The content decryption context menu is only available in the
(File ->) Content Decryption -> Export Public Server Certificate
will copy both the public leaf certificate (easydcpcreator_.cert.sha256.crt) and the signature chain (easydcpcreator _.chain.sha256.pem) to the selected folder. The signature chain contains the leaf certificate as well as intermediate certificates and the root certificate. You may safely distribute these certificates to content providers who want to issue a Distribution KDM to your easyDCP + installation.
When issuing (D)KDMs with easyDCP KDM Generator+, place only the leaf certificate file (*.crt) into the server certificate’s folder or just drag and drop it into the corresponding input form.
HINT: Every easyDCP Application uses different Server Certificates. KDMs issued for one easyDCP application cannot be used in any other easyDCP application.
In fact, this is the major difference between easyDCP KDM Generator and easyDCP KDM Generator+.
While easyDCP KDM Generator can be used to issue KDMs for DCPs created and encrypted by yourself using easyDCP Creator+, easyDCP KDM Generator+ can also be used to generate KDMs for DCP that have been created by a third party mastering station.
Just like easyDCP Player+, easyDCP KDM Generator+ also allows you to export its own public certificate. Provide this certificate containing your public key to the content owner so they can issue a Distribution KDM (DKDM) to your easyDCP KDM Generator+ installation.
You can load this DKDM into easyDCP KDM Generator+ and generate new KDMs for other recipients from it. The new KDMs time windows have to be completely covered by the DKDMs time window.
Unfortunately we cannot issue licenses that are expiring after a few days. To evaluate the software, free trial versions can be downloaded.
The restrictions of the demo versions are:
Tip: You can also generate DCPs and pay on a project basis with easyDCP Publisher.
With the free demo editions of the easyDCP standalone programs almost all functionalities of the full versions can be tested. However, there are the following restrictions:
From now on, you will receive a discount on your service and support fees if you extend the service during the ongoing service period.
This is how it works: Since 2017-01-01 you receive a COUPON code on your bill for your next purchase of service extension. This voucher reduces your costs for the next service renewal of the same license by 10%.
The COUPON code is valid for the respective license from the issue of the invoice until the day on which your existing service expires. The date of the last validity is displayed in the COUPON.
How to use this voucher code:
NOTE: Your ongoing service must still be valid
You will automatically receive a discount of 10%. The new service is automatically added to the end of the current service period. The invoice now contains a new COUPON code in order to receive a 10% discount for the next renewal.
Hint: You can spare yourself the manual entry of the voucher code by signing up for a subscription, which automatically extends the service in time. You then receive the discount without entering a COPUON code.
With activated service subscription your service will be prolonged automatically for 6 month 30 days before it expires without any notification to do it manually. The prolongation will be charged to your credit card, its details are stored for this use at our acquirer „Heidelpay“. You will receive an order confirmation and invoice for a successful service prolongation as usual.
Service prolongation via service subscription comes automatically with 10% discount.
How to setup a Service Subscription?
Your next automatic prolongation will be shown at „Next Payment“.
A service subscription can be created and removed at any time before a service gets inactive.
What happens if an automatic service prolongation fails?
If payment fails we will keep retrying. After certain fail we will deactivate the service subscription and inform you by email. Your Service Status will be set to manual mode and you will receive the known „Service Notification“.
Reasons for failed payments can be expired validity, insufficient covering of payment amount or general deactivation of your credit card. If possible we will inform you about reason of rejection.
How safe are your Credit Card details?
Your CC details are exclusively stored on servers of our acquierer. These servers are regularly monitored by the CC-companies.
The generation of personalized signer certificates for certain easyDCP applications is a free service provided by Fraunhofer IIS.
New personalized signer certificates will be issued with every License & Certificate Request during new installation of after migration of the software.
Requirements to get personalized signer certificates issued by Fraunhofer IIS are:
- The email-domain used for your web-account at http://www.easyDCP.com and the requested domain within the License & Certificate Set-request must match.
- Requested domain for validation is not a public address like e. g. gmail.com, t-online.de etc. Blacklist is supported.
If a comprehensible reason exist that email domain and requested domain cannot match please contact email@example.com
easyDCP Creator+ generates a proprietary DCP digest file along with each encrypted DCP.
This digest file contains all track files keys used for the encryption during the DCP creation process. Whenever one wants to generate KDMs, you can load this digest file into a separate tool called easyDCP KDM Generator.
easyDCP KDM Generator is included in each purchase of easyDCP Creator+.
All you need to do is collect your recipient´s public server certificates and put them into a local folder. Use only the "cert.sha256" files. Usually, they have either a *.crt or *.pem suffix.
In easyDCP KDM Generator, you merely need to load the digest file, point to the folder with the server certificates and specify the start and end dates of the KDMs validity period.
Upon clicking the "Generate" button, easyDCP KDM Generator will create KDMs for all server certificates in a single batch job. Please note, that a digest file may contain multiple compositions, but a KDM only ever contains keys for a single composition. Thus, easyDCP KDM Generator will create x KDMs.
For more details, please refer to the http://www.easydcp.com/sync/manuals/easyDCP_KDM_Generator_User_Manual.pdf.
One easyDCP software license can be installed only on one computer system.
However, if you need to move the easyDCP license to another computer or operating system you can do this easily using Migration function in the web shop:
easyDCP Resolve Plug-In customers can get additional important informations for migration here.
After the migration is complete you can generate a new license for the new ware system. Please refer to the following FAQ on how to activate your product.
Migration with older Versions: For version easyDCP Creator(+)2.1.X and older, easyDCP Player(+)1.9.X and older, and easyDCP KDM Generator(+)1.47 and older, be prepared to use the new hashcode of your target hardware/software.
Different versions of easyDCP can be installed side-by-side
However be aware that the all share the same user application data folder, where state settings, KDMs, server and signer certificate and license are stored.
easyDCP 3.6.0 and above will be activated within the application/preferences.
Please watch our video tutorial or proceed as follows:
Note: This way of activating your easyDCP Product is only available from easyDCP Version 3.6 or higher.
easyDCP Creator+ is bundled with a tool called easyDCP KDM Generator. A demo version of easyDCP KDM Generator is included in the easyDCP Creator+ trial version.
easyDCP KDM Generator generates Interop- and SMPTE-compliant KDM files for DCPs created with easyDCP Creator+.
easyDCP KDM Generator has a separate manual that explains the procedure in more detail.
A full commercial version of easyDCP KDM Generator is part of the easyDCP Creator+ product.
Please note: easyDCP KDM Generator is not upgradable to easyDCP KDM Generator+
Customers who own an easyDCP standalone license for easyDCP can receive and use a legacy licenses for previous easyDCP releases free-of-charge on the same hardware.
You will find the option "Other releases" in your license status.
You can find more information on how you can activate your Application in our FAQs: How do I activate my easyDCP Product?
DKDMs are used for the exchange of encrypted DCPs between postproduction houses. Processing DKDMs needs the same operation and security requirements that are used in the creation and operation of KDMs for the digital cinema.
easyDCP Creator+ enables to encrypt digital cinema content and the standard accessory easyDCP KDM Generator generates KDMs and DKDMs for the transfer of digital cinema content to postproduction houses or cinemas.
For further information please refer to:
For automatic generating and distribution of KDMs the online service KDM Studio is available at www.dcptools.com.
KDM Studio is developed by the DCPtools Team based on easyDCP KDM Gnerator+.
A Distribution KDM (DKDM) is technically identical to a regular KDM.
The difference is that it targets another mastering station instead of a cinema server.
You can generate a DKDM with easyDCP KDM Generator. The procedure is identical to generating a regular KDM.
The other way around is also possible with easyDCP. Your distributor can generate a DKDM to your easyDCP Player+ or easyDCP Creator+ public certificate (they each have theire own certificate). easyDCP Player+ or easyDCP Creator+ are then able to open the encrypted DCP.
Starting with version easyDCP Player+ 1.3 the DCP can be exported and loaded into easyDCP Creator.
This is explained in the section: I have an existing DCP. Is there a way to import the DCP into easyDCP Creator?".
Please check also: I have an existing DCP. Is there a way to import the DCP into easyDCP Suite?
How to generate KDMs and DKDMs in easyDCP:
There can be many reasons that subtitles cannot be displayed.
easyDCP Player performs a whole range of checks when it loads the subtiteles.
It will automatically verify that the XML document´s structure meets the specifications and it will also make sure that all characters used in the subtitle document are actually present in the enclosed font file. (Font)
If any potential issues were identified, they will be shown in the log window.
In short, make sure no warnings are raised when the DCP is opened by eayDCP Player.
This page contains:
In order to run properly, each installation of easyDCP KDM Generator+ needs three different sets of files issued separately for each installation:
During the activation process all of those files are generated using appropriate functions in the easyDCP web shop at http://www.easyDCP.com. Licenses and Server Certificates are bound to the particular hardware easyDCP KDM Generator+ is running on. Signer certificates are not tied to the hardware.
Important: If some hardware components in the production machine are changed or the machine stops operating at all, the license and server certificates will not work anymore. Using the migration function in the easyDCP web shop, a license can be ported to another machine. However, a server certificate cannot be used on another hardware. Likewise, it is not possible to re-use the certificates if certain hardware components get replaced on the system. And once the server certificates cannot be used anymore.
ALL (D)KDMs ISSUED FOR THESE SERVER CERTIFICATES ARE LOST AND CANNOT BE RECOVERED.
We recommend our easyDCP KDM Generator+ customers to set-up a second computer serving as backup machine for their (D)KDMs. If used properly, existing (D)KDMs can be recovered and ported to a fresh installation, in case the production machine is not working anymore. The set-up is simple and your existing (D)KDM workflow requires only small changes.
NOTE: You can use your existing easyDCP KDM Generator+ instance to issue backup-(D)KDMs of your existing (D)KDMs for your new backup easyDCP KDM Generator+ instance. This is a one-time-only job and should be performed as soon as possible.
This chapter gives an overview over the recommended workflow when using two instances of easyDCP KDM Generator+ in parallel.
Figure 1 shows a block diagram comprising two activated instances of the software, both identified by their Server Certificate. As mentioned above, the Server Certificate is bound to a specific hardware and installation of the operating system and cannot be used on another installation.
Figure 1: Two activated instances of easyDCP KDM Generator+ running on different hardware
Figure 2 shows one of the common applications using easyDCP KDM Generator+. Here, the Main Unit (MU) receives certain input data:
Figure 2: Standard KDM generation process using one installation of easyDCP KDM Generator+
As result easyDCP KDM Generator+ generates a batch of KDMs for the selected Cinema Servers (step 3).
Based on the workflow described above, we recommend generating a Backup DKDM for the Backup Unit (BU) shown in Figure 1 whenever a new key is used as input format (step 1). Basically, the processing-steps are identical to the description given in 4.1, but instead of only ingesting certificates from the Cinema Servers we also point our Main Unit of easyDCP KDM Generator+ to the Server Certificate of our Backup Unit (Figure 3, step 2). By doing this, easyDCP KDM Generator+ issues a Backup DKDM that can be read from the Backup Unit later. In case the MU is not available anymore, the Backup KDM can be used to recover the original keys that were used to encrypt the DCP.
Figure 3: KDM Generation Process using the Backup Unit (BU)
In case of a hardware crash or when the system components used to assemble the Main Unit’s system hash change, it is possible that the Server Certificates of the Main Unit cannot be accessed anymore. In this case it is possible to move the main unit onto a new hardware or issue a new set of license and certificates for the new configuration of the main unit. In any case, the previous Main Unit’s Server Certificates must be replaced. Through the easyDCP-web shop it is possible to get new licenses and certificates on the fly. Indeed, none of the old (D)KDMs of the former Main Unit (MU) will work with the new installation, called New Main Unit (NMU) here, since the new Main Unit is identified by a new Server Certificate. In order to get (D)KDMs working on the NMU it is necessary to use the BU as shown in Figure 4. Please note that the BU of KDM Generator+ is used instead of the MU.
Figure 4: Issuing DKDMs for the New Main Unit (NMU) using the Backup Unit (BU)
By ingesting both, all Backup-KDMs (1) as well as the Server Certificate from the New Main Unit (NMU – step 2) new DKDMs for the New Main Unit are generated.
Step 1. Download the easyDCP KDM Generator+ Installer for your target OS from your license status again and install it.
Step 3. www.easydcp.com will offer you: "Activate your complementary license". Select it for activation.
Now your license status shows a new entry called: "easyDCP KDM Generator+ Backup"
Step 4: Download the license and certificate data set and import it into your easyDCP KDM Generator+ Backup system.
NOTE: The complementary license is locked for migration. If you need to migrate your easyDCP KDM Generator+ Backup system please contact us at info@easyDCP.com.
easyDCP applications require different kinds of certificates
Is required to be able to receive KDMs. If a partner wants to send you an encrypted DCP, they will need your public server certificate so that they can issue a DKDM for.
Will be used to digitally sign content of encrypted DCPs or KDMs. Generally, all DCPs should be digitally signed to ensure that they will be ingested without any problems into a digital cinema server. Only for unencryted DCPs with Interop conformity, a signature is optional.
Which easyDCP application needs which certificates?
easyDCP KDM Generator
easyDCP KDM Generator+
easyDCP JPEG2000 Transcoder
How you get your Signer- and Server- certificate?
From easyDCP Player 2.0.X, easyDCP Creator 2.2.X and easyDCP KDM Generator 1.4.15
During „License & Certificate Request“ and activation via webshop www.easydcp.com Signer- and Server Certificates will be provided in "License & Certificate".
What kind of certificate are required, if at all, depends on the easyDCP application.
Older easyDCP versions
Please use license status on www.easydcp.com: New server certificate/manage certificate
How I can access to my previous Signer- and Server Certificates?
Please use license status on www.easydcp.com: Manage certificates
This option is available for customers with valid service extension
Please note: Every "Certificate Request" will be secured with a password specified by you.
You select the password when you fill in the request and will be prompted to enter it again, whey you import the License & Certificate Set and whenever a KDM is accessed.
The password cannot be recovered!
The newest easyDCP KDM Generator version 1.4.15 offers a simple support for TDL (Trusted Device List) for e.g. double projection in KDMs.
If a TDL for KDM is required, you only need to import the corresponding projector Certificates in the field " Trusted Device List" available at easyDCP KDM Generator 1.4.15 "Advanced Settings".
easyDCP introduces a new and important function with easyDCP+ Version 3.4: easyDCP DCP/IMF-Package Validator
The function is integrated in easyDCP Creator+ and easyDCP Player+. Validation can be performed on encrypted and unencrypted files.
The easyDCP validation check includes:
- Syntax checks of the metadata
- Compliance check of image and sound files
- Review the current and desired DCP / IMF-Package naming convention
For immediate diagnosis, the easyDCP Validation Report provides a traffic light view with OK, warnings and "red" for errors.
The easyDCP Validation Report also includes a detailed evaluation. It consists of an HTML file, which can also be opened offline with any browser.
This file provides detailed information on the results of the validation and, if applicable, specific notes on the occurrence of warnings and errors.
A sample of DCP validation can be found here:
To perform a validation:
easyDCP Validation Report as proof of quality:
Fraunhofer IIS provided the essential prerequisite for the DCI Compliance Test Plan. With the new easyDCP Validator you get the perfect tool to run the test plan fully automatically. The conclusive easyDCP Validation Report can be attached to DCP delivery or IMF package delivery as a quality and compliance proof.
easyDCP Validation verifies the following conformities:
as well as other "Common Practice Tests" which have resulted from years of experience. E.g. Digital Cinema Naming Convention, checks of subtitles outside of the area that can be read by the creator.
Sales support: All questions regarding the products and their features. For example:
Prices for new products
How to purchase
How to update from previous versions, s.o.
Sales support is available for everyone. Please contact: firstname.lastname@example.org
License support: Questions about activation, migration, available updates and upgrades as well as the status of licenses.
License support is available for every customer independent from the service status. Contact: email@example.com
Technical support: Usage and troubleshooting for all easyDCP solutions
Technical support requires a valid service contract for the respective easyDCP software. Please use "Technical Support" option within your web account.
How to manage ...
Service and service extensions:
Each new purchased easyDCP product comes with a valid service contract lasting for 6 months. Within this period, technical service as well as updates for the respective products are included without any payment.
Once the service is about to expire, customers will be notified by e-mail. It is highly recommended to extends the service extension from minimum of 6 months and will always be appended to the end of the current service-period. If the customer decides for a service subscription the service extendes for another 6 month automatically if the customer has not completed the subscription at the latest 30 days before the end of the last renewal.
In case a customer decided not to prolong the support and no new version of specific software has been released, it is still possible to get back into normal service. Here a service fee of 50% (calculated form the regular service fee) for the period between previous service and the date the client wants to get back into support has to be paid.
If a new version of specific software has been released during a non-supported period, no prolongation of the (expired) service is possible anymore. New: Here clients have to purchase a onetime fee in order to get the latest version of the easyDCP software. The update price depends on the date when the previous service extension has ended and the date the client purchased the update for his respective easyDCP application. The younger the last license the lower the update fee. Updates comes without automatic prolongation of service extension.
Migrating your software to a new hardware or re-activating a license after changing components in your existing hardware is always possible. For further details please check: How can I perform a migration (hardware/operating-system-change)
Major an Minor Updates (eg. Version X.3.X > X.4.X):
Updates will arrive as needed. Estimate between 2 to 6 updates per year.
Customers with valid service (check status in your web account) have free access to updated versions of the software. There is no automatic update procedure and manual integration is required. If the update is a so-called point-release (e.g. 3.2 to 3.3) or a major release (e.g. 3.9 to 4.0) a new license is required. Minor releases (3.3.1 to 3.3.2) do not require a new license. Usually, only a new license for specific easyDCP software must be downloaded and activated. There is no need to update the certificates (signer and /or server) for a software update. Please use the "Request License & Certificate Set" as well as the "Import License & Certificate Set" options within easyDCP since they take care about proper activation of specific software. For your support please check: How do I activate my easyDCP product
Customer without valid service are requested to purchase an update. New: The update price depends on the date when the previous service extension has ended and the date the client purchased the update for his respective easyDCP application. The younger the last license the lower the update fee. Updates comes without automatic prolongation of service extension. Usually, only a new license for specific easyDCP software must be downloaded and activated. There is no need to update the certificates (signer and/or server) for a software update. Please use the "Request License & Certificate Set" as well as the "Import License & Certificate Set" options within easyDCP since they take care about proper activation of specific software. For your support please check: How do I activate my easyDCP product
Upgrade (e.g. easyDCP Creator to easyDCP Creator+):
The upgrade price is calculated using the difference between the existing product and the new product. No additional upgrade-fee is charged. The option "Upgrade" within your web account shows the available and the most cost-effective options for an upgrade.
Upgrades requires up to date of the upgrade provided software and valid service contract. If a service period expired or the initial version is somehow outdated, clients have to renew the service before upgrading. Please see the comments above explaining how to prolong an expired service.
Bonus licenses are available under certain conditions. Actually bonus licenses for easyDCP Resolve Plugin and easyDCP SAM Rio Plugin will be issued when the following prerequisites are met: easyDCP Bonus licenses for DaVinci Resolve 10/11/12 or easyDCP Bonus licenses for SAM Rio
If your question has not been answered please do not hesitate to send us an e-mail: firstname.lastname@example.org
You can download the manual here.
The procedure is different in every country. We can't send you the certificates.
Usually, on the cinema server manufacturers' FTP servers you can find both the public server certificates and the signature chain that were used to sign the certificates.
If you decide to trust the certificate by examining the signature chain, you only need the server certificate to create a KDM. The server certificate usually has either a *.pem or a *.crt suffix.
easyDCP KDM Generator will accept either, but do not use both.
Furthermore, there may be pairs of certificate and chain that state "mpeg", "sha1" and "sha256".
Like with DCPs, there are SMPTE ("sha256") and Interop ("sha1" / "mpeg") KDMs.
Almost all modern cinema servers prefer SMPTE KDMs - even for Interop DCPs. So mostly the "sha256" version is used.
Only if you surely know your recipient only accepts Interop KDMs, use the "sha1" certificate and remember to check the "Enable Interop mode" option in the easyDCP KDM Generator's options tab.
Please see also: Where can I get the server certificates needed to create the KDMs?