DaCaPo

KDMs and Encryption

Create a KDM

A KDM, or Key Delivery Message, allows a cinema server or projector to decrypt an encrypted DCP during a defined validity period.

This guide explains how to open the KDM / DKDM Creator, set the validity period, select the DCP key and recipient certificate, and generate one or more KDM files in DaCaPo.

What you’ll learn

  • What a KDM is used for.
  • How to open the KDM / DKDM Creator.
  • How to define the validity period.
  • How to select the encrypted DCP key.
  • How to load the cinema server or projector certificate.
  • How to generate KDMs for one or several certificates.

What is a KDM?

A KDM, or Key Delivery Message, allows a cinema server or projector to decrypt an encrypted DCP.

The KDM is valid only between its configured Start Time and End Time.

A KDM does not contain the DCP itself. It is used together with the corresponding encrypted DCP.

To provide access to another DCP authoring or mastering system, create a DKDM instead.

Before you begin

You need:

  • An encrypted DCP.
  • A usable decryption key for that DCP.
  • The public certificate for the target server or projector.
  • The required Start Time and End Time.
  • A destination folder for the generated file or files.
Step 1

Open the KDM / DKDM Creator

There are two ways to open the Creator:

  • Choose File > Create KDM / DKDM.
  • Right-click an unlocked encrypted Timeline and choose Create KDM / DKDM.

When opened from a Timeline, DaCaPo automatically uses the decryption key associated with that Timeline.

When opened from the File menu, a compatible key source must be provided manually.

Step 2

Add optional Annotation Text

The optional Annotation Text field can be used to add a descriptive note to the generated KDM.

This field may be left empty.

Step 3

Set the validity period

The Start Time and End Time fields define when the KDM is valid.

The recipient system will only be able to decrypt and play the content during the specified validity period.

Check the date and time carefully before generating the KDM.
Step 4

Select the DCP Key

The DCP Key is the encryption key used to create the KDM.

When the Creator is opened from a Timeline, the key is loaded automatically from the Timeline's encryption slot.

When opened from the File menu, provide a compatible key source manually.

Compatible sources include:

  • .dcpkey
  • DKDM
  • Digest XML
  • Other supported key files
Step 5

Select the Server Certificate

Select the public certificate for the target server or projector.

Supported certificate formats include:

  • PEM
  • CRT
  • DER

Create KDMs for multiple certificates

A folder containing multiple certificates can also be selected.

In that case, DaCaPo generates a separate KDM for each certificate found in the folder.

Step 6

Choose the destination

Select the folder where the generated KDM file or files should be saved.

Step 7

Generate the KDM

Click Generate to create the KDM.

The generated file or files can then be delivered to the recipient system together with the encrypted DCP.

Common problems

No DCP Key is available

Open the Creator from an unlocked encrypted Timeline or provide a compatible key source manually.

The recipient cannot use the KDM

Confirm that the correct server or projector certificate was selected and that the KDM validity period is active.

The KDM is not yet valid

Check the configured Start Time.

The KDM has expired

Create a new KDM with an appropriate End Time.

Manual reference: KDM / DKDM creation; Annotation Text; Validity Period; DCP Key; Server Certificate; Destination; Generate.

Reviewed against: DaCaPo User Manual 0.9.2, July 2026.