Windows Broadcaster Will Not Connect to ZEN Master (SSH Tunnel / Key Permissions)
What This Covers
A Zixi Broadcaster installed on Windows shows as Pending or offline in ZEN Master even though the Broadcaster itself is running and its web UI (port 4444) is reachable. The cause is that the reverse-SSH tunnel the Broadcaster opens back to ZEN Master fails to start, almost always because of file ownership or permissions on the SSH private key or the .ssh directory used by the Windows service account.
This is specific to Windows. Linux hosts are not affected in the same way.
Symptoms
- In ZEN Master, the Broadcaster never leaves Pending, or it flips to offline shortly after you complete Step 5: Connect the Broadcaster.
- The Broadcaster service is running and the local UI at http://localhost:4444 works.
- The Broadcaster log / Windows Event log shows an SSH error referencing the .ssh path under the service profile, for example:
C:\Windows\System32\config\systemprofile\.ssh\... bad permissions
Permissions for '...id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
Load key "...": bad permissions- The error appears immediately at tunnel start, not after a period of streaming.
Root Cause
The Broadcaster runs as a Windows service under the LocalSystem account. To reach ZEN Master it launches the bundled OpenSSH client (ssh.exe) and opens a reverse tunnel, supplying the private key downloaded from ZEN Master. Because the service uses the LocalSystem profile, SSH looks for its key material under:
C:\Windows\System32\config\systemprofile\.sshModern OpenSSH on Windows 10/11 and Windows Server strictly enforces ownership and ACLs on the private key file and the .ssh directory. If the key file is owned by the wrong account, is readable/writable by groups such as Users or Everyone, or the .ssh directory does not exist or is not writable by the service account, OpenSSH refuses to use the key and aborts. The tunnel never comes up, so ZEN Master never sees the Broadcaster as connected.
Step-by-Step Resolution
Work through these in order. Steps 1–2 resolve the large majority of cases.
1. Pre-create and permission the .ssh directory
Confirm the directory exists and is writable by the account the Broadcaster service runs as (LocalSystem by default):
C:\Windows\System32\config\systemprofile\.sshIf it is missing, create it. Grant the Broadcaster service account (LocalSystem, or the dedicated service account if you changed it) Full Control of this directory, and remove broad inherited permissions for Users / Everyone.
2. Fix the private key file ownership and ACLs
The private key must be owned by the service account and not readable or writable by any group or other user. In an elevated PowerShell, for the key file in that .ssh directory:
icacls "C:\Windows\System32\config\systemprofile\.ssh\<keyfile>" /inheritance:r
icacls "C:\Windows\System32\config\systemprofile\.ssh\<keyfile>" /grant:r "SYSTEM:F"
icacls "C:\Windows\System32\config\systemprofile\.ssh\<keyfile>" /remove "Users" "Authenticated Users" "Everyone"(If the service runs under a named account rather than LocalSystem, grant that account in place of SYSTEM.) Restart the Broadcaster service and recheck status in ZEN Master.
3. Run the install / service with Administrator privileges
If the directory and key cannot be created or re-permissioned, the installer or service may not have had sufficient rights. Reinstall or start the Broadcaster service as Administrator so it can create and lock down the .ssh directory correctly.
4. Verify the Remote Source Port matches ZEN Master
A wrong tunnel port produces the same "offline in ZEN" symptom even when the key is fine. In the Broadcaster UI under Settings → SSH Connections, confirm the Remote Source Port (and Local Destination IP/Port) exactly match the values shown in the Broadcaster's Config instructions in ZEN Master. See SSH Connections and Step 5: Connect the Broadcaster.
5. (Last resort) Swap in the 32-bit ssh.exe
In rare environments where the bundled 64-bit ssh.exe still fails the key check, replacing it with the 32-bit ssh.exe from the Zixi Feeder package (placed in the Broadcaster install directory in place of ssh.exe) has resolved the tunnel for some sites. Treat this as a workaround of last resort and note the change for support.
6. Re-download a fresh SSH key
If the key may be corrupt or mismatched, generate/download a fresh key from ZEN Master (see Step 3: Create an SSH Key), re-apply it in the Broadcaster's SSH Connection, and re-apply the ownership/ACL fix from Step 2.
Decision Tree
- Broadcaster stuck Pending/offline in ZEN but local UI (4444) works? → continue.
- Log references .ssh path / "bad permissions" / "too open"? → YES → key/directory permissions issue → Steps 1–3.
- No permissions error, but still offline? → check Remote Source Port vs ZEN config → Step 4.
- Permissions correct and port correct, still failing? → try 32-bit ssh.exe (Step 5) and/or a fresh key (Step 6).
- Still failing after all of the above? → collect logs and escalate.
Escalation Checklist
Open a Zixi Support ticket and include:
Item | Details / Location |
|---|---|
Broadcaster version and Windows OS/build | Broadcaster UI header; Windows version (10/11 / Server 2016/2019), 32- or 64-bit |
Broadcaster log / Windows Event log excerpt | The SSH error showing the .ssh path and the "bad permissions" / "too open" text |
Service account the Broadcaster runs as | LocalSystem or a named service account |
Current ACLs on the key file and .ssh directory | Output of icacls for both |
Remote Source Port configured vs. ZEN Master Config value | Broadcaster Settings → SSH Connections, and ZEN Master Broadcaster → Config |
Whether 32-bit ssh.exe swap was attempted | Yes/No |