Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Operations   » Digital Cinema Forum   » Which Certificate To Generate KDM ???

   
Author Topic: Which Certificate To Generate KDM ???
Jim Cassedy
Phenomenal Film Handler

Posts: 1661
From: San Francisco, CA
Registered: Dec 2006


 - posted 08-03-2015 07:34 PM      Profile for Jim Cassedy   Email Jim Cassedy   Send New Private Message       Edit/Delete Post 
I had to replace the dolphin board in a Doremi DCP2000 today.
This also changes the esn on on the server.

This server is not in a regular, commercial theater situation, so I have no
encrypted content to test with, nor does this location have any relationship
with the studios or bookers where I can get them to send me anything.

Using DCP-o-Matic, (which I've used many times before) I've created an
encrypted test file. I've also downloaded the certificates from Doremi for
the new esn in my serverthingy. But there are 6 certificates. Which one(s?)
do I use to generate the KDM in DCP-oh-Matic?

The certificate files look like this:
(Obviously, I've removed the actual server serial #)

File
1) dcp2000-12345-01.cert.mpeg.pem
2) dcp2000-12345-01.chain.mpeg.pem
3) dcp2000-12345-01.cert.sha1.pem
4) dcp2000-12345-01.chain.sha1.pem
5) dcp2000-12345-01.cert.sha256.pem
6 dcp-2000-12345-01.chain.sha256.pem

So, which one do I use? (And what's the difference?)

The projector is a Series 1 NEC, but I forget the model number.

I'm going to need to play "real" encrypted content in about a week,
but I want to test before then, and I'm not getting any cooperation
from the film distributors in trying to get some content and KDM's
sent early . So I need to generate my own encrypted content to test.

Non-encrypted and alternate inputstuff is playing fine.

(and, "yes" I've informed Deluxe/Technicolor and the other content
providers we deal with of the change in the server ESN.)

 |  IP: Logged

Carsten Kurz
Film God

Posts: 4340
From: Cologne, NRW, Germany
Registered: Aug 2009


 - posted 08-04-2015 06:34 AM      Profile for Carsten Kurz   Email Carsten Kurz   Send New Private Message       Edit/Delete Post 
You need the *.cert.sha.256.pem file.

BTW - DCP-o-matic has it's own download mechanism for the server certificates from the Doremi FTP, and it selects the right one automatically. Give it a go with the eSN. And no reason to keep these numbers a secret. Create the KDM type 'Modified Transitional 1'

The projector SN and type are irrelevant.

- Carsten

 |  IP: Logged

Dave Macaulay
Film God

Posts: 2321
From: Toronto, Canada
Registered: Apr 2001


 - posted 08-04-2015 07:45 AM      Profile for Dave Macaulay   Email Dave Macaulay   Send New Private Message       Edit/Delete Post 
Call Doremi and they will send you a KDM for the encrypted content "StEM reel 3" pretty quickly. The "reel" is only about 10 seconds long so if you have deleted it, it can be downloaded pretty easily. This CPL is on new servers to test decryption when other content is not available.

 |  IP: Logged

Jim Cassedy
Phenomenal Film Handler

Posts: 1661
From: San Francisco, CA
Registered: Dec 2006


 - posted 08-04-2015 08:37 PM      Profile for Jim Cassedy   Email Jim Cassedy   Send New Private Message       Edit/Delete Post 
Thanks Carsten & Dave.
Actually, since this was keeping me awake last night, I did a lot of
online searching & reading and was able to determine which was the
proper certificate to use for KDM generation.

For some reason the 'automatic' Doremi certificate finder on my version
of DCP-O-Matic couldn't fetch the certificate on it's own, but I have
a feeling that was due to the firewall I was behind.

Dave- I was aware of the STEM file, the server I was working on was several
years old, and had been moved from another location. It was in storage
for about two years, so the CMOS battery had gone dead and then when I
replaced it I had to re-enter all the bios settings, drive ID's & boot
order, etc. Then, I couldn't get the dolphin board & secure clock
function, even with a new battery. ( I think the old one had been dead
for too long)

I was able to get a new dolphin board, and all the latest software
upgrades, and the good news is that the encrypted test DCP's and KDM's I
generated last night worked without any problems when I went in and tried
them this morning. So, problem (apparently) solved!

 |  IP: Logged

Dave Macaulay
Film God

Posts: 2321
From: Toronto, Canada
Registered: Apr 2001


 - posted 08-05-2015 12:09 AM      Profile for Dave Macaulay   Email Dave Macaulay   Send New Private Message       Edit/Delete Post 
The Dolphin card battery going dead is immediately fatal. I think Doremi gives you 5 minutes to replace it after powering off, I have seen a card die when doing that though.
I think Doremi can recover a card that has lost its encryption keys from battery failure.

 |  IP: Logged



All times are Central (GMT -6:00)  
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.