biss ca entitlements.md

Managing BISS-CA entitlements

To successfully decrypt BISS-CA content, MK.IO Beam Distribution must have the correct entitlements. The Content Provider requires a public key exported from the receivers BISS-CA Key Pair table.

To get the correct entitlements, follow these steps:

Obtaining BISS-CA entitlements

  1. Contact content provider
  2. Exchange keys
  3. Check authorization

Step #1 - Contact content provider

Contact the provider of the scrambled content and determine how they wish to exchange key pairs. They will require one of the following methods:

The keys will need to be exchanged between the content provider and the receiver operator using an out-of-band method chosen by the content provider.

Step #2 - Exchange keys

Method 1: Send Public Key

If requested by the content provider, the receiver operator must supply a public key to enable entitlement by the scrambler using a self-generated key pair.

  1. If a self-generated key pair is not already available, create a self-generated key pair.

  2. Export the public key.

  3. Send the public key to the content provider who will manage entitlements.

Method 2: Import Public/Private Key

The content provider will supply a public and private key pair to the receiver operator, which must be imported into the receiver. This is done using an injected key pair.

  1. Import injected key pair.

  2. The public key should already be registered with the content provider who will manage entitlements.

Step #3 - Check authorization

  1. Enable BISS-CA decryption for service decode.

  2. From the video-plus icon Services page, click Alarm to view the alarms page.

  3. Confirm that no alarms are raised.

  4. If the raised alarm Label reports BISS CA not decrypting and the Info column states not authorized then this is due to one or more of the following conditions:

  1. Contact the content provider to confirm that the correct public key has been registered and that entitlements have been enabled.

Info: It may be necessary to refer to the EKID value, see Managing BISS-CA keys.