# SSL cipher order

**URL:** https://community.wowza.com/t/ssl-cipher-order/49918
**Category:** Wowza Streaming Engine
**Created:** [October 13, 2017, 12:55pm UTC](https://community.wowza.com/t/ssl-cipher-order/49918 "2017-10-13T12:55:50Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Tom\_Kuipers](https://avatars.discourse-cdn.com/v4/letter/t/5f8ce5/32.png) [@Tom\_Kuipers](https://community.wowza.com/u/Tom_Kuipers)
#### Post date: [October 13, 2017, 12:55pm UTC](https://community.wowza.com/t/ssl-cipher-order/49918/1 "2017-10-13T12:55:50Z")

</div>

I’ve SSL configured and working for mpegdash streaming. When testing the SSL implementation using [https://testssl.sh/](https://testssl.sh/) or [https://www.ssllabs.com/](https://www.ssllabs.com/) it is suggested to specify the cipher order on the server. In apache tomcat this can be done by setting SSLHonorCipherOrder to true.

For Wowza I would also like to specify this, however I don’t see a property for this in the SSLConfig section of VHost.xml.

How can I force Wowza to honor the cipher order?

---

<div class="post-metadata">

### Author: ![Paul\_Gration](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@Paul\_Gration](https://community.wowza.com/u/Paul_Gration)
#### Post date: [January 11, 2019, 12:50pm UTC](https://community.wowza.com/t/ssl-cipher-order/49918/2 "2019-01-11T12:50:55Z")

</div>

We’re wondering the same, I assumed that the order of the in a VHost configuration would be used but testssl reports back that no order is specified…

---

<div class="post-metadata">

### Author: ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)
#### Post date: [January 11, 2019, 5:59pm UTC](https://community.wowza.com/t/ssl-cipher-order/49918/3 "2019-01-11T17:59:15Z")

</div>

There is no equivalent of “SSLHonorCipherOrder” with Wowza Streaming Engine.

You must manually configure your cipher suites in your VHost.xml file, but first you need to find what your cert supports. The article below will show you how to find those.

[https://www.wowza.com/docs/how-to-improve-ssl-configuration](https://www.wowza.com/docs/how-to-improve-ssl-configuration)

In your VHost.xml file you will see the following.

```auto
<CipherSuites></CipherSuites><Protocols></Protocols>

```

You can add what you found in your debug output to those sections. As every  
cert is a bit different the information below is merely an example.

```auto
<CipherSuites>TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_CBC_SHA,TLS_DHE_RSA_WITH_AES_256_CBC_SHA,TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,TLS_DHE_RSA_WITH_AES_256_CBC_SHA256</CipherSuites><Protocols>TLSv1,TLSv1.1,TLSv1.2</Protocols>

```

Specifically, you should only add what you want to use and the cipher suites and protocols chosen will be the only ones used.
