
If you have already set up OScam with a CCcam or Newcamd reader and are now trying to add an iCAM source — you have probably already encountered the issue that the config simply does not acceptprotocol = icam or the reader hangs in RECONNECT state. The problem is not in the parameters — in most cases, the problem is deeper: the binary is compiled without support for this protocol. Let's break down the icam oscam setup step by step, from checking the build to working channels on the receiver.
What is iCAM and why is it in OScam
iCAM is a closed protocol for exchanging ECM requests that appeared in the ecosystem of ICE servers and several forks of cardsharing software. Unlike CCcam or Newcamd, it is not publicly documented and its implementation in OScam is based on reverse engineering of the protocol.
Origin of the iCAM protocol
The protocol was developed by the ICE team as an alternative to CCcam with an emphasis on session encryption and a non-standard packet format. It made its way into the original OScam as one of the supported reader modules — but not as a client protocol, rather as a type of reader for connecting to an iCAM server.
ModuleREADER_ICAM is not included in most ready-made binaries that are distributed online. This is the first trap: you are looking for the parameter in the config, but it is simply unavailable in your build.
Differences between iCAM and CCcam, Newcamd, and CS378x
CCcam uses session encryption based on SHA1 + xor with a fixed packet format. Newcamd works with 3DES encryption and is widely supported in any cardsharing software. CS378x is a Cardsharing 3.78x protocol with its own structure.
iCAM differs in several ways. Firstly, the packet length is not fixed — the server uses its own agreement on formatting ECM requests. Secondly, the session encryption is different: keys are negotiated in the handshake, not transmitted statically. Thirdly, the server can check the client's timestamp — some implementations reject connections if there is a discrepancy of more than 60 seconds.
In practice: if you have a working CCcam account and the option to choose — stick with CCcam. iCAM is only needed if the server exclusively provides this type of connection.
When iCAM is really needed, and when CCcam is enough
iCAM makes sense in two cases: the server accepts only iCAM connections, or you are building your own infrastructure on the ICE fork and want to use its native protocol. In other cases, CCcam or CS378x is a more reliable choice with better compatibility.
If the server has the option to connect via CCcam — go for CCcam. iCAM requires rebuilding the binary, additional debugging, and has a smaller community for troubleshooting.
Checking iCAM support in your OScam build
Before touchingoscam.server, make sure that your binary can actually work with the icam oscam pair. This takes 10 seconds and saves hours of debugging.
The command oscam -V and flag decoding
Run:
oscam -V 2>&1 | grep -i icam
If the output contains a line likeREADER_ICAM — support is present. If the line is empty — the binary is compiled without this module. The full outputoscam -V shows all compiled modules, approximately like this:
oscam -V 2>&1 | head -50
# Ищем строки вида:
# Version: 11.7.201
# Compiled: WITH_LB, WITH_WEBIF, READER_NAGRA, READER_VIACCESS, READER_ICAM...
IfREADER_ICAM the list is missing — read the next section about recompilation.
Which modules should be compiled (WITH_LB, READER_ICAM)
For the normal operation of icam oscam configurations, at least three modules are needed:
READER_ICAM— the protocol itself, without it nothing worksWITH_LB— load balancer, needed for prioritizing readersWITH_WEBIF— web interface for monitoring (technically optional, but debugging is more difficult without it)
If you are usingREADER_VIACCESS or other card modules in parallel with iCAM — they must also be present.
Recompilation of OScam with iCAM support from source
Standard procedure on Debian/Ubuntu:
# Зависимости
apt-get install build-essential libssl-dev libpcsclite-dev git
# Клонируем исходники
git clone https://github.com/oscam-emu/oscam-emu.git
cd oscam-emu
# Настройка флагов сборки
./config.sh --enable READER_ICAM WITH_LB WITH_WEBIF WITH_EMU
# Или редактируем config.h вручную, раскомментируем #define READER_ICAM
make -j$(nproc)
# Бинарник появится в ./Distribution/oscam-*
# Заменяем существующий
cp Distribution/oscam-11.7.* /usr/local/bin/oscam
chmod +x /usr/local/bin/oscam
If you are working on Enigma2 / OpenATV — a cross-compiler for ARM is needed. This is a separate story, but the principle is the same: the flag--enable READER_ICAM in config.sh.
Look for OScam configs in/usr/local/etc/,/etc/tuxbox/config/oscam/, or/etc/oscam/ — depends on the distribution and installation method.
Setting up the iCAM reader in oscam.server
Fileoscam.server — the place where all content key sources are described. Each section[reader] — one reader. For icam oscam, the section looks different than for CCcam, and each parameter has significance.
Structure of the [reader] section for iCAM
Basic template:
[reader]
label = icam_main
protocol = icam
device = your.server.host,13000
user = yourlogin
password = yourpassword
group = 1
caid = 0500
ident = 0500:032830,0500:023800
inactivitytimeout = 120
reconnecttimeout = 30
lb_weight = 100
lb_priority = 1
logport = 0
Let's break down each line — because most guides do not do this.
Mandatory parameters: protocol, device, user, password
protocol = icam — tells OScam to use the iCAM module for this reader. Without this parameter, OScam will try to determine the protocol automatically and will most likely be wrong.
device = host,port — the address and port of the server. The port is written with a comma, not a colon. For example:device = 192.168.1.100,12900 ordevice = icam.example.com,13000. The iCAM does not have a standard port — the provider sets it themselves, usually in the range of 12000–15000.
user / password — credentials provided by the provider. Case-sensitive.
Group parameters, caid, ident, ECM cache
group = 1 — reader group. Clients inoscam.user with the same group number will gain access to this reader. If you have multiple readers (iCAM + CCcam) — use different groups.
caid = 0500 — CAID of the encoding system. 0500 is Viaccess. If your package uses Irdeto (0604) or Nagravision (1801) — change accordingly. Incorrect CAID = the reader will ignore all ECM requests from channels.
ident = 0500:032830 — specifies which specific providers within the CAID this reader services. Multiple separated by commas. If you don't know the ident — for the time being, you can remove the parameter, OScam will try all.
inactivitytimeout = 120 — how many seconds to wait for silence before reconnecting. If the channel is unstable, reduce to 60. For NAT — on the contrary, increase to 300 and set keepalive on the router.
reconnecttimeout = 30 — pause between reconnection attempts. 30 seconds is normal. Less than 10 makes no sense, the server will perceive it as flooding.
Example of a working config with comments
[reader]
label = icam_viaccess # произвольное имя, видно в логах
protocol = icam
device = 203.0.113.10,12950 # IP:порт сервера
user = client42
password = s3cur3pass
group = 1
caid = 0500 # Viaccess 3.x
ident = 0500:032830,0500:023800
inactivitytimeout = 180
reconnecttimeout = 30
lb_weight = 100 # приоритет в loadbalancer
lb_priority = 1 # меньше = выше приоритет
logport = 0
rsakey = # пустой — используется стандартный handshake
audisabled = 1 # AU через iCAM обычно не работает
If you need two iCAM readers (backup), add a second section withlabel = icam_backup,group = 2,lb_priority = 2. OScam will use the backup if the primary is unavailable.
Binding the iCAM reader to clients through oscam.user
The reader inoscam.server by itself does nothing — it needs to be linked to client accounts through groups.
Parameters group and au in oscam.user
[account]
user = myboxclient
pwd = boxpassword
group = 1 # должен совпадать с group ридера
au = 1 # автоматическое обновление (если сервер поддерживает)
caid = 0500 # ограничить только этим CAID
ident = 0500:032830
uniq = 3 # макс. одновременных подключений
sleep = 0
monlevel = 0
group = 1 inoscam.user means: this client will gain access to readers from group 1. If the reader is in group 2, and the client is in group 1 — there is no connection, the channel will not open.
Limiting caid/ident for a specific user
If you have multiple readers with different CAIDs — throughcaid andident inoscam.user you can strictly limit what the client can decrypt. This is useful when you have, say, iCAM with Viaccess (0500) and a separate card with Nagravision (1801) — you give different clients access to different readers.
Configuring services via oscam.services
File/etc/oscam/oscam.services or/usr/local/etc/oscam.services allows you to create named channel sets:
[viaccess_pack]
caid = 0500
ident = 0500:032830
srvid = 0001,0002,0003
Inoscam.user you addservices = viaccess_pack — and the client sees only the channels from this set. This is relevant if one iCAM account covers several packages, and you want to distribute different subscriptions to different clients.
Debugging iCAM connection: logs and common errors
OScam writes detailed logs — the problem is that without understanding what is written there, they look like a mess. Let's break down specific scenarios.
Enabling debug log: oscam -d 255 and logging levels
The standard launch of OScam writes a minimum. For debugging:
# Максимальный debug в файл
oscam -d 65535 -l /var/log/oscam_debug.log
# Или только нужные категории (255 = всё про ридеры)
oscam -d 255
# Наблюдать в реальном времени
tail -f /var/log/oscam.log | grep -i icam
Levels: 1 = errors, 2 = warnings, 4 = info, 8 = ECM detail, 16 = readers.-d 255 includes all levels at once.
Reading oscam.log: what CONNECTED, ECM timeout, no matching reader means
Several typical lines and what they mean:
# Успешное подключение:
2026/05/27 12:14:33 r icam_main [ICAM] CONNECTED to 203.0.113.10:12950
# Ридер не нашёл подходящего запроса:
2026/05/27 12:14:45 c myboxclient (0500&032830:1234) no matching reader
# Таймаут ECM:
2026/05/27 12:15:01 r icam_main [ICAM] ECM timeout after 4000ms
# Успешная расшифровка:
2026/05/27 12:15:03 c myboxclient (0500&032830:1234) found (ecm time 342ms) by icam_main
no matching reader — this is not a reader problem, it is a routing problem. OScam did not find a reader that serves this CAID/ident/group. Check the group in both files.
Error 'icam: login failed' — causes and fix
Three main reasons:
- Incorrect login or password — trivial, but it happens. Passwords are case-sensitive, spaces at the end of the line break authorization.
- IP not in the server whitelist — many iCAM servers accept connections only from registered IPs. If you have a dynamic IP or CGNAT — the server will reject the connection. Update your IP with the provider.
- Discrepancy in system time — some iCAM implementations check the timestamp. If the receiver's clock deviates by more than 60–120 seconds from the server — you will get login failed. Fix:
ntpdate pool.ntp.orgor configure an NTP client.
Error 'no ECM response' with correct login
The reader connected (CONNECTED in the log), but channels do not open and there are no ECM responses. Usually, this means that the reader accepts the request but cannot process it — most often due to a CAID/ident mismatch.
Check: inoscam.server the reader caid = 0500, but what CAID is the channel you are opening? Enable-d 255 and look for lines with ECM request. The CAID of the channel will be visible there.
Problem with CAID/ident mismatch
Inoscam.server the parameterident — is a filter. If you specified0500:032830, but your channel is encrypted with ident0500:023800 — the reader will ignore the ECM. The solution is simple: add a second ident separated by a comma or temporarily remove the ident parameter altogether for testing.
# Расширенный ident:
ident = 0500:032830,0500:023800,0500:040810
# Или без фильтра (для тестирования):
# ident = (закомментировать строку)
Integration of iCAM with DVB card and emulators
The real benefit of icam oscam settings is revealed when the iCAM reader works in conjunction with a local smart card through a load balancer.
Combination of iCAM reader + local card through load balancer
Inoscam.conf the section[lb]:
[lb]
lb_mode = 1 # 1 = выбирает лучший ридер по времени ответа
lb_save = 100 # сохранять статистику каждые 100 ECM
lb_nbest_readers = 2 # пробовать 2 лучших ридера
lb_min_ecmcount = 5 # минимум 5 ECM для статистики
lb_max_ecmcount = 500
lb_reopen_seconds = 300 # пробовать неудачный ридер каждые 300с
Withlb_mode = 1 OScam will automatically select the reader with the shorter response time — iCAM or local card. No manual configuration is needed.
Reader priorities: lb_weight and lb_priority
If you want to forcibly prefer the local card over the iCAM server:
# Локальная карта:
[reader]
label = local_card
...
lb_weight = 200 # выше вес = выше приоритет при равном времени
lb_priority = 1
# iCAM-ридер:
[reader]
label = icam_main
...
lb_weight = 100
lb_priority = 2
lb_priority works differently than it seems: a smaller number = higher priority.lb_weight used by the loadbalancer when response times are the same — a reader with a weight of 200 will be selected more often.
Failover: what will happen if the iCAM server fails
Whenlb_mode = 1 OScam automatically switches to the next available reader when the primary stops responding. The switching time depends oninactivitytimeout +reconnecttimeout. With values of 120 + 30 — a maximum of 2–3 minutes until switching to the backup reader.
One nuance: if you have iCAM and a local card servicing the same CAID 0500 — OScam may periodically try both in parallel, which creates extra load. Uselb_nber_best_readers = 1 for a strict selection of only one reader.
Using iCAM with Enigma2/OpenATV via CCcam client
A common situation: the receiver under Enigma2 only supports the CCcam protocol, and you have an iCAM account. The solution is OScam on the same receiver or on a separate server in the network.
OScam acts as an intermediary: it accepts a CCcam connection from Enigma2 ([cs378x] or[newcamd] section inoscam.conf), and connects to the iCAM server as a reader. Enigma2 does not know that iCAM is behind it.
# В oscam.conf:
[cs378x]
port = 12000
# Enigma2 подключается на 127.0.0.1:12000 через CCcam
# OScam получает ECM → отправляет на iCAM-ридер → возвращает CW
The OScam web interface is available on port 8888 by default:http://192.168.1.X:8888. There, the statistics of readers are visible in real time.
Security and performance of iCAM in OScam
Open port 8888 and lack of connection restrictions — standard configuration for 80% of installations (no, this is not statistics — just my experience supporting such servers). This is bad.
Access restriction: nodeid, allowed_ports, iptables rules
Inoscam.conf the section[webif]:
[webif]
httpport = 8888
httpuser = admin
httppwd = strongpassword123
httpallowed = 127.0.0.1,192.168.0.0/24
httpdyndns = 0
httprefresh = 10
httpallowed — a list of IPs or subnets with access to WebIF. Without this parameter, WebIF is accessible from anywhere.
Additionally via iptables:
# Разрешить WebIF только из локальной сети
iptables -A INPUT -p tcp --dport 8888 -s 192.168.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8888 -j DROP
# Порт iCAM-клиентов (если принимаете входящие):
iptables -A INPUT -p tcp --dport 12000 -j ACCEPT
Protection against freeze: cacheex and anti-cascading
Anti-cascading — protection against reselling: one account should not serve hundreds of clients. Inoscam.user:
[account]
user = client1
...
uniq = 3 # макс. 3 одновременных соединения с одного аккаунта
Inoscam.conf globally:
[anticasc]
enabled = 1
numusers = 1 # разрешённых пользователей на аккаунт
stime = 10 # окно подсчёта (минуты)
denysamples = 10 # запросов до блокировки
CacheEx — mode of exchanging CW between multiple OScam servers, reduces the load on the iCAM reader with a high number of requests. Configured viacacheex = 1 in the [reader] section and requires separate peer configuration. Relevant only for servers with 20+ clients.
Monitoring via WebIF and MQTT
WebIF on port 8888 shows in real-time:
- Status of each reader (CONNECTED / RECONNECT / FAIL)
- ECM OK / ECM NOK for each reader
- Average response time (should be< 800ms for normal viewing)
- List of connected clients
If ECM OK = 0 after 5 minutes of operation — the reader is connected but not processing requests. Check the logs with-d 255.
OScam supports outputting statistics via MQTT starting from some builds — useful if you have a Grafana/Prometheus stack. But for home use, WebIF is quite sufficient.
How does iCAM differ from the regular CCcam protocol in OScam?
CCcam — an open protocol with a known packet structure, supported almost everywhere. iCAM uses a closed scheme for exchanging ECM with its own session encryption. CCcam works in any OScam build, iCAM requires explicit compilation with the READER_ICAM flag. In practice, the icam oscam combination is more complex to configure and debug.
Why is there no option protocol = icam in my oscam.server?
Your OScam build is compiled without READER_ICAM. Check:oscam -V 2>&1 | grep -i icam. If empty — a rebuild from source is needed via./config.sh --enable READER_ICAM andmake.
What port does iCAM use by default?
There is no standard port. The port is set by the server provider — usually something in the range of 12000–15000. In the config, it is written asdevice = hostname,port. The exact port must be in the connection data from the provider.
iCAM reader shows CONNECTED, but channels do not open — what to do?
The first thing is to check that CAID and ident in oscam.server match the CAID of the channel. The second is to ensure that the reader's group matches the client's group in oscam.user. Enableoscam -d 255 and look for lines with ECM request in the log — it will show whether the request is reaching the reader and what happens next.
Is it possible to use iCAM simultaneously with a CCcam reader?
Yes, no problem. OScam supports multiple readers with different protocols simultaneously. The distribution among them is configured through the load balancer:lb_mode = 1 in oscam.conf, priorities throughlb_priority andlb_weight in each [reader] section.
How to check that iCAM is really working and not just connected?
Open the OScam WebIF athttp://server_address:8888 and check the reader statistics. If ECM OK is greater than zero and the average response time is less than 800ms — the reader is actually processing requests. Also, inoscam.log look for linesfound by icam_main — each such line indicates a successful decryption.
Why does iCAM periodically disconnect with a timeout error?
Three main reasons: unstable internet connection to the server, too short inactivity timeout, or NAT on the router is breaking long-lived TCP connections. Try increasingreconnecttimeout = 30 andinactivitytimeout = 300. Check the ping to the server — if the loss is more than 2–3%, the problem is in the channel. With NAT, configure TCP keepalive on the router or reduce inactivity timeout below the provider's NAT timeout.
Practical checklist for smooth viewing
Even the best CCCam or OSCam line needs two or three simple preparations. Update your receiver firmware, reset the ECM cache once a week and keep 15–20% free space on the USB stick or internal flash so that the reader can store keys without delays.
When tuning a dish, aim for MER/BER reserve: a two‑degree offset or a loose F‑connector often causes the “freezing” that users blame on cardsharing. Keep a short patch cord to test alternative routers, and save two profiles in OSCam — one for TCP, one for UDP — so you can switch instantly if your ISP starts filtering a protocol.
Utgard.tv monitors each hub 24/7, but you can speed up diagnostics by keeping a short log of your receiver actions. Note the time when you changed the channel, which CAID was active and whether you used Wi‑Fi or Ethernet. This tiny “journal” helps engineers reproduce your environment in the lab and return with a solution in minutes instead of hours.
- Keep two line slots enabled: if the first server hits a maintenance window, the second one instantly takes over without re-entering credentials.
- Run a monthly speed and latency test. Stable 1–2 Mbps with ping <80 ms is enough for SD/HD, but if jitter exceeds 20 ms, switch the router to wired mode.
- Save the Utgard.tv status page and Telegram bot @utgard_sharing_bot to bookmarks — they publish maintenance notices before SEMrush or uptime monitors raise alerts.