KDM Manager
Issue cinema-ready KDMs in your browser. For filmmakers re-keying their own encrypted DCPs for festivals, distributors, and venues — and for mastering facilities running web-based KDM deliveries. Drop in a DKDM, add a projector cert, get a signed KDM XML. No server in the loop. → Open DCP Inspector
Read this before generating an identity.
  • Keys live in this browser's IndexedDB only. No server, no sync, no backup. Clearing browser data or switching machines wipes the identity.
  • Browser-resident keys are not DCI-compliant for playback (DCI Spec §9.4.3 requires hardware key storage). This is a facility cert for inspection / re-keying, not a playback cert.
  • A malicious browser extension or XSS payload on tools.colorbymosaic.com can call crypto.subtle.decrypt with the non-extractable key. The non-extractable flag stops passive snooping, not active attacks. Don't install untrusted extensions in this browser profile.
  • The inspector decrypts picture and audio essence only for analysis. It never writes decrypted picture or audio essence to disk.

Identity

Generate the trust certificates used by a DCP Author or mastering facility to target this browser/profile on this machine. This is local to this machine only and does not follow the user between browsers or to other computers.

DKDMs

DKDMs for specific CPLs. These are produced by a DCP Author or mastering facility and target this machine's certificates. These also provide DCP Inspector access to decrypt a given DCP.
Loading…

Recipients

Target cinema servers you wish to generate new keys for. Each recipient is one cinema / playback device you can issue KDMs to. Drop .pem / .crt / .cer files anywhere in this section, or paste a cert below.
Loading…

Generate KDM

Generate new KDMs from a DKDM you've been given, targeting specific cinema servers you have certs for. Pick a CPL (from your imported DKDMs), pick a recipient, set the validity window, download a fresh signed KDM to provide to the exhibitor.
Loading…