
25
1.877.877.2269
BLACKBOX.COM
NEED HELP?
LEAVE THE TECH TO US
LIVE 24/7
TECHNICAL
SUPPORT
1.877.877.2269
CHAPTER 4: BASIC OPERATION
FIGURE 4-27.
Once enable encryption is applied, you will be running in HLS mode and the actual video data being sent will be encrypted.
However, the HTTP exchanges will still be in the clear (i.e. no encryption via https). That means that the encryption key and
initialization vectors will be passed in the clear as well.
To protect the encryption key from being exposed, you have to configure the HTTP server for SSL. Go to the SSL tab and upload a
security certificate and key exchange files, and enable SSL and define your domain that matches your security certificate (issued by
a certificate issuing service — NOT by Black Box). These certificates are typically only valid for a period of time and then they expire
and the user has to renew them. Failure to do so will result in https no longer working properly.
When requesting a security certificate you must enter some data. You can do this from the “SSL” tab in Maestro:.
4. Click the SSL/RTMP tab
FIGURE 4-28.
5. Generate CSR (Certificate Signing Request). This will provide you with two files: The CSR and your Private key. Send your CSR file
off to a signing authority and they will return via email a signed certificate file to you along with a certificate chain file.
IMPORTANT NOTE: Be sure to save the Private Key file, because you will need it when uploading the certificate. If you do not have the
Private Key file, you will need to start the process over, including requesting the certificate from the signing authority again.