Setting up card sharing on Windows: step-by-step guide 2026

Card sharing allows multiple receivers to use one paid smart card to decode encrypted satellite channels. This article provides a complete setup of the card sharing server and client on Windows 10 and Windows 11, including software selection, file configuration, and connection testing.

What is card sharing and how does it work

Card sharing is a technology for sharing conditional access (Conditional Access, CA) to encrypted TV channels. The physical smart card is located in one CAM module or card reader connected to the server. The server reads control words (Control Words, CW) from the card and transmits them over the network to client receivers, which use these words to decrypt the signal in real time.

Control words are updated every 10 seconds (the standard MPEG-2 scrambling cycle), so the latency in the network between the server and the client is critically important. With a ping above 300 ms, artifacts or temporary freezes appear on the screen.

Supported encryption systems

  • Nagravision 3 (Nagra3) — used on Viasat, Sky Deutschland
  • Viaccess 2.6 / 3.0 — Tricolor TV of older generations, Canal+
  • Conax — a number of Eastern European operators
  • Irdeto 2 — platforms on Hotbird 13°E
  • Biss — unencrypted channels with a fixed key (sports broadcasts)

Necessary software for Windows

On Windows, the role of the card sharing server is most often performed by two applications:CCcam (closed protocol, historically popular) andOScam (open source, current development). For most tasks in 2026, OScam is recommended — it supports more encryption systems, is actively updated, and has a web interface for monitoring.

OScam for Windows

Official OScam builds for Windows are available in the Releases section of the project repository. You need the version markedoscam-XXXX-win32 orwin64. After downloading, unpack the archive into a folder, for exampleC:\OScam\. The folder should contain:

  • oscam.exe — executable file
  • oscam.conf — main configuration file
  • oscam.server — description of readers (cards)
  • oscam.user — client list

Installing CCcam on Windows

CCcam is a proprietary program originally written for Linux. On Windows, it runs through the Cygwin emulator or a special Windows build. The configuration is stored in a single fileCCcam.cfg, which simplifies initial setup but limits flexibility.

Setting up OScam server on Windows

File oscam.conf — main parameters

Open the fileoscam.conf with any text editor (Notepad++, VS Code). The minimum working configuration looks like this:

[global]

The parameternewcamd defines the port for the NewCamd protocol (used directly by most receivers). The parametercccam opens the port for clients via the CCcam protocol. The number after@ — is the encryption system identifier:0500 — this is Viaccess,0B00 — Nagravision.

File oscam.server — connecting the card reader

This describes the physical card reading device. If a USB card reader is used (for example, Omnikey 3121 or SCR3310), the entry will look like this:

[reader]

The parameterprotocol = pcsc indicates OScam to use the PC/SC interface, standard for Windows. The device name in thedevice field must match what the system sees — it can be found in the device manager or in the OScam web interface under the "Readers" tab.

If the card is in a receiver with a CAM module that transmits data over the network, thecs357x ornewcamd protocol is used in the reader section.

File oscam.user — creating client accounts

Each client (receiver, set-top box, plugin on media player) must have a unique entry:

[account]

The parameterau = 1 includes EMM auto-update for this client — relevant for the main receiver. For the player on PC (Kodi, VLC with plugin) EMM is usually not needed, soau = 0.

Firewall configuration and port forwarding

Opening ports in Windows Defender Firewall

OScam listens on several ports by default. Each needs to be opened manually:

  1. Open "Control Panel" → "System and Security" → "Windows Defender Firewall"
  2. Click "Advanced settings" → "Inbound Rules" → "New Rule"
  3. Select "Port", specify TCP, enter port numbers separated by commas:12000, 15000, 8888
  4. Select "Allow the connection", set the rule name — for example,OScam Cardsharing

Port forwarding on the router

To allow clients from the internet to connect to the server, configure Port Forwarding on the router. On most devices, this is the "NAT" or "Virtual Servers" section. Example for a router with OpenWrt firmware:

config redirect

Here192.168.1.100 — local IP of the computer with OScam. A static IP in the local network is mandatory — assign it through the router's DHCP settings by MAC address of the network card.

Connecting clients to the cardsharing server

Configuring Dreambox / Enigma2 receiver

On receivers with Enigma2 (Dreambox, VU+, Formuler, and others) install the pluginCCcam orOScam via the package manager. CCcam client configuration file:

C: 93.184.216.100 12000 receiver01 pass_receiver01 no 01 { 0500:000000 }

The line is interpreted as follows:C: — type of line (Client), followed by the server IP address, port, login, password, encryption type (no = without DES), priority, and in curly braces — allowed CAID.

Configuring Kodi with IPTV Simple or Oscar plugin

Kodi does not support cardsharing directly, but the combinationTVHeadend + OScam allows watching encrypted channels over the local network. TVHeadend is installed as a service on the same PC or on Raspberry Pi, OScam acts as a CA client:

  1. In TVHeadend, open "Configuration" → "CAs" → add a new module of typeoscam
  2. Specify the OScam address:127.0.0.1 and port9001 (for the DVBAPI protocol)
  3. In the fileoscam.conf add the section:
[dvbapi]

Configuring the Android receiver through the app

On Android set-top boxes (Mecool, Formuler Z8, X96 Max+) the appTivimate is used in conjunction with the pluginOSCAM-client or an IPTV player that supports SoftCam. The connection parameters are identical to the Enigma2 settings — server IP, port, and credentials from the fileoscam.user.

Autostart OScam in Windows

To have the server start automatically when Windows starts, register OScam as a system service using the utilityNSSM (Non-Sucking Service Manager):

nssm install OScam "C:\OScam\oscam.exe" "-B -c C:\OScam"

After this, OScam will appear in the list of Windows services (services.msc) and will start with the system without requiring user login.

Diagnostics and troubleshooting

The channel freezes every 10 seconds

This is a classic symptom of delay when updating control words. Check the ping from the client to the server with the commandping 93.184.216.100 -n 20. If the average response time exceeds 200 ms — the problem is in the network. Possible solutions: choose a closer server, switch from Wi-Fi to Ethernet, configure QoS on the router to prioritize card sharing traffic.

Error "Card not found" in OScam logs

Open the OScam web interface athttp://127.0.0.1:8888 and go to the "Readers" tab. If the reader shows the status "CARD NOT INSERTED" — check the physical connection of the card reader and the presence of PC/SC drivers (the "Smart Card" service in Windows should be running). If the status is "CARD ERROR" — the card may be damaged or incompatible with the reader.

The client connects, but channels are not decoded

In the fileoscam.user check the parametercaid — it should correspond to the encryption system of the specific channel. You can view which CAID the channel uses in the signal information on the receiver (menu "Channel Information" or INFO button on the remote).

Security of the card sharing server

An open internet card sharing server must be protected from unauthorized access:

  • Use complex passwords inoscam.user — at least 12 characters with numbers and special characters.
  • Restrict access to the web interface (httpport) only to the local network via the parameterhttpallowed = 127.0.0.1,192.168.1.0/24
  • Set up fail2ban or a similar tool to block IPs after several failed connection attempts
  • Regularly update OScam — new versions close vulnerabilities in protocol parsing

Frequently Asked Questions

Can card sharing be used with a virtual card (emulator)?

Technically, OScam supports software card emulators (SoftCam), but functionality depends on the specific encryption system and the availability of current keys. For Nagravision 3, emulation does not work due to cryptographic protection. For Biss and some outdated systems — it is possible.

How many clients can one server serve?

Theoretically, one card can serve up to 10–15 simultaneous clients provided there is a good channel. In practice, operators monitor for abnormal activity and block cards with a suspicious number of requests. A reasonable number of clients is 3–5.

Does OScam work on Windows 11?

Yes, OScam works on Windows 11 without additional compatibility settings. The 64-bit executable interacts correctly with the smart card service via the standard PC/SC interface.

Practical checklist for smooth viewing

Even the best CCCam or OSCam line needs two or three simple preparations. Update your receiver firmware, reset the ECM cache once a week and keep 15–20% free space on the USB stick or internal flash so that the reader can store keys without delays.

When tuning a dish, aim for MER/BER reserve: a two‑degree offset or a loose F‑connector often causes the “freezing” that users blame on cardsharing. Keep a short patch cord to test alternative routers, and save two profiles in OSCam — one for TCP, one for UDP — so you can switch instantly if your ISP starts filtering a protocol.

Utgard.tv monitors each hub 24/7, but you can speed up diagnostics by keeping a short log of your receiver actions. Note the time when you changed the channel, which CAID was active and whether you used Wi‑Fi or Ethernet. This tiny “journal” helps engineers reproduce your environment in the lab and return with a solution in minutes instead of hours.

  • Keep two line slots enabled: if the first server hits a maintenance window, the second one instantly takes over without re-entering credentials.
  • Run a monthly speed and latency test. Stable 1–2 Mbps with ping <80 ms is enough for SD/HD, but if jitter exceeds 20 ms, switch the router to wired mode.
  • Save the Utgard.tv status page and Telegram bot @utgard_sharing_bot to bookmarks — they publish maintenance notices before SEMrush or uptime monitors raise alerts.