This is topic Which Certificate To Use In DCP-O-Matic? in forum Digital Cinema Forum at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=16;t=002564

Posted by Jim Cassedy (Member # 4115) on 01-29-2016, 08:28 PM:
 
I rarely need to make KDM's, but I've got to generate awholebunch soon.

I've already made a KDM for the theater in question once before, and I have
two certificate files stored on my computer for the auditorium in question.

The file names are:
#1: DCP-2000-XXXYYY-ZZ.chain.sha256.pem
#2: DCP-2000-XXXYYY-ZZ.cert.sha256.pem

I can't remember which one I used last time.
I'm guessing #2 is the one I should use?

I just wanted to check before I get started on the project.

I might have asked this question a long time ago, but I searched
& can't seem to find the post.
 
Posted by Michael Putlack (Member # 6523) on 01-29-2016, 09:58 PM:
 
If you're not sure, can't you just make two keys and have them ingest both?
 
Posted by Carsten Kurz (Member # 5396) on 01-30-2016, 05:38 AM:
 
#2 is sufficient. It contains only the device certificate, not the whole certificate chain.

The chain-file is used by professional software tools to make sure your device/manufacturer is DCI compliant (the certificate chain will allow these tools to follow the certificate chain up to the manufacturer and certification authority)

When you create your own KDMs, the plain device certificate will do.

Note DCP-o-matic will download the necessary certificate for Dolby/Doremi servers when you supply it with E-SN or serial number (from the new combined Dolby-Doremi certificate repository in recent versions).

- Carsten
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2