docs: add instructions on how to use encryption with OBS Studio (#5636)

This commit is contained in:
Alessandro Ros
2026-04-03 22:04:20 +02:00
committed by GitHub
parent f453b59cd6
commit f52a63858c
2 changed files with 81 additions and 3 deletions
+80 -2
View File
@@ -4,6 +4,8 @@ OBS Studio can publish streams to the server in several ways. The recommended on
## OBS Studio and RTMP
### Standard
In `Settings -> Stream` (or in the Auto-configuration Wizard), use the following parameters:
- Service: `Custom...`
@@ -27,7 +29,7 @@ If you want to generate a stream that can be read with WebRTC, open `Settings ->
Then use the button `Start Recording` (instead of `Start Streaming`) to start streaming.
## OBS Studio and RTMP, multitrack video
### Multitrack video
OBS Studio can publish multiple video tracks or renditions at once (simulcast). Make sure that the OBS Studio version is ≥ 31.0.0. Open `Settings -> Stream` and use the following parameters:
@@ -109,8 +111,72 @@ Save the configuration and click `Start streaming`.
The resulting stream will be available on path `/mystream`.
### Encryption (RTMPS)
When publishing streams to _MediaMTX_ with RTMP, you can encrypt streams in transit by using the encrypted variant of RTMP (RTMPS). This can be enabled by using the `rtmps` scheme and the 1936 port:
```
rtmps://localhost:1936/mystream
```
Make sure that RTMP encryption is allowed in _MediaMTX_ (`rtmpEncryption: "optional"`).
OBS Studio requires _MediaMTX_ to use a TLS certificate signed by a public certificate authority and silently rejects self-signed certificates. You can either buy a certificate from a public certificate authority or create a local certificate authority and use it to generate the server certificate and validate it on the OBS Studio machine, by following these instructions:
1. Create the key pair of the local certificate authority:
```sh
openssl req \
-x509 \
-nodes \
-days 3650 \
-newkey rsa:4096 \
-keyout myca.key \
-out myca.crt \
-subj "/O=myca/CN=myca"
```
2. Use the key pair to create the server certificate. Replace `localhost` with the domain name OBS Studio will use to connect to the server:
```sh
openssl req \
-newkey rsa:4096 \
-nodes \
-keyout server.key \
-CA myca.crt \
-CAkey myca.key \
-subj "/CN=localhost" \
-x509 \
-days 3650 \
-out server.crt
```
You must use a domain name to connect to the server, not an IP address. If you do not have a domain name, edit the `/etc/hosts` file of the OBS Studio machine and associate a dummy domain name to the IP address of the server.
3. Put the newly-generated `server.key` and `server.cert` on the _MediaMTX_ machine, in the same folder of the _MediaMTX_ executable, and check that the configuration points to them.
4. Install the public key (`ca.crt`) of the local certificate authority on the OBS Studio machine.
If you are using Linux, this can be accomplished with these commands:
```sh
sudo mkdir -p /usr/local/share/ca-certificates
sudo cp myca.crt /usr/local/share/ca-certificates/
sudo update-ca-certificates
```
WARNING: this will still not work when OBS Studio is installed with Flatpak, since Flatpak isolates OBS Studio from the host and prevents it from reading the `ca-certificates` folder. Install OBS Studio through another mean (snap / ppa / .deb).
If you are using Windows, this can be accomplished with the command:
```sh
certutil -addstore "Root" myca.crt
```
## OBS Studio and WebRTC
### Standard
Recent versions of OBS Studio can also publish streams to the server with the [WebRTC / WHIP protocol](04-webrtc-clients.md) Use the following parameters:
- Service: `WHIP`
@@ -120,7 +186,7 @@ Save the configuration and click `Start streaming`.
The resulting stream will be available on path `/mystream`.
## OBS Studio and WebRTC, multitrack video
### Multitrack video
OBS Studio can publish multiple video tracks or renditions at once (simulcast) with WebRTC / WHIP too. Make sure that the OBS Studio version is ≥ 32.1.0. Open `Settings -> Stream` and use the following parameters:
@@ -133,3 +199,15 @@ Currently it's not possible to change resolution or bitrate (or canvas) of rendi
Save the configuration and click `Start streaming`.
The resulting stream will be available on path `/mystream`.
### Encryption
When publishing streams to _MediaMTX_ with WebRTC, you can encrypt the WebRTC handshake by using the HTTPS-based variant of WHIP. This can be enabled by using the `https` scheme:
```
https://localhost:8889/mystream
```
Make sure that WebRTC encryption is enabled in _MediaMTX_ (`webrtcEncryption: true`).
OBS Studio requires _MediaMTX_ to use a TLS certificate signed by a public certificate authority and silently rejects self-signed certificates. You can either buy a certificate from a public certificate authority or create a local certificate authority and use it to generate the server certificate and validate it on the OBS Studio machine. Instructions are reported in [OBS Studio and RTMP, encryption (RTMPS)](#encryption-rtmps).
+1 -1
View File
@@ -25,7 +25,7 @@ Streams can be published and read with the rtmps scheme and the 1937 port:
rtmps://localhost:1937/...
```
Be aware that RTMPS is currently unsupported by all major players. However, you can use a local _MediaMTX_ instance to decrypt streams before reading them, or alternatively a proxy like [stunnel](https://www.stunnel.org) or [nginx](https://nginx.org/). For instance, you can launch a local _MediaMTX_ instance with this configuration:
Be aware that RTMPS is currently unsupported by most major players. However, you can use a local _MediaMTX_ instance to decrypt streams before reading them, or alternatively a proxy like [stunnel](https://www.stunnel.org) or [nginx](https://nginx.org/). For instance, you can launch a local _MediaMTX_ instance with this configuration:
```yml
paths: