Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Anything and everything to do with DCP-o-matic.
Post Reply
t9nu
Posts: 4
Joined: Tue Sep 03, 2019 8:58 am

Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by t9nu » Tue Sep 03, 2019 9:33 am

I've been researching so many days but found only one topic that doesn't work.

I try to add a screen while creating a kdm. Every time that I add a certificate this popup message will show.
I found one solution that suggests deleting the lastest certificate data in the pem file and it doesn't work.

this is my certificate data in a pem file. Help please.

-----BEGIN CERTIFICATE-----
MIIEsTCCA5mgAwIBAgIILnE4/7SS550wDQYJKoZIhvcNAQEFBQAwgZIxIzAhBgNV
BAoTGkRDMi5JTlRFUk9QLkRPUkVNSUxBQlMuQ09NMRowGAYDVQQLExFEQy5ET1JF
TUlMQUJTLkNPTTEoMCYGA1UEAxMfLlVTMS5NWEZpLkNJTkVBU1NFVC5EQzIuSU5U
RVJPUDElMCMGA1UELhMcSmtDZVh4Z1ZNcFpReHRvam5IRVVqcUs4THIwPTAeFw0w
NzAxMDEwMDAwMDBaFw0yNTEyMzEyMzU5NTlaMIGeMSMwIQYDVQQKExpEQzIuSU5U
RVJPUC5ET1JFTUlMQUJTLkNPTTEaMBgGA1UECxMRREMuRE9SRU1JTEFCUy5DT00x
NDAyBgNVBAMTK01FIENTIFNNLkNpbmVBc3NldC0xMTkxMjgzNjIuREMuREMyLklO
VEVST1AxJTAjBgNVBC4THFRPTThiR1Y0TGN4bUNEWC9CRVZ3QytHeGlHRT0wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCXRF9l1Axz0dUlljKXPuOV4dr/
DsDMnAdT6DifPNWStviGdOdHJeJ2O4BU1V1d2ef8r52QLzTpWJTiBZAsUAR5tFvL
Dx/x1oXtbRnkUl8rxEQ00TKzXWmprU4aVTFQ96CVf8yHxQXfMtJLjD6tnV3B4ylD
V0p6spRWBgPLC5G/UDKWiW4Vo/s9YA+jUKGjFmDkqKfTYNdopCgR4nHm2znW0CWf
qpCfve0rJlZuqGd+Yfk42+olkL+/sGZHl3t/LCOFm2jYP3TnjKoD0qvtxYOPQYNc
Te/9o+cCZAkyxDwdQVnn6BvghWdsr8iZOc0hX4Nzd8uz94Dx9W497NQzBVtXAgMB
AAGjgfwwgfkwDAYDVR0TAQH/BAIwADALBgNVHQ8EBAMCBLAwHQYDVR0OBBYEFEzj
PGxleC3MZgg1/wRFcAvhsYhhMIG8BgNVHSMEgbQwgbGAFCZAnl8YFTKWUMbaI5xx
FI6ivC69oYGVpIGSMIGPMSMwIQYDVQQKExpEQzIuSU5URVJPUC5ET1JFTUlMQUJT
LkNPTTEaMBgGA1UECxMRREMuRE9SRU1JTEFCUy5DT00xJTAjBgNVBAMTHC5NWEZp
cy5DSU5FQVNTRVQuREMyLklOVEVST1AxJTAjBgNVBC4THDZOcUVrOVU0Z1QrRThl
K1hRVW9kMzh5aElRUT2CAQIwDQYJKoZIhvcNAQEFBQADggEBAFhqZJ09YuZzokxd
r0VQ51K4+RJzojNOeRuxWgkPANo/xyBf4SPaurqwR+VPUinei2hnzjYrYJy9YGjo
9x9naU3NDL9/ACOlyYFFe0m/FHuZqkTNfCJrgJ7G6OOBHGiQB6OYvhIEBUn7yYX+
a7nF23WqhPwFUPYwlkuZAZ7VDVKjQW8egrjSCvu1JNq+1JXJYMQpn0aqMxVzVgb4
bVHbneAE18XX8YR00fD1a1Hyn8YwnaodddDiDns+wBZaR+Y8EfBh7jDXwAOiwm3i
45Wthav1Xy4MRS5Zf3veTv5faGdQe/51Zi6UjZh83BK3Cmac90YgyXNqAtz/Cwoj
6U9enFY=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEnDCCA4SgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBjzEjMCEGA1UEChMaREMy
LklOVEVST1AuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMu
Q09NMSUwIwYDVQQDExwuTVhGaXMuQ0lORUFTU0VULkRDMi5JTlRFUk9QMSUwIwYD
VQQuExw2TnFFazlVNGdUK0U4ZStYUVVvZDM4eWhJUVE9MB4XDTA3MDEwMTAwMDAw
MFoXDTI1MTIzMTIzNTk1OVowgZIxIzAhBgNVBAoTGkRDMi5JTlRFUk9QLkRPUkVN
SUxBQlMuQ09NMRowGAYDVQQLExFEQy5ET1JFTUlMQUJTLkNPTTEoMCYGA1UEAxMf
LlVTMS5NWEZpLkNJTkVBU1NFVC5EQzIuSU5URVJPUDElMCMGA1UELhMcSmtDZVh4
Z1ZNcFpReHRvam5IRVVqcUs4THIwPTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAJx24HsWf/IK9KXAbf7/RpzIxcLNc94xSXB2mBkejGkp2trPpidH+010
ivUsIXDZMj+B+1lvreYkoP+T7DQf1qgHCyJh7IdO43wxzhikuayp/LiIkcpUJTFA
bDrlWToKiNwA3WK26oWrrkdDVH+oVcypgjGRBw0Z6TE20xDcfcLnMT2s+7FtWVUF
raVik4Sj5tcF1KNQNg0YJ0tDUIB4wgPrebepLRDQnQXv7O4xaCHSuDzMz/tXycFu
TvOxreL7P3XdhbIYSUxH5J3GZc1kWPtls8p6AS5drZ8OK6iSmkfAJ/QPgliEfPD6
JnS8CWlPaqMZLcWzijNgEq69tBDx860CAwEAAaOB/TCB+jATBgNVHRMBAf8ECTAH
AQH/AgIA7DALBgNVHQ8EBAMCAQYwHQYDVR0OBBYEFCZAnl8YFTKWUMbaI5xxFI6i
vC69MIG2BgNVHSMEga4wgauAFOjahJPVOIE/hPHvl0FKHd/MoSEEoYGPpIGMMIGJ
MSMwIQYDVQQKExpEQzIuSU5URVJPUC5ET1JFTUlMQUJTLkNPTTEaMBgGA1UECxMR
REMuRE9SRU1JTEFCUy5DT00xHzAdBgNVBAMTFi5DSU5FQVNTRVQuREMyLklOVEVS
T1AxJTAjBgNVBC4THFc5WGh5UU9Bb1dUd2w4ZlFxL3pZckljckJ5bz2CAQIwDQYJ
KoZIhvcNAQEFBQADggEBAEVNDsNL43Y8iK53HeZTpjCIAi0ZGSFVKlQvTPKCgdub
NYvT54xRGGW597yUzES2aNeYOngdbfsRisceJ/z3F22jZQM6tKDzr3Cj4lQP6Soz
g9V+YAZRS7yiGlDyWDxFgdUshFBdJEv6uoLTPmnakZBpsj1ym8EIyIZUKIFibt2M
7vdrkL3nSmGdbhk8U/7Xh9AvWPZ8v3p0XR63N9Q9ixLLclQ6UKUM4i48G27EyzA0
ig3r27/ZAqvgogLiU2HGUW3Vs+tkDn11fX6J9mkVPycBNHfqHIgcvqYlky29Uze0
Q5UHiR5vbQ6++zhOE+swa669RxhOvhxb8pkMElCfU3k=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEkjCCA3qgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBiTEjMCEGA1UEChMaREMy
LklOVEVST1AuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMu
Q09NMR8wHQYDVQQDExYuQ0lORUFTU0VULkRDMi5JTlRFUk9QMSUwIwYDVQQuExxX
OVhoeVFPQW9XVHdsOGZRcS96WXJJY3JCeW89MB4XDTA3MDEwMTAwMDAwMFoXDTI1
MTIzMTIzNTk1OVowgY8xIzAhBgNVBAoTGkRDMi5JTlRFUk9QLkRPUkVNSUxBQlMu
Q09NMRowGAYDVQQLExFEQy5ET1JFTUlMQUJTLkNPTTElMCMGA1UEAxMcLk1YRmlz
LkNJTkVBU1NFVC5EQzIuSU5URVJPUDElMCMGA1UELhMcNk5xRWs5VTRnVCtFOGUr
WFFVb2QzOHloSVFRPTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALKH
0xid8kkyxP15i/YxVZHuxsYLDMvkqTRDx73YsUBwl4mKEUi5LZm138WpDZbSfJbD
yMNEukkq563L7d4/wkzvTYkHwcEPJ8twaiOwcaHZcTmxqjK8Jmy8UfYK1OGTQNY/
d/EGBq76/x5uGRz8epUgdr030uOeP5Mx48FS0UbEBy6Aq+bg37FTmzl8lNadPIY9
XwQx1T4W+fEn+Vue3Uotx6bPUBOeX7+iY+lYiOXAnRweEx8ZlLU3qzGy4ZKsIhrl
DYYJKaNeQ6SWySE5S/Uqmk1mbc8r3gkryXT3OdhPq8brpgmzyywBwWEzULCK8sAs
neUB5MOdWoHvuK8ImvECAwEAAaOB/DCB+TATBgNVHRMBAf8ECTAHAQH/AgIA7TAL
BgNVHQ8EBAMCAQYwHQYDVR0OBBYEFOjahJPVOIE/hPHvl0FKHd/MoSEEMIG1BgNV
HSMEga0wgaqAFFvV4ckDgKFk8JfH0Kv82KyHKwcqoYGOpIGLMIGIMSMwIQYDVQQK
ExpEQzIuSU5URVJPUC5ET1JFTUlMQUJTLkNPTTEaMBgGA1UECxMRREMuRE9SRU1J
TEFCUy5DT00xHjAcBgNVBAMTFS5QUk9EVUNUUy5EQzIuSU5URVJPUDElMCMGA1UE
LhMcazIrWkNmTHRydDdMYWFIWUFXeldicmVWL01FPYIBBjANBgkqhkiG9w0BAQUF
AAOCAQEAdHo/WjTbdkayx/UpMnmFIfI/m+9+WaTjrNB3iBoX8le9mPSDmcSNl/Nb
O2PJa6S7axUyATDAP1UnpSnKUdStLDBUgUz5GKSZjSIJTEM3pYj64wMMMilmFcrR
dMM2R/nLhKY2SwLS8jGX1xuWGW8HRxO55OQA+ypXt4pTiaHAG6jU/RL6sWGkvdVn
3t7niNmi80i1EnQMzB4HcDBfxiw04cCCxPvVCDkUaDjlQhb5yff/pJc5F1nVQOyX
LhmoZ8sxPKy9I2AR+6f9Bzs2SyGluxx7q3YelAUEl893IEajbv7W4ItTHVanVVib
T+Gvx+iOx7uG0AScu8DvHu/5NCmpmw==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEhzCCA2+gAwIBAgIBBjANBgkqhkiG9w0BAQUFADCBiDEjMCEGA1UEChMaREMy
LklOVEVST1AuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMu
Q09NMR4wHAYDVQQDExUuUFJPRFVDVFMuREMyLklOVEVST1AxJTAjBgNVBC4THGsy
K1pDZkx0cnQ3TGFhSFlBV3pXYnJlVi9NRT0wHhcNMDcwMTAxMDAwMDAwWhcNMjUx
MjMxMjM1OTU5WjCBiTEjMCEGA1UEChMaREMyLklOVEVST1AuRE9SRU1JTEFCUy5D
T00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMuQ09NMR8wHQYDVQQDExYuQ0lORUFT
U0VULkRDMi5JTlRFUk9QMSUwIwYDVQQuExxXOVhoeVFPQW9XVHdsOGZRcS96WXJJ
Y3JCeW89MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3CjRe7RlgVLO
zjhwE6LGSdjZJx1+OurPYj8QHmZ1u1YrtiyMwWhRriT16Cl88rTkdkVAVaa3Jymy
P4vHVzHzk8fdjXj0Ht3oj7h/10Ur2OVLfdRIp1mjgW1w94oyokWKombXdWT+liq6
5c7G4QEpcqv7u+4YQPpq9lLOO3taoEzwj2WT3AyyXWTaSjEozPXahRCpViqoYOze
CP60mHk+q1D+yTHsNAK+uUW/vk7dY4ecdBIM69xavO3O+NQ95gCGjc8IQSC5LjUg
FDIfKoK+jabnGZNeprWAJC6jGOsMQVQuje4HmeJ8EdUtfLF9RPUy4s09INwOq509
k5KaR06w1QIDAQABo4H4MIH1MBMGA1UdEwEB/wQJMAcBAf8CAgDuMAsGA1UdDwQE
AwIBBjAdBgNVHQ4EFgQUW9XhyQOAoWTwl8fQq/zYrIcrByowgbEGA1UdIwSBqTCB
poAUk2+ZCfLtrt7LaaHYAWzWbreV/MGhgYqkgYcwgYQxIzAhBgNVBAoTGkRDMi5J
TlRFUk9QLkRPUkVNSUxBQlMuQ09NMRowGAYDVQQLExFEQy5ET1JFTUlMQUJTLkNP
TTEaMBgGA1UEAxMRLlJPT1QuREMyLklOVEVST1AxJTAjBgNVBC4THEs5aklENFF2
ZnFTMXNTNklqaUU4ekVxU2QvZz2CAQIwDQYJKoZIhvcNAQEFBQADggEBADIYRHOS
bWOfhW4Nu7ngY0y4pCmNew5JcU1bBQwREG2NObF0rJwQGID9xyFIVJuugTJI3GsO
hCnzrxytw7PXfwHTg5YYuYOd6pIg4o6zSPqKKM/1vO7REs8ZdDhWJKOyD+F+U4za
Eiyii57lzxRzhl7YVb977J+vg3Zh8EKnNrdjyRMHmxPnIHFc+ap1yfki0IDzUAmH
mV619gs/eThexT3OrdBpzj3mMdY6mx2wnQzChDNSqkLVwOCNJv2pE7UUqbJcC1B0
lS7v4Cg4kl5zxR130bj5kqrhvLsE3j6/pffwVUNjkmoDCFBXHLLQX5Sn8AA7KyuY
epOFg2pOJ55X360=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEgjCCA2qgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBhDEjMCEGA1UEChMaREMy
LklOVEVST1AuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMu
Q09NMRowGAYDVQQDExEuUk9PVC5EQzIuSU5URVJPUDElMCMGA1UELhMcSzlqSUQ0
UXZmcVMxc1M2SWppRTh6RXFTZC9nPTAeFw0wNzAxMDEwMDAwMDBaFw0yNTEyMzEy
MzU5NTlaMIGIMSMwIQYDVQQKExpEQzIuSU5URVJPUC5ET1JFTUlMQUJTLkNPTTEa
MBgGA1UECxMRREMuRE9SRU1JTEFCUy5DT00xHjAcBgNVBAMTFS5QUk9EVUNUUy5E
QzIuSU5URVJPUDElMCMGA1UELhMcazIrWkNmTHRydDdMYWFIWUFXeldicmVWL01F
PTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBayqWWmtqdLdKrA4uX
iy4Xn+Si21Mws17L4O6pL8Lo+K/eYnILE3l3xXlklWe25JeXQfFYgQMHrIsg6Smb
FgrNBoCK3iuB0+KL2nPYpQ66bYyIz005sNBGbiFC+qD9cFMd9a39w6jCRmhv748q
5IYCFde+/VZ8af+4+IVrLP3AIwP4N+9zVxLFGeTRSdaOXRP7DrPQHHJe3QxDPlo+
ZemPCWL2VjUQBUNWnwXvtW7RlSNDoIRfJQk9Zn7sDRn3d41aTJTbiQm9jlIW+HA/
BWpVhZOBu5SyzrZikzmfoCM8/AYfzzYslCU+x17dMXbhPObiI63LLqj1rGyr/JXQ
HnMCAwEAAaOB+DCB9TATBgNVHRMBAf8ECTAHAQH/AgIA7zALBgNVHQ8EBAMCAQYw
HQYDVR0OBBYEFJNvmQny7a7ey2mh2AFs1m63lfzBMIGxBgNVHSMEgakwgaaAFCvY
yA+EL36ktbEuiI4hPMxKknf4oYGKpIGHMIGEMSMwIQYDVQQKExpEQzIuSU5URVJP
UC5ET1JFTUlMQUJTLkNPTTEaMBgGA1UECxMRREMuRE9SRU1JTEFCUy5DT00xGjAY
BgNVBAMTES5ST09ULkRDMi5JTlRFUk9QMSUwIwYDVQQuExxLOWpJRDRRdmZxUzFz
UzZJamlFOHpFcVNkL2c9ggEBMA0GCSqGSIb3DQEBBQUAA4IBAQBUFnNTINyYsjPa
4k4p53sLphIpAnREgyFTdzJazOoDTBwtgfIz5YxI4NBZc7onX0aiVbpqk01kDcH2
OLYXYmVB40xhuBQkhkyJdmJYXqqEQkZ5t5TiBQFCAW84l1LTjKj9K6NMwoiWmJ9/
1zVxp1EN9dqC0WfQ9y8lbDp1vSz+rA5EtWggNzQMHyAABaAHwERLpdGEMA2S9Y56
+gnqWIp3G/aicI6FmlbqUctAWvf/RV5PCCpzTXZjLFVO0QKl2jOb/ZB03UgLXhnX
fTaHMLJE6mlocrz2cZQ9d8CQBKZnx93DWgGQy+g+CPSB8Ay3PCjsgSi70CTLUW/J
9um+eSrj
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEfjCCA2agAwIBAgIBATANBgkqhkiG9w0BAQUFADCBhDEjMCEGA1UEChMaREMy
LklOVEVST1AuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAsTEURDLkRPUkVNSUxBQlMu
Q09NMRowGAYDVQQDExEuUk9PVC5EQzIuSU5URVJPUDElMCMGA1UELhMcSzlqSUQ0
UXZmcVMxc1M2SWppRTh6RXFTZC9nPTAeFw0wNzAxMDEwMDAwMDBaFw0yNTEyMzEy
MzU5NTlaMIGEMSMwIQYDVQQKExpEQzIuSU5URVJPUC5ET1JFTUlMQUJTLkNPTTEa
MBgGA1UECxMRREMuRE9SRU1JTEFCUy5DT00xGjAYBgNVBAMTES5ST09ULkRDMi5J
TlRFUk9QMSUwIwYDVQQuExxLOWpJRDRRdmZxUzFzUzZJamlFOHpFcVNkL2c9MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzd4f83PITte48iXCjN+Tr0RQ
j3F98T1g4x+Z8YSd6X9L8zUmHDebo+rQMOOeq91d9Px60Xi+2ra5kyVjVEiwFpNl
q5a7Q7lsk9I4imwbDmjzkCWUA4xa32px2owiAK7N10qCjj2P/D/mfnFRA/nCZSdR
Bm+BDRRqGaNT+2DBMXW6Zo/xsrOK8cLKMOpm4lx5cUfcjvzt4th8kILCZ9Xt24iW
C8Vr4jtyn5c6uumPwwYoCT9SOZj8iFwcpp9ilCMN1k87X+F1KwGtuVRiPU+57RLp
w3cDBUxBWv1L63yERRjgs/uNIFloqOUYMP08wOE0GnP7nXrL9p5U0yDe2DqkDwID
AQABo4H4MIH1MBMGA1UdEwEB/wQJMAcBAf8CAgDwMAsGA1UdDwQEAwIBBjAdBgNV
HQ4EFgQUK9jID4QvfqS1sS6IjiE8zEqSd/gwgbEGA1UdIwSBqTCBpoAUK9jID4Qv
fqS1sS6IjiE8zEqSd/ihgYqkgYcwgYQxIzAhBgNVBAoTGkRDMi5JTlRFUk9QLkRP
UkVNSUxBQlMuQ09NMRowGAYDVQQLExFEQy5ET1JFTUlMQUJTLkNPTTEaMBgGA1UE
AxMRLlJPT1QuREMyLklOVEVST1AxJTAjBgNVBC4THEs5aklENFF2ZnFTMXNTNklq
aUU4ekVxU2QvZz2CAQEwDQYJKoZIhvcNAQEFBQADggEBALLCjiEdKrCm0KTJfPPH
RYLJranOwCrtfY852z54vbXfBJqWh9I3gNOxu7sZeQ4beyCiMzij3sRYGNv28xYI
ZYS2HFEDgKoNjRgq9I3AIkXZF/eUsgE2Zfbo1ZqeNUVBt9kDFEkY8DzorSzldT4B
/gObLzY6DDG4x3e6MP9Hdl21ols0bb+FnUzcOGRK2IakFzHdMoIEQqRW13k0V9E/
lkDVuHOSQsVr8ALKNckBsERXUTCu6Cyj2fLaMlWaTLVXJwArerA6dRpbMRsDO+SO
QnTl4UpLtcWKVLG7IIDkTqOTNYw8qFZPugm/9CH/xm4Qf0AsEwAFJR/9crGysLGn
JsI=
-----END CERTIFICATE-----

Carsten
Posts: 1397
Joined: Tue Apr 15, 2014 9:11 pm
Location: Germany

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by Carsten » Tue Sep 03, 2019 9:54 am

Hmm, this seems to be a very long chain. Carl, is it possible that DCP-o-matic can only deal with a limited number of intermediate certs?

Yes, normally it should be possible to crop away the unnecessary certs...just let me try it...

Hmm, this is a Dolby/Doremi cineasset certificate chain. I'm not sure if I'm interpreting those certs properly, but the first cert at least works for me, I can cut it into a text file, name it 'cineasset.pem', and DCP-o-matic accepts it in KDM/screen management.

Hmm. Which version of DCP-o-matic are you using? With 2.14.7 I just tried, I can successfully add screens and create KDMS for all the first cert only, the last cert only, and the full chain, without any error!? Yes, not all of these KDMs will then actually work (only the leaf cert will), but I don't get the error you mention.

If you can verify a KDM with the cineasset user, I'd say try the first cert only, cut away all the other following blocks. Make sure to save text only, not RTF, doc, etc.

- Carsten

Carsten
Posts: 1397
Joined: Tue Apr 15, 2014 9:11 pm
Location: Germany

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by Carsten » Tue Sep 03, 2019 10:26 am

In order of appearance:

(created by copy/pasting into: https://www.sslshopper.com/certificate-decoder.html )

Certificate Information:
Common Name: ME CS SM.CineAsset-119128362.DC.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .US1.MXFi.CINEASSET.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 3346518669010331549 (0x2e7138ffb492e79d)
---
Certificate Information:
Common Name: .US1.MXFi.CINEASSET.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .MXFis.CINEASSET.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 2 (0x2)
---
Certificate Information:
Common Name: .MXFis.CINEASSET.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .CINEASSET.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 2 (0x2)
---
Certificate Information:
Common Name: .CINEASSET.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .PRODUCTS.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 6 (0x6)
---
Certificate Information:
Common Name: .PRODUCTS.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .ROOT.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 2 (0x2)
---
Certificate Information:
Common Name: .ROOT.DC2.INTEROP
Organization: DC2.INTEROP.DOREMILABS.COM
Organization Unit: DC.DOREMILABS.COM
Valid From: December 31, 2006
Valid To: December 31, 2025
Issuer: .ROOT.DC2.INTEROP, DC2.INTEROP.DOREMILABS.COM
Serial Number: 1 (0x1)
---

The final one, quite obviously, is the root cert. I am not an x.509 expert, but, from the serial numbers, I would guess that only the first cert with a long serial number is likely to be associated with an individual device or software installation, so that should be the leaf/decryption cert needed to create KDMs.
All other serial numbers occur too short/small to me or are immediately recognizable as non-leaf certs. Maybe someone with a deeper knowledge can chime in.


- Carsten
Last edited by Carsten on Tue Sep 03, 2019 12:27 pm, edited 1 time in total.

t9nu
Posts: 4
Joined: Tue Sep 03, 2019 8:58 am

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by t9nu » Tue Sep 03, 2019 11:05 am

Carsten wrote:
Tue Sep 03, 2019 9:54 am
Hmm, this seems to be a very long chain. Carl, is it possible that DCP-o-matic can only deal with a limited number of intermediate certs?

Yes, normally it should be possible to crop away the unnecessary certs...just let me try it...

Hmm, this is a Dolby/Doremi cineasset certificate chain. I'm not sure if I'm interpreting those certs properly, but the first cert at least works for me, I can cut it into a text file, name it 'cineasset.pem', and DCP-o-matic accepts it in KDM/screen management.

Hmm. Which version of DCP-o-matic are you using? With 2.14.7 I just tried, I can successfully add screens and create KDMS for all the first cert only, the last cert only, and the full chain, without any error!? Yes, not all of these KDMs will then actually work (only the leaf cert will), but I don't get the error you mention.

If you can verify a KDM with the cineasset user, I'd say try the first cert only, cut away all the other following blocks. Make sure to save text only, not RTF, doc, etc.

- Carsten
I use the latest version 2.14.8 on PC a Mac os. Thanks for your kindness.

t9nu
Posts: 4
Joined: Tue Sep 03, 2019 8:58 am

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by t9nu » Tue Sep 03, 2019 11:07 am

Thank, for your respond Carsten.

I already did everything like you told me. But it is not working at all.
So I attachment a Photo to show how problem is. This information might be helpful for your support

-T9nu
Attachments
Add Screen.jpg
Add Screen.jpg (257.31 KiB) Viewed 226 times

carl
Site Admin
Posts: 1050
Joined: Thu Nov 14, 2013 2:53 pm

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by carl » Tue Sep 03, 2019 11:19 am

It looks like you have added a second trusted device but not the original media block cert. Try "Get from file..." next to "Recipient certificate" and give it your certificate.

t9nu
Posts: 4
Joined: Tue Sep 03, 2019 8:58 am

Re: Could not load certificate(Unexpected data after certificate) Problem. Help please!!!!!!

Post by t9nu » Tue Sep 03, 2019 12:07 pm

Problem solved with the first certificate. Thank you so much.

Post Reply