# Limiting direct access to Wowza Streaming Engine content to only requests from specific server/client certificate

**URL:** <https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382>\
**Category:** Wowza Streaming Engine\
**Tags:** server-administration, security\
**Created:** [May 21, 2019, 4:12pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382 "2019-05-21T16:12:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rich\_Sokol](https://avatars.discourse-cdn.com/v4/letter/r/d78d45/32.png) [@Rich\_Sokol](https://community.wowza.com/u/Rich_Sokol)\
**Post date:** [May 21, 2019, 4:12pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382/1 "2019-05-21T16:12:24Z")

</div>

We are looking to lock down our Wowza Streaming Engine implementation to be only accessed via requests from our web server(s). Thus ensuring only authenticated users can access our content. Our web servers can make SSL requests for streaming content and we would like Wowza to identify a specific client certificate and only handle requests with this certificate. Has anyone done anything like this? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 22, 2019, 9:06pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382/2 "2019-05-22T21:06:15Z")

</div>

I don’t believe we have a way to authenticate based on a specific certificate, but you could restrict it based on the IP address. Let me check with the engineers though to be sure. Also, HTTPS by itself doesn’t secure media streams, but when used in conjunction with some type of token-based authentication system, it can more fully protect streaming.

[https://www.wowza.com/docs/how-to-configure-security-using-wowza-streaming-engine-manager](https://www.wowza.com/docs/how-to-configure-security-using-wowza-streaming-engine-manager)

---

<div class="post-metadata">

**Author:** ![Rich\_Sokol](https://avatars.discourse-cdn.com/v4/letter/r/d78d45/32.png) [@Rich\_Sokol](https://community.wowza.com/u/Rich_Sokol)\
**Post date:** [May 23, 2019, 2:15pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382/3 "2019-05-23T14:15:12Z")

</div>

Thanks! We are simply trying to NOT allow direct access to our WSE for users that have not gone through our MAC/DAC requirements to view content. We are an enterprise environment with this constraint. Has anyone front-ended WSE with something like Nginx to proxy requests? Our MAC/DAC functionality is REST based and our environment uses PKI authentication. What are the options locking down WSE in this manner?

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 23, 2019, 7:59pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382/4 "2019-05-23T19:59:05Z")

</div>

Our engineers say it IS possible to do this, but a bit tricky to set up. I can have someone reach out to you with more info ok? They’d like to take a closer look.

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 23, 2019, 8:02pm UTC](https://community.wowza.com/t/limiting-direct-access-to-wowza-streaming-engine-content-to-only-requests-from-specific-server-client-certificate/53382/5 "2019-05-23T20:02:56Z")

</div>

Also, the engineers say that because Wowza is IP based, not MAC based, you could write a plugin or use something else to validate the IP address.
