSuites[14]: SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA
ciperSuites[15]: TLS_EMPTY_RENEGOTIATION_INFO_SCSV

```

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 5, 2011, 12:49pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/6 "2011-08-05T12:49:35Z")

</div>

This will be addressed in Wowza Server 3. We are adding a new CipherSuites and Protocols elements to the SSLConfig element in [install-dir]/conf/VHost.xml.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 5, 2011, 1:05pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/7 "2011-08-05T13:05:51Z")

</div>

I have added this to Wowza Media Server 3 Preview 2 Patch 5:

[WowzaMediaServer3.0.0-preview2-patch5.zip](https://www.wowza.com/downloads/hide627834_WowzaMediaServer-3-0-0-preview2/WowzaMediaServer3.0.0-preview2-patch5.zip)

On Windows when using Java 6 the default CipherSuites and Protocols values are:

```auto
<CipherSuites>SSL_RSA_WITH_RC4_128_MD5,SSL_RSA_WITH_RC4_128_SHA,TLS_RSA_WITH_AES_128_CBC_SHA,TLS_DHE_RSA_WITH_AES_128_CBC_SHA,TLS_DHE_DSS_WITH_AES_128_CBC_SHA,SSL_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA,SSL_RSA_WITH_DES_CBC_SHA,SSL_DHE_RSA_WITH_DES_CBC_SHA,SSL_DHE_DSS_WITH_DES_CBC_SHA,SSL_RSA_EXPORT_WITH_RC4_40_MD5,SSL_RSA_EXPORT_WITH_DES40_CBC_SHA,SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA,SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA,TLS_EMPTY_RENEGOTIATION_INFO_SCSV</CipherSuites>
<Protocols>SSLv2Hello,SSLv3,TLSv1</Protocols>

```

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [August 5, 2011, 1:06pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/8 "2011-08-05T13:06:06Z")

</div>

I have added this to Wowza Media Server 3 Preview 2 Patch 5:

[WowzaMediaServer3.0.0-preview2-patch5.zip](https://www.wowza.com/downloads/hide627834_WowzaMediaServer-3-0-0-preview2/WowzaMediaServer3.0.0-preview2-patch5.zip)

On Windows when using Java 6 the default CipherSuites and Protocols values are:

```auto
<CipherSuites>SSL_RSA_WITH_RC4_128_MD5,SSL_RSA_WITH_RC4_128_SHA,TLS_RSA_WITH_AES_128_CBC_SHA,TLS_DHE_RSA_WITH_AES_128_CBC_SHA,TLS_DHE_DSS_WITH_AES_128_CBC_SHA,SSL_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA,SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA,SSL_RSA_WITH_DES_CBC_SHA,SSL_DHE_RSA_WITH_DES_CBC_SHA,SSL_DHE_DSS_WITH_DES_CBC_SHA,SSL_RSA_EXPORT_WITH_RC4_40_MD5,SSL_RSA_EXPORT_WITH_DES40_CBC_SHA,SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA,SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA,TLS_EMPTY_RENEGOTIATION_INFO_SCSV</CipherSuites>
<Protocols>SSLv2Hello,SSLv3,TLSv1</Protocols>

```

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [October 10, 2011, 9:04am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/9 "2011-10-10T09:04:59Z")

</div>

It is included in base Wowza Media Server 3. So no need for a patch.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [October 10, 2011, 9:20am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/10 "2011-10-10T09:20:59Z")

</div>

We do not plan to add this to Wowza 2.2.4.

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [May 22, 2012, 7:50am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/11 "2012-05-22T07:50:12Z")

</div>

Install this patch. It will fix a problem with SSLConfig/CipherSuites and SSLConfig/Protocols:

[WowzaMediaServer3.1.1-patch6.zip](https://www.wowza.com/downloads/WowzaMediaServer-3-1-1/WowzaMediaServer3.1.1-patch6.zip)

See this forum post that describes how to use a few new properties for debugging and configuring SSLConfig/CipherSuites and SSLConfig/Protocols:

[SSL configuration improvements in 3.1.106 or greater](http://community.wowza.com/t/-/102)

Charlie

---

<div class="post-metadata">

**Author:** ![kaushik\_kunal](https://avatars.discourse-cdn.com/v4/letter/k/898d66/32.png) [@kaushik\_kunal](https://community.wowza.com/u/kaushik_kunal)\
**Post date:** [August 3, 2011, 4:36pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/12 "2011-08-03T16:36:18Z")

</div>

Hi Richard,

we are using SSL with wowza and want to implement something like below like how we do for apache in ssl.conf file.

SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM

I am not able to find such config file inside wowza. Do you know where we need to put the above statment inside wowza folder?

Thanks,

Kunal

---

<div class="post-metadata">

**Author:** ![kaushik\_kunal](https://avatars.discourse-cdn.com/v4/letter/k/898d66/32.png) [@kaushik\_kunal](https://community.wowza.com/u/kaushik_kunal)\
**Post date:** [August 4, 2011, 10:03am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/13 "2011-08-04T10:03:02Z")

</div>

Thanks, Charlie. Just to clarify, our corporate scan team ran a Qualys scan against our Wowza servers and we were dinged for allowing low encryption ciphers. Per their recommendation, we should only be allowing high ciphers. Please confirm that this is not possible. (Security is at the front of everyone’s mind here due to recent events). Thanks again

Kunal

---

<div class="post-metadata">

**Author:** ![Sitarama\_Marni](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@Sitarama\_Marni](https://community.wowza.com/u/Sitarama_Marni)\
**Post date:** [October 10, 2011, 9:00am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/14 "2011-10-10T09:00:53Z")

</div>

Charlie, Is there a patch on this for 2.2.4 version too?

---

<div class="post-metadata">

**Author:** ![Sitarama\_Marni](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@Sitarama\_Marni](https://community.wowza.com/u/Sitarama_Marni)\
**Post date:** [October 10, 2011, 9:16am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/15 "2011-10-10T09:16:54Z")

</div>

got it.

Our company will not allow us to upgrade to version 3 yet, so Is there a possibility that we can have this a patch to version 2.2.4?

---

<div class="post-metadata">

**Author:** ![Sitarama\_Marni](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@Sitarama\_Marni](https://community.wowza.com/u/Sitarama_Marni)\
**Post date:** [April 23, 2012, 7:37am UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/16 "2012-04-23T07:37:07Z")

</div>

Our security team reporting that our Wowza SSL listener is still accepting the low key ciphers.

It appears handshakes are successfully being exchanged using Cipher EDH-RSA-DES-CBC-SHA and TLSv1 protocol, even though the VHost.xml is configured to allow only high key cipher.

Any one had success in getting the Qualys scan through with only high key ciphers?

---

<div class="post-metadata">

**Author:** ![Brandon\_Barrick](https://avatars.discourse-cdn.com/v4/letter/b/41988e/32.png) [@Brandon\_Barrick](https://community.wowza.com/u/Brandon_Barrick)\
**Post date:** [January 13, 2012, 5:19pm UTC](https://community.wowza.com/t/how-to-secure-the-ciphers/35871/17 "2012-01-13T17:19:51Z")

</div>

Just to confirm, all SSL ciphers would be available for use in versions of Wowza previous to version 3? There is no other workaround in Wowza 2 to only make strong ciphers available?
