37 lines
1.5 KiB
Markdown
37 lines
1.5 KiB
Markdown
# UML L0 RCA generation tools
|
|||
|
|
|
||
|
|
Both tools use the Rust/c-its certificate path pinned to commit
|
||
|
|
`e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4`in https://github.com/TheEnbyperor/c-its. Requirements are Python 3.10+,
|
||
|
|
`cryptography`, Git, Rust/Cargo, and internet access for the first build.
|
||
|
|
|
||
|
|
## Rebuild the registered root
|
||
|
|
|
||
|
|
```text
|
||
|
|
python rebuild\_registered\_rca.py
|
||
|
|
```
|
||
|
|
|
||
|
|
Uses `private/UML\_L0\_RCA\_private\_encrypted.pem`. It succeeds only when the result is
|
||
|
|
byte-for-byte identical to the registered `AFD566A8034ED5DB.oer`. Use this to prove
|
||
|
|
how the registered certificate was made or to verify the registered key. It never
|
||
|
|
creates a key and does not alter the registered files.
|
||
|
|
|
||
|
|
## Create a separate new root
|
||
|
|
|
||
|
|
```text
|
||
|
|
python create\_new\_root.py
|
||
|
|
```
|
||
|
|
|
||
|
|
Creates a new P-256 key and candidate root certificate. It copies the registered
|
||
|
|
root's reviewed TBS profile, including CertificateID, permissions, region and
|
||
|
|
validity, but replaces the public key and signature. The result therefore has a
|
||
|
|
different HashedId8 and is **not EU-registered**.
|
||
|
|
|
||
|
|
Use this only for an isolated test root or a deliberate EU registration/re-key
|
||
|
|
process. Before submission, review the inherited validity/profile and coordinate
|
||
|
|
revocation or registration with the EU CCMS CPOC. Files appear under a directory
|
||
|
|
named `CANDIDATE\_SUBMISSION\_NOT\_REGISTERED`; that name is a warning, not approval.
|
||
|
|
|
||
|
|
In both workflows the private scalar is passed to the local Rust process through
|
||
|
|
standard input and is never stored unencrypted by these tools.
|
||
|
|
|