
If you are dealing with icam settings and cannot understand why the channels are silent after installation — you are in the right place. iCam looks like OScam, but behaves slightly differently, especially in terms of the FreeCAM protocol and ECM processing. Here we will break down the configs from start to finish: from access rights to failban and dvbapi mapping.
What is iCam and where are its configs stored
iCam is a fork of OScam, tailored for the FreeCAM protocol. The basic architecture is the same: oscam.conf, oscam.server, oscam.user, oscam.dvbapi. But inside, patches have been added for specific ECM request processing and optimization for certain chipsets — Broadcom, HiSilicon, Amlogic.
If you already have a working OScam config, it will usually work in iCam without changes. The exception is FreeCAM-specific parameters that are not present in pure OScam.
Differences between iCam and classic OScam
The main difference is the native support for the FreeCAM protocol. It is completely absent in classic OScam. iCam also processes ECM timeout slightly differently in multi-reader configs: it switches to the next reader more aggressively in case of a delay, which reduces glitches on weak channels.
Another point: iCam often has a more up-to-date database of softcam keys and updated provid tables for a number of European packages. Otherwise, the parameters are the same, the syntax is the same.
Location of configuration files
On Enigma2 receivers (OpenATV, OpenPLi, VTI), the configs are located here:
/etc/tuxbox/config/oscam.conf— main config/etc/tuxbox/config/oscam.server— readers/etc/tuxbox/config/oscam.user— client accounts/etc/tuxbox/config/oscam.dvbapi— CAID mapping for decoding
On some images, the folder is called /etc/tuxbox/config/oscam/ (with a subfolder). Check via find /etc/tuxbox -name "oscam.conf" — this is more accurate than guessing.
On a Linux x86 server, the standard path is /usr/local/etc/ or /etc/oscam/. It depends on how the binary was built. Look in oscam --version — there will be a line Config dir:.
Access rights and file owner
Configs should belong to root and be unreadable to outsiders. Especially oscam.user — it contains client passwords in plain text:
chmod 600 /etc/tuxbox/config/oscam.conf
chmod 600 /etc/tuxbox/config/oscam.server
chmod 600 /etc/tuxbox/config/oscam.user
chown root:root /etc/tuxbox/config/oscam.*
If iCam is not running as root (which is rare, but happens), change the owner accordingly. Incorrect permissions are a common reason why the service starts but nothing works: the file is simply unreadable.
Basic oscam.conf setup for iCam
This is the central file. Most problems with icam settings start here — incorrect WebIf port, logging disabled, aggressive anticasc. Below is a working template with an explanation of each parameter.
Section [global] — nice, logfile, WaitForCards
[global]
logfile = /var/log/oscam.log
maxlogsize = 10000
loghistorysize = 256
nice = -1
WaitForCards = 1
preferlocalcards = 1
saveinithistory = 1
readerrestartseconds = 5
dropdups = 1
nice=-1 gives iCam a slightly higher scheduler priority — on busy receivers, this reduces ECM delays by 50–150 ms. WaitForCards=1 means that the service will not start client connections until all readers are initialized. Without this, the client connects, receives 0 cards, and disconnects.
dropdups=1 — protection against duplicate ECM requests. On multi-client servers, without this, you can get double load on the same channel for multiple users.
Section [webif] — httpport, httpuser, httppwd, httpallowed
[webif]
httpport = 8888
httpuser = myadmin
httppwd = MyStr0ngPass!
httpallowed = 127.0.0.1,192.168.0.0-192.168.255.255
httpdyndns = 0
httprefresh = 15
httpreadonly = 0
Port 8888 is standard for OScam/iCam WebIf. If it is occupied (something often hangs on 8888 on the receiver), use 8080, 8090, 9080. Important: httpallowed must include only your addresses. No httpallowed = 0.0.0.0 — this is open access to the interface from any IP.
If the receiver is behind NAT and you want to access WebIf from outside — add only the specific external IP, not a range.
Section [monitor] — port, aulow, monlevel
[monitor]
port = 988
aulow = 30
monlevel = 2
hideclientfrom = 0
monlevel=2 allows you to see clients and readers through monitoring, but not change the config. monlevel=0 — complete ban, monlevel=4 — full access. For production, keep 2.
Section [anticasc] — anti-cascade settings
[anticasc]
enabled = 1
numusers = 1
sampletime = 2
samples = 10
penalty = 2
aclogfile = /var/log/oscam_ac.log
fakedelay = 1000
denysamples = 10
Anti-cascade protects against sharing your line. numusers=1 — one account = one connection. penalty=2 — in case of violation, the account receives a response delay (fake delay), not a drop — this is softer and less likely to break legitimate clients with an unstable network.
On old receivers with ARM 400 MHz, it is better to disable anticasc (enabled=0) or raise sampletime to 10. Otherwise, the anti-cascade process will consume more CPU than useful work.
Setting up oscam.server — connecting readers
The oscam.server file describes where iCam gets the keys for decryption. Each [reader] block is one source: physical card, CCcam line, Newcamd server, or FreeCAM.
Local DVB card (protocol = internal)
[reader]
label = local_dvb
protocol = internal
device = /dev/sci0
detect = cd
mhz = 357
cardmhz = 357
caid = 0500,0604
group = 1
emmcache = 1,3,2
On Enigma2, the physical card is almost always /dev/sci0 (first slot) or /dev/sci1 (second). If the receiver uses the DVB stack, it may be /dev/dvb/adapter0/ca0. Check: ls /dev/sci* /dev/dvb/.
With two tuners on one receiver — each tuner gets its own [reader] with a separate device and different groups. Then clients can be distributed across groups: some clients watch through adapter0, others through adapter1.
CCcam client (protocol = cccam)
[reader]
label = cccam_main
protocol = cccam
device = yourserver.example.com,12000
user = myusername
password = mypassword
cccversion = 2.3.2
cccmaxhops = 5
cccmindown = 0
ccckeepalive = 1
inactivitytimeout = 30
reconnecttimeout = 30
group = 2
caid = 0500,0604,1830
cccversion=2.3.2 — most modern servers support this version of the protocol. There is no point in using 2.0.11 or 2.1.x if the server does not require a specific version.
inactivitytimeout=30 and reconnecttimeout=30 — if the reader is silent for 30 seconds, iCam will try to reconnect. Without these parameters, a hung reader can hang for hours without providing keys.
Newcamd connection (protocol = newcamd)
[reader]
label = newcamd_reader
protocol = newcamd
device = yourserver.example.com,15000
user = nmuser
password = nmpass
key = 0102030405060708091011121314
caid = 0604
group = 3
Newcamd requires a key (14 bytes in hex). If you do not know the key — ask your line provider. Without the correct key, the handshake will not pass, and the reader will remain in FAIL status.
FreeCAM specifics of iCam
FreeCAM — a protocol for which many choose iCam. It is configured as a separate block:
[reader]
label = freecam_reader
protocol = freecam
device = yourfreecamserver.com,8080
user = fcuser
password = fcpass
group = 4
caid = 1830,0B00
inactivitytimeout = 60
FreeCAM uses its own binary protocol — not CCcam, not Newcamd. The port varies among different servers, most often in the range of 8080–8090. Specific parameters depend on the server — check with your provider.
Parameters group, caid, ident, fallback
group — this is a key parameter for routing. A reader with group=2 will be used only by those clients (oscam.user) who also have group=2specified. Without matching groups — 0 cards, even if the reader is alive.
fallback=1 marks the reader as backup — iCam will only refer to it if the main readers do not respond. Convenient for the "expensive line on standby" scenario.
ident restricts the reader to specific provid. For example, ident=0500:032830,032000 — the reader will decode only these two providers CAID 0500. Other requests will go to other readers.
Setting up oscam.user — clients connecting to you
If you are sharing the signal with others — each client gets an entry in oscam.user. Without this file, client connections will be rejected.
Creating a client account
[account]
user = client1
pwd = client1pass
group = 1,2
cccmaxhops = 1
cccreshare = 0
au = 1
caid = 0500,0604,1830
monlevel = 0
uniq = 1
uniq=1 — one IP = one connection for this account. Protection against sharing the login. uniq=3 — one account in principle, regardless of IP.
Binding to reader groups via group
When the client sends an ECM request, iCam checks: which readers are available to the client? Specifically, those indicated in group the account and matching group the readers. If the client is in group=1, and your readers are in group=2 — the client will receive nothing.
Restrictions: cccmaxhops, cccreshare, au, caid
The difference between cccmaxhops and cccreshare confuses almost everyone who starts with icam settings.
cccmaxhops determines which "depth" cards the client can see. If you have a reader connected to a server that has cards on hop 1, and you set the client to cccmaxhops=1 — they see these cards. If cccmaxhops=0 — only physical cards directly in your receiver.
cccreshare — whether the client is allowed to further forward the received cards to their clients. cccreshare=0 means: not allowed. This is the standard setting — you do not want the client to build their server on your line.
au=1 — allows EMM card updates through this client. This is rarely needed, only if the client is itself a reader with a physical card.
Protection: monlevel, failban, suppresscmd08
[account]
user = client1
pwd = client1pass
group = 1
monlevel = 0
suppresscmd08 = 1
suppresscmd08=1 disables command 0x08 from the client — this reduces protocol chatter and slightly lowers the load. Failban is configured in oscam.conf: failbancount=3, failbantime=600 — three failed logins and the IP is banned for 10 minutes.
Configuring oscam.dvbapi for Enigma2
Without the correct oscam.dvbapi, iCam will not know which reader to use to decode a specific channel. This is critical for Enigma2 receivers — this is where the mapping "channel → CAID → priority" is configured.
Syntax of mapping lines
P: 0500:032830 0000
P: 0604:000000 0000
I: 1702:000000 0000
D: 0500:032830 7007 0:0:1500
P: — priority (Priority). iCam will try this CAID:provid first for the specified SID (0000 = all channels). I: — ignore (Ignore). Do not touch this CAID at all. D: — delay in milliseconds before sending ECM.
CAID and provider priority
The order of lines P: matters. iCam reads from top to bottom and uses the first matching CAID. If a channel has both 0500 (Viaccess) and 0604 (Irdeto) — which one to try first? The one that is higher in the file.
Example for a typical European configuration:
P: 0500:032830 0000
P: 0500:032000 0000
P: 0604:000000 0000
P: 1830:000000 0000
P: 0B00:000000 0000
Ignoring channels (I:)
If a certain CAID causes problems (for example, FTA channels that iCam tries to decode and wastes ECM requests):
I: 1702:000000 0000
I: 0:0 1234
The second line completely ignores the specific SID 1234 — iCam will not attempt to decode it at all.
Delays and chid
If the picture glitches for the first 1–2 seconds when switching channels — add a delay:
D: 0500:032830 0000 0:0:800
800 ms delay gives the receiver time to stabilize the stream before the first ECM request. Adjust the number experimentally: 500, 800, 1200. More than 2000 — there will already be a noticeable pause when switching.
Port forwarding and network settings
iCam can be configured perfectly, but without the correct network settings, clients will not reach it.
Which ports to open on the router
- CCcam: by default 12000 (configured in
[cccam]the oscam.conf section) - Newcamd: usually 15000–15010
- WebIf: 8888 (or whatever you specified in httpport)
- Monitor: 988
On the router, only forward the ports that are actually needed by external clients. WebIf to the outside — only if you are using remote monitoring and understand the risks.
DDNS for dynamic IP
If the provider gives a dynamic IP — DDNS is needed. DynDNS, No-IP, Duck DNS — any will do. The main thing is that your router or receiver updates the record automatically. Clients specify your DDNS host instead of the IP.
If the provider uses CGNAT (your "external" IP starts with 100.64.x.x or 10.x.x.x) — direct port forwarding does not work. A VPN with a dedicated IP or reverse-tunnel through a VPS is needed. WireGuard + forwarding through VPS is a working and inexpensive option.
Firewall iptables — example of rules
# Разрешить CCcam
iptables -A INPUT -p tcp --dport 12000 -j ACCEPT
# Разрешить WebIf только с локальной сети
iptables -A INPUT -p tcp --dport 8888 -s 192.168.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8888 -j DROP
# Разрешить Newcamd
iptables -A INPUT -p tcp --dport 15000 -j ACCEPT
On Ubuntu/Debian with ufw:
ufw allow 12000/tcp
ufw allow from 192.168.0.0/24 to any port 8888
ufw allow 15000/tcp
Testing connection telnet/nc
Quick check — try to connect to the port:
telnet yourserver.com 12000
# или
nc -zv yourserver.com 12000
If the connection is established (garbage appears or a pause instead of "Connection refused") — the port is open and iCam is listening. If there is an immediate refusal — either iCam is not running, or the firewall is blocking.
Solutions to typical iCam problems
Most problems with icam settings can be solved through logs. The first thing to do is to make sure that logging is actually working.
Channels do not open — diagnostics by logs
Temporarily enable detailed logging:
[global]
logfile = /var/log/oscam.log
debug = 4
Then:
tail -f /var/log/oscam.log
Switch to the channel and see what is being written. Look for lines with ECM, FOUND, NOT FOUND, TIMEOUT. If you see ECM TIMEOUT — the reader does not have time to respond. If NO MATCHING READER — there is a problem with group or caid filters.
After diagnostics, be sure to return debug=0. With debug=65535 logging on a busy server grows by 50–100 MB per hour.
ECM timeout — what to check
Standard ctimeout in iCam — 3500 ms. On slow or unstable lines, this is not enough. Try:
[global]
ctimeout = 5000
If after increasing the timeout the channels open — the problem is with the line delay. Look for a faster server or check your internet connection.
CCcam client connects but 0 cards
The most common reasons:
- Group mismatch: reader in group=2, client looking in group=1
cccreshare=0on the account on the server — it does not pass the cards further- Reader is connected, but the card is not initialized — check the status in WebIf
caidfilter in oscam.user does not include the required CAID
In WebIf (http://yourserver:8888) the "Readers" section shows each reader and the number of cards. If the reader is CONNECTED but 0 cards — the problem is on the server side, not yours.
FreeCAM does not work
FreeCAM requires a specific version of the iCam binary — not every build includes support. Check:
icam --version
There should be a line with FreeCAM in the list of supported protocols. If it is not there — you have the standard OScam build, not iCam with the FreeCAM patch. You need the correct binary for your platform.
High CPU load
On Enigma2 with ARM 400–600 MHz high CPU from iCam — almost always one of three:
- Anticasc too frequent
sampletime— increase to 5–10 - Fallback reader is stuck: main reader drops, fallback responds, main reconnects, gets stuck again — cycle every 30 seconds
- Debug log is enabled and written to slow Flash memory
On old receivers (400 MHz) anticasc is better to disable completely. Also move the log to RAM disk: logfile=/tmp/oscam.log — this drastically reduces I/O load.
Security and optimization of the iCam server
Many configure icam settings and forget about security. This is a mistake. An open WebIf with default passwords is a real risk.
Strong passwords and disabling defaults
Never leave standard credentials. Replace them immediately after the first launch:
[webif]
httpuser = adminname_not_admin
httppwd = R4nd0m!P@ssw0rd#92
The same for client accounts in oscam.user — passwords like "1234" or "test" are scanned by automated bots in the first hours after opening the port.
WebIf IP restriction
The best protection for WebIf is not to expose it at all. If remote access is needed — use an SSH tunnel:
ssh -L 8888:localhost:8888 user@yourserver.com
After that, WebIf is accessible on your localhost:8888 through an encrypted tunnel. Port 8888 on the server can be left only for 127.0.0.1.
Logging suspicious connections
iCam logs every login — successful and unsuccessful. Set up rotation and keep logs for at least 30 days:
[global]
logfile = /var/log/oscam.log
maxlogsize = 50000
If you see a lot in the logs WRONG PASSWORD from one IP — this is a brute force. Add the IP to the iptables blacklist. failbancount=3 and failbantime=600 in oscam.conf automate this.
Regular binary updates
iCam is updated infrequently, but each update is either a security fix or an improvement in compatibility with new readers. Before updating:
# Бэкап конфигов
tar czf /root/icam_config_backup_$(date +%Y%m%d).tar.gz /etc/tuxbox/config/oscam*
# Остановить сервис
/etc/init.d/icam stop
# Заменить бинарник
cp icam_new /usr/bin/icam
chmod 755 /usr/bin/icam
# Запустить
/etc/init.d/icam start
Configs between minor versions are compatible. For major updates — read the CHANGELOG for changes in syntax.
How does iCam differ from regular OScam?
iCam is a fork of OScam with support for the proprietary FreeCAM protocol, modified ECM processing, and optimizations for specific chipsets (Broadcom, Amlogic). Configuration files are fully compatible with OScam — existing configs can be transferred without changes. The only thing that will not transfer is FreeCAM-specific parameters that are not present in pure OScam.
Where is the iCam config located on an Enigma2 receiver?
The standard path is /etc/tuxbox/config/. On some images (OpenPLi new versions, VTI) configs have moved to /etc/tuxbox/config/oscam/ or /var/tuxbox/config/. The exact path: execute find /etc /var -name "oscam.conf" 2>/dev/null — it will show where it actually lies.
What port should the client use to connect to the iCam server?
The port from the section [cccam] in oscam.conf, parameter port. By default 12000. This port must be open in iptables/ufw and forwarded on the router (NAT → your receiver). Check: telnet yourip 12000 — if it connects, everything is ok.
Why does iCam show 0 cards to the client?
Four main reasons: (1) mismatch group in oscam.user and oscam.server, (2) cccreshare=0 for the account prohibits card sharing, (3) the reader is in CONNECTED status but does not see cards on the server, (4) caid The filter in the account does not include the required CAID. See WebIf → Readers → status of each reader.
How to enable detailed iCam logging for diagnostics?
In oscam.conf in the section [global]: logfile=/var/log/oscam.log and debug=4. For maximum — debug=65535. After diagnostics, be sure to return debug=0 — with full debug, the log grows by several gigabytes per day and can fill up the partition.
Is it possible to run iCam simultaneously with another softcam?
Technically, it can be launched, but they will conflict over the dvbapi socket — only one softcam can work with the DVB stack at the same time. In Enigma2, disable other softcams through Softcam Manager or remove them from /etc/init.d/ autostart. Two active softcams = none work properly.
How to update iCam without losing configuration?
First, backup: tar czf /root/icam_cfg_$(date +%Y%m%d).tar.gz /etc/tuxbox/config/oscam*. Then: stop the service (/etc/init.d/icam stop), replace the binary, start it. Configurations are compatible between minor versions. During a major update — read the CHANGELOG, sometimes the syntax of individual parameters changes.
Practical checklist for smooth viewing
Even the best CCCam or OSCam line needs two or three simple preparations. Update your receiver firmware, reset the ECM cache once a week and keep 15–20% free space on the USB stick or internal flash so that the reader can store keys without delays.
When tuning a dish, aim for MER/BER reserve: a two‑degree offset or a loose F‑connector often causes the “freezing” that users blame on cardsharing. Keep a short patch cord to test alternative routers, and save two profiles in OSCam — one for TCP, one for UDP — so you can switch instantly if your ISP starts filtering a protocol.
Utgard.tv monitors each hub 24/7, but you can speed up diagnostics by keeping a short log of your receiver actions. Note the time when you changed the channel, which CAID was active and whether you used Wi‑Fi or Ethernet. This tiny “journal” helps engineers reproduce your environment in the lab and return with a solution in minutes instead of hours.
- Keep two line slots enabled: if the first server hits a maintenance window, the second one instantly takes over without re-entering credentials.
- Run a monthly speed and latency test. Stable 1–2 Mbps with ping <80 ms is enough for SD/HD, but if jitter exceeds 20 ms, switch the router to wired mode.
- Save the Utgard.tv status page and Telegram bot @utgard_sharing_bot to bookmarks — they publish maintenance notices before SEMrush or uptime monitors raise alerts.