DaCaPo

KDMs and Encryption

Create a DKDM

A DKDM, or Distribution Key Delivery Message, allows another DCP authoring or mastering system to decrypt an encrypted DCP during a defined validity period.

This guide explains how to open the KDM / DKDM Creator, set the validity period, select the DCP key and recipient certificate, and generate one or more DKDM files in DaCaPo.

What you’ll learn

  • What a DKDM is used for.
  • The difference between a KDM and DKDM.
  • How to open the KDM / DKDM Creator.
  • How to define the validity period.
  • How to select the encrypted DCP key.
  • How to load the recipient mastering-system certificate.
  • How to generate DKDMs for one or several certificates.

What is a DKDM?

A DKDM, or Distribution Key Delivery Message, allows another DCP authoring or mastering system to decrypt an encrypted DCP.

The DKDM is valid only between its configured Start Time and End Time.

The recipient can use the DKDM to open and work with the encrypted DCP during that validity period.

KDM versus DKDM

Message type Recipient Typical use
KDM Cinema server or projector Exhibition
DKDM DCP authoring or mastering system Post-production and mastering
To authorize a cinema server or projector for exhibition, see Create a KDM.

Before you begin

You need:

  • An encrypted DCP.
  • A usable decryption key for that DCP.
  • The public certificate for the recipient authoring or mastering system.
  • The required Start Time and End Time.
  • A destination folder for the generated file or files.
Step 1

Open the KDM / DKDM Creator

There are two ways to open the Creator:

  • Choose File > Create KDM / DKDM.
  • Right-click an unlocked encrypted Timeline and choose Create KDM / DKDM.

When opened from a Timeline, DaCaPo automatically uses the decryption key associated with that Timeline.

When opened from the File menu, a compatible key source must be provided manually.

Step 2

Add optional Annotation Text

The optional Annotation Text field can be used to add a descriptive note to the generated DKDM.

This field may be left empty.

Step 3

Set the validity period

The Start Time and End Time fields define when the DKDM is valid.

The recipient system will only be able to decrypt the content during the specified validity period.

Confirm the required validity period with the receiving facility before generating the DKDM.
Step 4

Select the DCP Key

The DCP Key is the encryption key used to create the DKDM.

When the Creator is opened from a Timeline, the key is loaded automatically from the Timeline's encryption slot.

When opened from the File menu, provide a compatible key source manually.

Compatible sources include:

  • .dcpkey
  • DKDM
  • Digest XML
  • Other supported key files
Step 5

Select the Server Certificate

Select the public certificate for the target DCP authoring or mastering system.

Supported certificate formats include:

  • PEM
  • CRT
  • DER

Create DKDMs for multiple certificates

A folder containing multiple certificates can also be selected.

In that case, DaCaPo generates a separate DKDM for each certificate found in the folder.

Step 6

Choose the destination

Select the folder where the generated DKDM file or files should be saved.

Step 7

Generate the DKDM

Click Generate to create the DKDM.

The generated file or files can then be delivered to the recipient system together with the encrypted DCP.

Common problems

No DCP Key is available

Open the Creator from an unlocked encrypted Timeline or provide a compatible key source manually.

The recipient cannot use the DKDM

Confirm that the correct authoring or mastering-system certificate was selected and that the DKDM validity period is active.

The DKDM is not yet valid

Check the configured Start Time.

The DKDM has expired

Create a new DKDM with an appropriate End Time.

Manual reference: KDM / DKDM creation; Annotation Text; Validity Period; DCP Key; Server Certificate; Destination; Generate; Preferences – Certificate; Export Public Certificate.

Reviewed against: DaCaPo User Manual 0.9.2, July 2026.