FPS Certificate Re-issuance and Validity of Existing Certificate

Keywords: FairPlay, FPS Certificate, DRM, FairPlay Streaming, license server

Hi all,

We are currently using FairPlay Streaming in production and already have an FPS certificate in place. However, the passphrase for the existing FPS certificate has unfortunately been lost.

We are now considering reissuing a new FPS certificate, and I would like to confirm a few points before proceeding:

1️⃣ If we reissue a new FPS certificate, will the existing certificate be automatically revoked? Or will it remain valid until its original expiration date?

2️⃣ Is it possible to have both the newly issued and the existing certificates valid at the same time? In other words, can we serve DRM licenses using either certificate depending on the packaging or client?

3️⃣ Are there any caveats or best practices we should be aware of when reissuing an FPS certificate? For example, would existing packaged content become unplayable, or would CDN/packaging server configurations need to be updated carefully?

Since this affects our production environment, we would like to minimize any service disruption or compatibility issues.

Unfortunately, when we contacted Apple support directly, we were advised to post this question here in the Forums for additional guidance.

Any advice or experiences would be greatly appreciated! Thank you in advance.

Hello,

  1. Even if you receive a new FPS cert the previously issued one is still valid and can be used.
  2. Yes, you can use both certificates. You will need to support two private keys and two secret ASk values in your Key Server.
  3. The content that is hosted on your servers does not use FPS certificate in any way. It is encrypted using your selected content key and IV. FPS certificate is used when protecting that content key and IV sent from your Key Server to the client device, but the value of content key/IV stays the same.
FPS Certificate Re-issuance and Validity of Existing Certificate
 
 
Q