iCam and OScam: emulator setup and integration in 2026

If you came across a mention of iCam on some old forum and are now trying to understand what it actually is and why it matters, this article is for you. The topic of icam oscam is mainly found among those who work with old Enigma2 receivers or deal with inherited configs. Here — specifically, without fluff: what to install, how to configure, and why in 2026 the choice is obvious.

What is iCam and its place among emulators

The origin of iCam and its historical role

iCam appeared as a lightweight fork/variant of a CAM emulator for Linux STB, primarily for Enigma2 receivers based on Dreambox and VU+ platforms. At the time, it occupied a niche precisely because it was lightweight: a binary size of about 300–500 KB, minimal dependencies, it could run even on receivers with 64 MB RAM without problems.

The main audience of iCam is users of DM500 and DM600 first generations, where resources were catastrophically scarce. It could connect to CCcam servers and distribute CW (Control Word) to the tuner via DVB API. More was not particularly required from it.

The difference between iCam and OScam, CCcam, and MgCamd

The fundamental difference is in the architecture. iCam is a client. It can only receive a line and pass it to the tuner. OScam is a full-fledged softcam with its own system of readers, accounts, groups, support for physical cards, and a dozen protocols simultaneously.

CCcam is a proprietary daemon, long considered the de facto standard, but its development has also stopped. MgCamd is another client-emulator, slightly more functional than iCam, but also without active support. In the icam oscam pair — one has become obsolete, the other lives and develops.

ParameteriCamOScamMgCamdCCcam
Binary size~400 KB1.5–4 MB~600 KB~2 MB
RAM consumption4–8 MB8–20 MB6–10 MB15–30 MB
newcamd supportYesYesYesNo
cccam supportClient onlyClient + serverClient onlyClient + server
gbox supportNoYesNoNo
Physical cardsNoYesNoNo
Web interfaceNoYes (port 8888)NoNo
Active developmentNoYes (SVN + GitHub)NoNo

Supported protocols and CAS systems

OScam supports almost everything that is on air: Viaccess (CAID 0500), Irdeto (0600), Conax (0B00), Nagravision (1830), Seca (0100), Cryptoworks (0D00), BISS (2600). iCam could at best work through newcamd or cccam as a transport — it had no decoding logic of its own.

Why iCam is practically not being developed today

The last commits in the public iCam repositories date back to around 2012–2014. Development has stalled. There is no support for new CAS systems, bugs are not fixed. OScam, meanwhile, continues to be updated through the SVN repository streamboard and several active forks on GitHub.

So if someone asks about icam oscam and what to choose — the answer is unequivocal: OScam. There is no point in keeping iCam even on old hardware, because OScam compiles for mips, arm, and sh4 and fits into the same 64 MB.

Installing iCam and OScam on Enigma2/Linux STB

Preparing the receiver and access via SSH/Telnet

The first step — SSH or Telnet. By default, Enigma2 listens on port 22 (SSH) and 23 (Telnet). Login is root, the password depends on the firmware — usually either empty ordreambox, orroot. To connect:

ssh root@192.168.1.100

If the receiver is very old and does not have OpenSSH — Telnet also works. The main thing is to ensure that the receiver and PC are on the same subnet.

Directory structure: /etc/tuxbox/config/oscam/

After installing OScam, the configuration files are located in/etc/tuxbox/config/oscam/. There are also:

  • oscam.conf — global settings
  • oscam.server — readers
  • oscam.user — client accounts
  • oscam.dvbapi — binding to the tuner
  • oscam.srvid — service-ID database (optional)

The binary is located in/usr/bin/oscam. Logs are written by default to/tmp/oscam.log.

Installation via opkg/ipk and manual compilation

On Enigma2 with a normal feed repository, installation with one command:

opkg update
opkg install enigma2-plugin-softcams-oscam

If the repository is outdated or empty (a common situation with old DM500), you need to manually download the ipk package for your architecture (mipsel for old Dreambox, armv7 for VU+/Gigablue) and install it:

opkg install /tmp/oscam_1.20_mipsel.ipk

If you need iCam — you will have to look for it in third-party feeds, for example in opendreambox community repositories, but I warn you: there will be a binary from 2013.

Checking startup via init.d and systemd

On Enigma2 receivers, init.d is used. Auto-start OScam:

/etc/init.d/oscam start
/etc/init.d/oscam stop
/etc/init.d/oscam restart

Important point: if iCam is already running on the receiver — it must be disabled, otherwise both will compete for the DVB API of the tuner. Find the script:

ls /etc/init.d/ | grep -i cam

And disable the unnecessary one:

chmod -x /etc/init.d/icam

Default ports: 988 (newcamd), 12000 (cccam), 8888 (webif)

Check that OScam is running and listening on ports:

ps aux | grep oscam
netstat -tlnp | grep oscam

Should be open: 8888 (webif), 988 (newcamd server, if configured), 12000 (cccam server, if configured). If netstat is unavailable, an alternative:

ss -tlnp | grep oscam

Configuration files: oscam.conf, oscam.server, oscam.user

oscam.conf: global settings and webif

Minimum workingoscam.conf:

[global]
nice = -1
WaitForCards = 1
logfile = /tmp/oscam.log
loghistorylines = 200
maxlogsize = 512
preferlocalcards = 1

[webif]
httpport = 8888
httpuser = admin
httppwd = yourpassword
httpallowed = 127.0.0.1,192.168.0.0/24
httpdyndns =
httprefresh = 30
httpsavelog = 1

nice = -1 — increases the process priority, OScam will process ECM requests faster.preferlocalcards = 1 — if there is a physical card, it is used first before network readers.

oscam.server: configuring reader for card/line reception

Reader for connecting via newcamd protocol:

[reader]
label = my_newcamd_line
enable = 1
protocol = newcamd
device = server.example.com,10300
user = mylogin
password = mypassword
key = 0102030405060708091011121314
caid = 0500,0B00
group = 1
reconnecttimeout = 30
loadbalanced = 0

Herekey — DES key exactly 14 bytes = 28 hex characters, without spaces. This is a strict requirement of the newcamd protocol. If the key is of incorrect length, the reader will not start.

Reader for cccam:

[reader]
label = my_cccam_line
enable = 1
protocol = cccam
device = server.example.com,12000
user = cclogin
password = ccpassword
cccversion = 2.3.2
cccmaxhops = 5
cccreshare = 0
group = 1
reconnecttimeout = 30

oscam.user: creating users and groups

This is where most beginners make a mistake.group in the section[reader] andgroup in the section[account] must match. If the reader is in group=1 and the user is in group=2, nothing will work; the card "does not see" this client.

[account]
user = localclient
pwd = clientpassword
group = 1
au = my_newcamd_line
uniq = 0
caid = 0500,0B00
ident = 0500:032830,0B00:000000

au = my_newcamd_line — binding authorization updates to a specific reader. This is necessary for CAS systems that require EMM (Entitlement Management Message). For simple viewing without a subscription, au can be omitted.

oscam.dvbapi: mapping CAID for decoding

Fileoscam.dvbapi connects OScam with the DVB tuner. Without it, channels will not be decoded even with a working reader.

[dvbapi]
enabled = 1
au = 1
pmt_mode = 0
request_mode = 0
boxtype = dreambox
user = localclient

user = localclient — the same account as in oscam.user.boxtype = dreambox — for receivers based on Dreambox. For VU+ useboxtype = vuplus. If the DVB API is not linked to the tuner, the first thing to check is the match of user in dvbapi and account in oscam.user.

Connection of configs to each other through group ID

The scheme is simple: reader (group=1) → serves → account (group=1) → authorizes through → dvbapi (user=localclient). Different group-IDs for reader and account are the most common reason for "OScam is running, webif works, but channels are not decoded."

CAID for common satellite packages: Viaccess — 0500, Conax — 0B00, Nagravision — 1830, Irdeto — 0602. The exact CAID for a specific transponder can be viewed through webif in the CAID section or in the logs during the first launch.

Integration of iCam/OScam with CCcam protocol

Setting up cccam reader in OScam

As already shown above, cccam reader is configured inoscam.server. The key parameters that confuse people arecccversion,cccmaxhops andcccreshare.

[reader]
label = cccam_provider
enable = 1
protocol = cccam
device = remote-host.example.com,12000
user = username
password = password
cccversion = 2.3.2
cccmaxhops = 5
cccreshare = 0
group = 1
reconnecttimeout = 60
lb_weight = 100

Parameters cccversion, cccmaxhops, cccreshare

cccversion — the version of the protocol that OScam presents to the server. Most servers accept 2.3.2, some older ones require 2.2.1. If the server refuses the connection — try lowering the version.

cccmaxhops — the maximum number of card hops that OScam accepts. Hop=1 means the card is directly on the server. Hop=3 — three intermediate nodes. The more hops, the higher the ECM latency. I usually set it to no more than 3–4.

cccreshare — how many times OScam can forward this card to other cccam clients. 0 = do not share. This setting is for those who use OScam as an intermediate server.

How OScam distributes lines to other clients

Typical scheme: one receiver receives a line via cccam, OScam operates inside, and several TVs or media players in the local network connect to OScam via newcamd. This is reasonable — newcamd provides lower latency and works more stably than cccam for local clients.

For this, inoscam.conf we add a newcamd server:

[newcamd]
port = 988@0500:032830
key = 0102030405060708091011121314

And we create accounts in oscam.user for each local client.

Difference between cccam and newcamd connection

newcamd — a binary protocol with DES encryption, originally developed for cardsharing. It is faster, has less overhead, and lower ECM time. cccam — a proprietary CCcam protocol, more complex in structure, with a sharelist system and hop counter. On the same server, a newcamd connection usually gives ECM 150–250 ms compared to 300–500 ms for cccam.

Using STB as an intermediate link

The receiver receives cccam from the provider → OScam takes CW → distributes via newcamd on LAN. This works even behind NAT — the outgoing cccam connection passes through NAT normally. However, if you want external clients to connect to your OScam via newcamd — you need to forward port 988 on the router.

OScam web interface and monitoring

Enabling webif and access via browser

After starting OScam, open in the browserhttp://ip-receiver:8888. The login and password are those specified inoscam.conf section[webif]. If you can't log in — check that your IP is included inhttpallowed. This is the first thing that blocks access.

Status section: active clients and readers

In the Status tab, all active connections are visible: how many clients are online, which reader is responding to them, the last ECM time. Normal ECM avg — 200–400 ms. If you see 800+ ms — the problem is either in the ping to the server, or in server overload, or in high hop count.

If the ECM time is normal on one CAID but there are freezes on another — this usually means that the reader for the problematic CAID is not configured or is limited by ident. Check the CAID column in the Readers section.

Readers section: ECM time, CW count, errors

In the Readers section, each reader shows: status (CONNECTED, CONNECTING, FAILED), number of processed ECMs, average response time, number of errors. The columnidle — how long the reader has not received requests. If the reader has been idle for a long time and the channels are not working — it means the DVB API is not sending requests to this reader, or the CAID mapping is incorrect.

Real-time logs and filters by CAID

Via SSH:

tail -f /tmp/oscam.log

Via webif: Live Log tab. There you can filter by CAID, reader, log level. Very convenient for diagnostics — you see in real time each ECM request, from which service-ID, through which reader it was answered.

Protection of webif through httpallowed and password

Do not leave webif open on the internet. This is not paranoia — an open webif allows you to see the list of your lines, CAID, accounts. Correct configuration:

httpallowed = 127.0.0.1,192.168.1.0/24

If remote access is needed — SSH tunnel:

ssh -L 8888:192.168.1.100:8888 root@your-external-ip

Then openhttp://127.0.0.1:8888 on the local machine. The traffic goes through an encrypted SSH tunnel, the webif on the receiver remains closed from the outside.

Typical errors and their diagnostics

ECM error: not found — no CAID in reader

In the logs you see:no matching reader found for ECM orCAID: 0B00 not found. Reason: in the section[reader] the parametercaid = restricts which systems the reader processes. Either add the required CAID:

caid = 0500,0B00,1830

Or remove the linecaid = completely — then the reader will accept all CAIDs. The second option is easier for diagnostics.

Connection refused — port is closed or firewall

Check port availability from another machine:

telnet 192.168.1.100 988

IfConnection refused — OScam is not listening on this port, checkoscam.conf. If there is a timeout — iptables is blocking. View the rules:

iptables -L -n | grep 988

Add a rule if needed:

iptables -I INPUT -p tcp --dport 988 -j ACCEPT

Wrong DES key — error in newcamd key (28 hex)

The DES key for newcamd must be exactly 14 bytes = 28 hex characters. No spaces, no separators. A common mistake is copying the key with spaces or it turned out to be 26 or 30 characters. OScam will log:

reader my_line: invalid DES key length

Or the reader will start, but the connection will drop with an authentication error. Check the key length:

echo -n "your_key" | wc -c

It should be 28.

Card initializing failed — problem with reader/card

This is an error when working with a physical card through a reader (smartcard reader). First, check the device:

ls -la /dev/ttyUSB0
ls -la /dev/sci0

If the device exists but there is a permission error:

chmod 666 /dev/ttyUSB0

Inoscam.server for a physical card:

[reader]
label = smartcard
protocol = mouse
device = /dev/ttyUSB0
group = 1

High ECM time and image freezes

ECM time >1000 ms causes visible freezes. Diagnostics in order:

Check the ping to the server:ping server.example.com. If the ping >100 ms — that’s already half the problem. Check the load on the receiver:top. If the receiver's CPU is near 90% — OScam cannot process requests in time. Reduce cccmaxhops in the reader — each additional hop adds 50–150 ms to the ECM time. If freezes occur only on a specific CAID — check via webif that there is an active reader for this CAID, not just fallback through several hops.

How does iCam differ from OScam and what to choose in 2026?

iCam — an outdated lightweight client with no active development. OScam — a full-fledged softcam with support for physical cards, all protocols, a web interface, and an active community. For any new installation, only OScam — the question of icam oscam has long been resolved. There is no point in keeping iCam even on old hardware.

What port does OScam run on by default?

Web interface (webif) — port 8888. Newcamd protocol — port 988. Cccam protocol — port 12000. Camd35 protocol — port 14999. All ports are configured in the corresponding sections of oscam.conf and can be changed to any.

How to view OScam logs in real-time?

Through SSH on the receiver:tail -f /tmp/oscam.log. Or through the web interface on port 8888, Live Log tab — there are filters by CAID, reader, and detail level. For the most detailed log, run OScam with the flagoscam --debug 0xFFFF.

What is CAID and where to get a list for your satellite?

CAID (Conditional Access Identifier) — a numerical identifier of the encryption system. For example: Viaccess — 0500, Conax — 0B00, Nagravision — 1830, Irdeto — 0602. The exact CAID for a specific transponder is determined through the OScam web interface in the CAID section — it automatically collects this information when scanning with the tuner.

Why do freezes occur when using the cccam protocol?

The main reason is high ECM time due to hop count or server load. Check ECM avg in webif (norm 200–400 ms). Reducecccmaxhops in the reader to 3–4. If possible — switch to newcamd, it provides lower latency on the same server. Also check the ping to the reader host — ping >150 ms guarantees problems.

Is it safe to open OScam webif on the internet?

No. An open webif shows a list of your lines, accounts, and configs. The correct solution is to limithttpallowed only with a local network (for example 192.168.0.0/24) and organize remote access via SSH tunnel or VPN. Port 8888 on the internet is a risk of leaking the entire configuration.

Can OScam be run on a router or Raspberry Pi?

Yes. OScam is compiled for ARM and there are ready packages for OpenWRT (ipk archives for mipsel/armv7) and Raspberry Pi OS (deb for armhf/arm64). Minimum requirements: 64 MB RAM, binary size 2–4 MB depending on the enabled modules. OScam works without problems on Raspberry Pi Zero.

Practical checklist for smooth viewing

Even the best CCCam or OSCam line needs two or three simple preparations. Update your receiver firmware, reset the ECM cache once a week and keep 15–20% free space on the USB stick or internal flash so that the reader can store keys without delays.

When tuning a dish, aim for MER/BER reserve: a two‑degree offset or a loose F‑connector often causes the “freezing” that users blame on cardsharing. Keep a short patch cord to test alternative routers, and save two profiles in OSCam — one for TCP, one for UDP — so you can switch instantly if your ISP starts filtering a protocol.

Utgard.tv monitors each hub 24/7, but you can speed up diagnostics by keeping a short log of your receiver actions. Note the time when you changed the channel, which CAID was active and whether you used Wi‑Fi or Ethernet. This tiny “journal” helps engineers reproduce your environment in the lab and return with a solution in minutes instead of hours.

  • Keep two line slots enabled: if the first server hits a maintenance window, the second one instantly takes over without re-entering credentials.
  • Run a monthly speed and latency test. Stable 1–2 Mbps with ping <80 ms is enough for SD/HD, but if jitter exceeds 20 ms, switch the router to wired mode.
  • Save the Utgard.tv status page and Telegram bot @utgard_sharing_bot to bookmarks — they publish maintenance notices before SEMrush or uptime monitors raise alerts.