Skip to content
Castreon
Delivery

DRM — Widevine, PlayReady and FairPlay

Updated 06 Oct 2026

Castreon can encrypt a channel with the three DRM systems that devices use for paid content: Widevine (Android, Chrome, Firefox, Android TV, most Smart TVs), PlayReady (Windows, Edge, Xbox, Smart TVs) and FairPlay (Safari, iPhone, iPad, Apple TV). The picture and the sound can only be decrypted inside the protected part of the device, with a license that your DRM provider gives each viewer.

Available from Castreon 1.0.5, on the Enterprise plan. For simple encryption on every plan, see HLS encryption with AES-128.

Who does what

Does
Castreon at every start of the channel asks your DRM provider for a new key (CPIX), encrypts the channel and publishes DASH and HLS with the DRM information players need
Your DRM provider (for example DoveRunner) keeps the keys and gives licenses to players
Your platform (app, website, middleware) decides who may watch and creates a license token for every viewer

Castreon never issues licenses and never sees your subscribers. The packaging is done by Shaka Packager, which is included in Castreon (BSD license) — there is nothing extra to install.

What you need

  • An Enterprise license on the server.
  • An account with a DRM provider that delivers keys over CPIX — for example DoveRunner (formerly PallyCon). The provider's plan must include the DRM systems you want (FairPlay also needs an Apple FairPlay Streaming certificate, which the provider explains).
  • Channels in H.264 or HEVC.
  • HTTPS for web players: browsers only allow DRM on HTTPS pages.

1. Connect your DRM provider

Settings → DRM:

  1. At DRM provider, choose:
    • DoveRunner (PallyCon) — paste only the KMS Token from DoveRunner Console → Multi-DRM → DRM Settings; Castreon builds the address itself;
    • Other provider (CPIX) — paste the complete CPIX address of your provider, with the token included (HTTPS only).
  2. Save. The KMS server shows the provider and the name of its server; the token itself is never shown again — not in the panel, not in the API, not in the audit log and not in the diagnostic report.
  3. Test connection asks for a test key for each delivery. You should see DASH (CENC) with PlayReady and Widevine, and HLS (CBCS) with FairPlay, Widevine and PlayReady.

The status at the top right shows Ready when the license, the provider and Shaka Packager are all in place.

2. Add the DRM output to a channel

  1. Open the channel → Edit → Add output and choose DRM as the Type.
  2. Content ID — the name under which the provider stores the key. Empty means the short name of the channel. Letters, digits, dot, dash and underscore.
  3. Choose the deliveries:
    • DASH · Widevine + PlayReady (CENC)
    • HLS · FairPlay + Widevine + PlayReady (CBCS)
  4. Optionally change Segment duration (s) (default 4) and Segments in playlist (default 6).
  5. Save. The channel restarts with the DRM output.

The other outputs of the channel keep working as before and are not encrypted. For a paid channel, keep only the DRM output (and, if you need them, push outputs to your own systems).

The addresses and the content IDs

For a channel with the short name channel1, Delivery shows:

Row in Delivery Value
DRM · DASH (Widevine, PlayReady) http://<domain>/live/channel1/drm/dash/manifest.mpd
DRM · DASH · content ID channel1
DRM · HLS (FairPlay, Widevine, PlayReady) http://<domain>/live/channel1/drm/hls/master.m3u8
DRM · HLS · content ID channel1-hls

DASH and HLS use different keys (CENC and CBCS must not share a key), so they have different content IDs: the HLS one ends in -hls. The license token your platform creates must use the content ID of the delivery the player opens.

The same Token for players and Allowed addresses apply as for the other outputs.

Which delivery for which device

Device Delivery DRM
Android phones and tablets, Android TV, Fire TV DASH Widevine (ExoPlayer / Media3)
Chrome, Firefox, Edge, Opera on a computer DASH Widevine (Edge also PlayReady) — with Shaka Player, dash.js, Video.js, Bitmovin, THEOplayer…
Samsung (Tizen), LG (webOS) and other Smart TVs DASH PlayReady or Widevine
Windows apps, Xbox DASH PlayReady
Safari on Mac, iPhone, iPad, Apple TV HLS FairPlay (AVPlayer, Safari)

Your player needs: the address of the delivery, the license server address of your provider and the license token of the viewer (DoveRunner: in the pallycon-customdata-v2 header). For FairPlay it also needs the FairPlay certificate address from your provider.

The license token

Your platform creates the token on its server, for every viewer, with the content ID, the DRM type and the rules (for example how long the license is valid), and signs it with the keys of your provider account (DoveRunner: Site ID, Site Key and Access Key). Keep these keys on your server — never in the app or in the web page. Your provider documents the exact format.

How it behaves

  • A new key at every start. When the channel restarts, the players load the new manifest and ask for a new license by themselves.
  • The provider does not answer: the channel does not deliver anything on the DRM addresses and tries again. The content never reaches the DRM addresses unencrypted.
  • No Enterprise license, no provider set, or a codec Shaka cannot take (AV1, VP9, copied MPEG-2): the channel starts without the DRM output and its log says why; the other outputs keep running.
  • Live clock: the DASH manifest tells players the time of the server (from /live/time, with a public time server as backup), so devices with a wrong clock still find the current segments. With the Public domain set to https://…, players use the full address of your server.
  • The keys received from the provider are kept only while the channel runs, readable only by Castreon, and deleted when it stops.

If it does not work

  • Test connection: "… refused the key request: HTTP 401 (or 403) — check the token in the KMS address" — the KMS Token (or the CPIX address) is wrong or was regenerated at the provider.
  • "the DRM provider sends the keys encrypted for a recipient" — turn off key encryption (CPIX with certificate) in the provider account; the connection is HTTPS anyway.
  • "the DRM provider did not send the data for FairPlay" (or another system) — the system is not active in your provider plan.
  • The channel log says "warning: the DRM output is off — …" — the reason follows: the plan, the provider settings, the codec of the profile or the source.
  • The player loads the manifest but gets no license — the problem is in the license token or the provider account: the content ID (with -hls for HLS), the DRM type, the validity time, the provider keys. Your provider's test tools (for DoveRunner: DevConsole) show the exact error code.
  • No picture in the browser, no error — the page or the stream is on HTTP; browsers only allow DRM over HTTPS.

Privacy

Cookies & local storage

Strictly necessary cookies are always active. Analytics and marketing use Google services and only start if you accept them — until then nothing is sent to Google. You can withdraw your consent here at any time.

Strictly necessary

Without them, sign-in, forms and your chosen language don’t work. They don’t require consent (§ 25(2) no. 2 TDDDG).

Always active
Name Purpose Duration Type
castreon-session Keeps your session: sign-in and chosen language 2 hours, renewed on every visit Cookie
XSRF-TOKEN Protects forms against forged requests 2 hours, renewed on every visit Cookie
remember_web_… Only if you tick “Remember me” at sign-in Until you sign out, max. 400 days Cookie
__cf_bm Cloudflare: tells visitors and bots apart, only when traffic is being checked 30 minutes Cookie · Cloudflare
castreon:consent Remembers your cookie choice 12 months Local storage
theme Customer account appearance: light, dark or system Until you change it Local storage

Analytics

Google Analytics 4 (Google Ireland Ltd.): which pages are visited, where visits come from and on which type of device — with pseudonymous identifiers, without storing your IP address. Helps us improve the website.

Name Purpose Duration Type
_ga Google Analytics: recognises the visitor (pseudonymous ID) 13 months Cookie · Google Analytics
_ga_VHWQRPHPEF Google Analytics: keeps the state of the visit 13 months Cookie · Google Analytics

Marketing

Google Ads (Google Ireland Ltd.): measures whether visits from Google ads lead to a trial or a plan, and allows Castreon ads to be shown on other websites (remarketing).

Name Purpose Duration Type
_gcl_au, _gcl_aw Google Ads: links the visit to the ad click (conversions) 90 days Cookie · Google Ads
IDE, test_cookie Google Ads: remarketing and ad measurement, on Google domains (doubleclick.net) Up to 13 months Cookie · Google (third party)