Security Services Platform Documentation

Apple FairPlay Streaming Certificate Application

1. Certificate generation

In order to use Fairplay Streaming DRM, a Fairplay Streaming deployment package must be acquired from Apple. The application for this deployment package needs to be filed through an Organizational Apple Developer account for the company that has the actual content rights – typically the customer. This process may be time-consuming, so it is important to start it as early as possible in the integration phase. These are the high-level steps:

  1. Create an Apple ID.

  2. Obtain a D-U-N-S number.

  3. Join the Apple Developer Program and enroll as an organization. There is an annual fee for joining this program.

  4. Apply for the FPS Deployment Package.

  5. Follow the two procedures Generate a Certificate Signing Request and Creating your FPS Certificate that are described in the FairPlayCertificateCreation.pdf document in the package.

See https://developer.apple.com/contact/fps/



2. Certificate registration in SSP

Once you have followed the above procedure, please share the following information with the NAGRA Cloud Operations team

  • The FairPlay certificate bundle

  • The Provisioning data

  • The FairPlay private keys (1024 + 2048)

    • If the private keys are encrypted, the please also provide the password

Note that these assets are sensitive and need to be encrypted in the exchange with Cloud Operations team.


In case you already have an old certificate (version SDK4) we also support that format. In that case please provide the following information instead of the above:

  • The FPS certificate file: application certificate, as a base64 string (.der,  .cer)

  • The application secret key, as a base64 string

  • The application certificate hash, as a base64 string

  • The application certificate private key, as a base64 string (and its password, if any)