# ModuleRTMPAuthentication replaces Secure URL Params?

**URL:** <https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517>\
**Category:** Wowza Streaming Engine\
**Created:** [December 19, 2009, 6:46pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517 "2009-12-19T18:46:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [December 19, 2009, 6:46pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/1 "2009-12-19T18:46:21Z")

</div>

If so, how do you construct the FMS Url in an encoder like FMLE that has no user/pass prompts?

For secure url params, the FMS url needed to be in this type of format:

rtmp://server/appname/_definst_/doPublish=PASSWORD

and a doPublish password property had to be set in the Application.xml

Now with the ModuleRTMPAuthentication , there is a publish.password file to set the user/pass.

How do we reference the user/pass in the FMS url ?

It appears Wirecast has a “Set Credentials” option now where an actual user/pass can be entered for a Flash server preset. I haven’t tested it against Wowza 2.0 yet, but I assume it will work as expected.

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [December 20, 2009, 5:41am UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/2 "2009-12-20T05:41:12Z")

</div>

In Wowza Media Server 2 we now support username/password login when using Flash Media Live Encoder. See the MediaSecurity AddOn package. If you properly configured RTMP authentication then you will be prompted for a username/password when the encoder connections.

[http://community.wowza.com/t/-/45](http://community.wowza.com/t/-/45)

Charlie

---

<div class="post-metadata">

**Author:** ![Charlie\_Good](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/charlie_good/32/383_2.png) [@Charlie\_Good](https://community.wowza.com/u/Charlie_Good)\
**Post date:** [December 24, 2009, 3:22pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/3 "2009-12-24T15:22:17Z")

</div>

Describe in detail how you expect this to work?

Charlie

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [January 4, 2010, 1:57pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/4 "2010-01-04T13:57:20Z")

</div>

Unfortunately you can’t combine. You would have to setup two applications, one for each method.

Richard

---

<div class="post-metadata">

**Author:** ![Michael\_Barsoumian](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@Michael\_Barsoumian](https://community.wowza.com/u/Michael_Barsoumian)\
**Post date:** [December 24, 2009, 3:10pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/5 "2009-12-24T15:10:08Z")

</div>

Is it possible to maintain backward compatibility with the older form of authentication (described above) while enabling the new method?

---

<div class="post-metadata">

**Author:** ![Michael\_Barsoumian](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@Michael\_Barsoumian](https://community.wowza.com/u/Michael_Barsoumian)\
**Post date:** [January 1, 2010, 5:47pm UTC](https://community.wowza.com/t/modulertmpauthentication-replaces-secure-url-params/517/6 "2010-01-01T17:47:45Z")

</div>

For example, for encoders that did not support authentication , the following would work for the stream address (with Wowza 1.X):

rtmp://server/SERVICENAME/_definst_/doPublish=PASSWORD

In the application.xml, the following property needed to be set:

secureurlparams.publish

PASSWORD.doPublish

So how can compatibility be maintained for existing users, connecting to the server via the server address method:

rtmp://server/SERVICENAME/_definst_/doPublish=PASSWORD

?
