Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but that tree was gitignored, so a clone of this repository could not build the firmware it ships. It is now committed here as ordinary files in its own folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP bridge's signature verification (--trust) used on the bench. Nothing is fetched from or pushed to the colleague's repository; this repository and its remotes carry everything. The folder's own .gitignore keeps build output, downloaded components and private key material out, as it did there; the committed file set is identical to that repository's tracked files. The ESP32-C5 is still flashed from obu-firmware/, which only takes vanetza-idf from microbu-esp32c5/, so the two stay separate folders. FLASHING.md says how to take a newer version of the colleague's tree (copy it over the folder, rebuild, test, commit).
This commit is contained in:
+58
@@ -0,0 +1,58 @@
|
||||
EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
HashedId8, Time32, PublicEncryptionKey, PublicVerificationKey, Signature
|
||||
FROM
|
||||
Ieee1609Dot2BaseTypes {iso(1) identified-organization(3) ieee(111)
|
||||
standards-association-numbered-series-standards(2) wave-stds(1609)
|
||||
dot2(2) base(1) base-types(2) major-version-2(2) minor-version-3(3)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
CertificateId, SubjectAssurance, SequenceOfPsidSsp, SequenceOfPsidGroupPermissions,
|
||||
ValidityPeriod, GeographicRegion, HashedData
|
||||
FROM
|
||||
Ieee1609Dot2 {iso(1) identified-organization(3) ieee(111)
|
||||
standards-association-numbered-series-standards(2) wave-stds(1609)
|
||||
dot2(2) base (1) schema (1) major-version-2(2) minor-version-4(4)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
EtsiTs103097Data, EtsiTs103097Data-Encrypted, EtsiTs103097Data-Signed,
|
||||
EtsiTs103097Data-SignedExternalPayload,
|
||||
EtsiTs103097Data-Unsecured, EtsiTs103097Data-Encrypted-Unicast, EtsiTs103097Data-SignedAndEncrypted-Unicast
|
||||
FROM
|
||||
EtsiTs103097Module {itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
CertificateFormat::= INTEGER {
|
||||
ts103097v131 (1)
|
||||
}(1..255)
|
||||
|
||||
CertificateSubjectAttributes ::= SEQUENCE {
|
||||
id CertificateId OPTIONAL,
|
||||
validityPeriod ValidityPeriod OPTIONAL,
|
||||
region GeographicRegion OPTIONAL,
|
||||
assuranceLevel SubjectAssurance OPTIONAL,
|
||||
appPermissions SequenceOfPsidSsp OPTIONAL,
|
||||
certIssuePermissions SequenceOfPsidGroupPermissions OPTIONAL,
|
||||
...
|
||||
}(WITH COMPONENTS { ..., appPermissions PRESENT} |
|
||||
WITH COMPONENTS { ..., certIssuePermissions PRESENT})
|
||||
|
||||
EcSignature::= CHOICE {
|
||||
encryptedEcSignature EtsiTs103097Data-Encrypted{EtsiTs103097Data-SignedExternalPayload},
|
||||
ecSignature EtsiTs103097Data-SignedExternalPayload
|
||||
}
|
||||
|
||||
PublicKeys ::= SEQUENCE {
|
||||
verificationKey PublicVerificationKey,
|
||||
encryptionKey PublicEncryptionKey OPTIONAL
|
||||
}
|
||||
|
||||
Version ::= INTEGER {v1(1)}
|
||||
|
||||
END
|
||||
+127
@@ -0,0 +1,127 @@
|
||||
/*************************************************************************************
|
||||
This file contains the EtsiTs102941Messages module containing all possible PKI messages.
|
||||
It should be used when all PKI messages needs to be implemented (for example, for CA development)
|
||||
**************************************************************************************/
|
||||
EtsiTs102941MessagesCa
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) messagesCa(0) major-version-3(3) minor-version-3(3)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Data-Signed,
|
||||
EtsiTs103097Data-SignedExternalPayload,
|
||||
EtsiTs103097Data-Encrypted-Unicast,
|
||||
EtsiTs103097Data-SignedAndEncrypted-Unicast
|
||||
FROM EtsiTs103097Module
|
||||
{itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
InnerEcRequestSignedForPop, InnerEcResponse
|
||||
FROM EtsiTs102941TypesEnrolment
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) enrolment(4) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EtsiTs102941ButterflyAuthorizationRequest-X509Signed, InnerAtRequest, InnerAtResponse
|
||||
FROM EtsiTs102941TypesAuthorization
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authorization(5) major-version-3(3) minor-version-2(2) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedCrl, ToBeSignedTlmCtl, ToBeSignedRcaCtl
|
||||
FROM EtsiTs102941TrustLists
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) trustLists(6) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
AuthorizationValidationRequest, AuthorizationValidationResponse
|
||||
FROM EtsiTs102941TypesAuthorizationValidation
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authValidation(7) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
CaCertificateRequest
|
||||
FROM EtsiTs102941TypesCaManagement
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) caManagement(8) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedLinkCertificate, ToBeSignedLinkCertificateTlm, ToBeSignedLinkCertificateRca
|
||||
FROM EtsiTs102941TypesLinkCertificate
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) linkCertificate(9) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EeRaCertRequest, RaEeCertInfo, EeRaDownloadRequest
|
||||
FROM Ieee1609Dot2Dot1EeRaInterface
|
||||
{iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) ee-ra(11) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
RaAcaCertRequest, AcaRaCertResponse
|
||||
FROM Ieee1609Dot2Dot1AcaRaInterface
|
||||
{iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) aca-ra(4) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- Messages
|
||||
************/
|
||||
EnrolmentRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentRequest PRESENT})})}
|
||||
EnrolmentResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentResponse PRESENT})})}
|
||||
AuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationRequestMessageWithPop ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationResponse PRESENT})})}
|
||||
CertificateRevocationListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateRevocationList PRESENT})})}
|
||||
TlmCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListTlm PRESENT})})}
|
||||
RcaCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListRca PRESENT})})}
|
||||
AuthorizationValidationRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationValidationRequest PRESENT})})}
|
||||
AuthorizationValidationResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationValidationResponse PRESENT})})}
|
||||
CaCertificateRequestMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data(WITH COMPONENTS{..., content (WITH COMPONENTS{caCertificateRequest PRESENT})})}
|
||||
CaCertificateRekeyingMessage ::= EtsiTs103097Data-Signed {EtsiTs103097Data-Signed {EtsiTs102941Data(WITH COMPONENTS{..., content (WITH COMPONENTS{caCertificateRequest PRESENT})})}}
|
||||
TlmLinkCertificateMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{linkCertificateTlm PRESENT})})}
|
||||
RcaSingleSignedLinkCertificateMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{singleSignedLinkCertificateRca PRESENT})})}
|
||||
RcaDoubleSignedLinkCertificateMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{doubleSignedlinkCertificateRca PRESENT})})}
|
||||
ButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationRequest PRESENT})})}
|
||||
X509SignedButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{x509SignedbutterflyAuthorizationRequest PRESENT})})}
|
||||
ButterflyAuthorizationResponseMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationResponse PRESENT})})}
|
||||
ButterflyAtDownloadRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAtDownloadRequest PRESENT})})}
|
||||
ButterflyCertRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyCertificateRequest PRESENT})})}
|
||||
ButterflyCertResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyCertificateResponse PRESENT})})}
|
||||
|
||||
/************
|
||||
-- EtsiTs102941Data
|
||||
************/
|
||||
|
||||
EtsiTs102941Data::= SEQUENCE {
|
||||
version Version (v1),
|
||||
content EtsiTs102941DataContent
|
||||
}
|
||||
|
||||
EtsiTs102941DataContent ::= CHOICE {
|
||||
enrolmentRequest InnerEcRequestSignedForPop,
|
||||
enrolmentResponse InnerEcResponse,
|
||||
authorizationRequest InnerAtRequest,
|
||||
authorizationResponse InnerAtResponse,
|
||||
certificateRevocationList ToBeSignedCrl,
|
||||
certificateTrustListTlm ToBeSignedTlmCtl,
|
||||
certificateTrustListRca ToBeSignedRcaCtl,
|
||||
authorizationValidationRequest AuthorizationValidationRequest,
|
||||
authorizationValidationResponse AuthorizationValidationResponse,
|
||||
caCertificateRequest CaCertificateRequest,
|
||||
...,
|
||||
linkCertificateTlm ToBeSignedLinkCertificateTlm,
|
||||
singleSignedLinkCertificateRca ToBeSignedLinkCertificateRca,
|
||||
doubleSignedlinkCertificateRca RcaSingleSignedLinkCertificateMessage,
|
||||
/* Extension for butterfly key provisioning */
|
||||
[[butterflyAuthorizationRequest EeRaCertRequest,
|
||||
x509SignedbutterflyAuthorizationRequest EtsiTs102941ButterflyAuthorizationRequest-X509Signed,
|
||||
butterflyAuthorizationResponse RaEeCertInfo,
|
||||
butterflyCertificateRequest RaAcaCertRequest,
|
||||
butterflyCertificateResponse AcaRaCertResponse,
|
||||
butterflyAtDownloadRequest EeRaDownloadRequest]]
|
||||
}
|
||||
|
||||
|
||||
|
||||
END
|
||||
Vendored
+106
@@ -0,0 +1,106 @@
|
||||
/*************************************************************************************
|
||||
This file contains the EtsiTs102941MessagesItss-OptionalPrivacy module providing the
|
||||
same subset of messages as the EtsiTs102941MessagesItss module.
|
||||
It should never be used together with the EtsiTs102941MessagesCA and EtsiTs102941MessagesItss
|
||||
|
||||
This module allows the usage of unencrypted EC signature for AA requests.
|
||||
**************************************************************************************/
|
||||
EtsiTs102941MessagesItss-OptionalPrivacy
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) messagesItssOp(2) major-version-3(3) minor-version-3(3)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Data-Signed,
|
||||
EtsiTs103097Data-Encrypted-Unicast,
|
||||
EtsiTs103097Data-SignedAndEncrypted-Unicast
|
||||
FROM EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
InnerEcRequestSignedForPop, InnerEcResponse
|
||||
FROM EtsiTs102941TypesEnrolment
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) enrolment(4) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EtsiTs102941ButterflyAuthorizationRequest-X509Signed, InnerAtRequest, InnerAtResponse
|
||||
FROM EtsiTs102941TypesAuthorization
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authorization(5) major-version-3(3) minor-version-2(2) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedCrl, ToBeSignedTlmCtl, ToBeSignedRcaCtl
|
||||
FROM EtsiTs102941TrustLists
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) trustLists(6) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedLinkCertificate, ToBeSignedLinkCertificateTlm
|
||||
FROM EtsiTs102941TypesLinkCertificate
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) linkCertificate(9) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
EeRaCertRequest, RaEeCertInfo, EeRaDownloadRequest
|
||||
FROM Ieee1609Dot2Dot1EeRaInterface
|
||||
{ iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) ee-ra(11) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
;
|
||||
|
||||
/************
|
||||
-- Messages
|
||||
************/
|
||||
|
||||
EnrolmentRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentRequest PRESENT})})}
|
||||
EnrolmentResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentResponse PRESENT})})}
|
||||
AuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationRequestMessageWithPop ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationResponse PRESENT})})}
|
||||
CertificateRevocationListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateRevocationList PRESENT})})}
|
||||
TlmCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListTlm PRESENT})})}
|
||||
RcaCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListRca PRESENT})})}
|
||||
TlmLinkCertificateMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{linkCertificateTlm PRESENT})})}
|
||||
ButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationRequest PRESENT})})}
|
||||
X509SignedButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{x509SignedbutterflyAuthorizationRequest PRESENT})})}
|
||||
ButterflyAuthorizationResponseMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationResponse PRESENT})})}
|
||||
ButterflyAtDownloadRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAtDownloadRequest PRESENT})})}
|
||||
|
||||
/************
|
||||
-- EtsiTs102941Data
|
||||
************/
|
||||
|
||||
EtsiTs102941Data::= SEQUENCE {
|
||||
version Version (v1),
|
||||
content EtsiTs102941DataContent
|
||||
}
|
||||
|
||||
EtsiTs102941DataContent ::= CHOICE {
|
||||
enrolmentRequest InnerEcRequestSignedForPop,
|
||||
enrolmentResponse InnerEcResponse,
|
||||
authorizationRequest InnerAtRequest,
|
||||
authorizationResponse InnerAtResponse,
|
||||
certificateRevocationList ToBeSignedCrl,
|
||||
certificateTrustListTlm ToBeSignedTlmCtl,
|
||||
certificateTrustListRca ToBeSignedRcaCtl,
|
||||
authorizationValidationRequest NULL,
|
||||
authorizationValidationResponse NULL,
|
||||
caCertificateRequest NULL,
|
||||
...,
|
||||
linkCertificateTlm ToBeSignedLinkCertificateTlm,
|
||||
singleSignedLinkCertificateRca NULL,
|
||||
doubleSignedlinkCertificateRca NULL,
|
||||
/* Extension for butterfly key provisioning */
|
||||
[[butterflyAuthorizationRequest EeRaCertRequest,
|
||||
x509SignedbutterflyAuthorizationRequest EtsiTs102941ButterflyAuthorizationRequest-X509Signed,
|
||||
butterflyAuthorizationResponse RaEeCertInfo,
|
||||
butterflyCertificateRequest NULL,
|
||||
butterflyCertificateResponse NULL,
|
||||
butterflyAtDownloadRequest EeRaDownloadRequest]]
|
||||
}
|
||||
|
||||
END
|
||||
+112
@@ -0,0 +1,112 @@
|
||||
/*************************************************************************************
|
||||
This file contains the EtsiTs102941MessagesItss module providing the ITS-S subset
|
||||
of messages defined in the module EtsiTs102941MessagesCA
|
||||
It should never be imported together with the module EtsiTs102941MessagesCA.
|
||||
Use the EtsiTs102941MessagesCA if all possible PKI message types are needed.
|
||||
|
||||
This module blocks the usage of unencrypted EC signature for AA requests.
|
||||
**************************************************************************************/
|
||||
EtsiTs102941MessagesItss
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) messagesItss(1) major-version-3(3) minor-version-3(3)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Data-Signed,
|
||||
EtsiTs103097Data-Encrypted-Unicast,
|
||||
EtsiTs103097Data-SignedAndEncrypted-Unicast
|
||||
FROM EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
InnerEcRequestSignedForPop, InnerEcResponse
|
||||
FROM EtsiTs102941TypesEnrolment
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) enrolment(4) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EtsiTs102941ButterflyAuthorizationRequest-X509Signed, InnerAtRequest, InnerAtResponse
|
||||
FROM EtsiTs102941TypesAuthorization
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authorization(5) major-version-3(3) minor-version-2(2) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedCrl, ToBeSignedTlmCtl, ToBeSignedRcaCtl
|
||||
FROM EtsiTs102941TrustLists
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) trustLists(6) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
ToBeSignedLinkCertificate, ToBeSignedLinkCertificateTlm
|
||||
FROM EtsiTs102941TypesLinkCertificate
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) linkCertificate(9) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EeRaCertRequest, RaEeCertInfo, EeRaDownloadRequest
|
||||
FROM Ieee1609Dot2Dot1EeRaInterface
|
||||
{ iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) ee-ra(11) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- Messages
|
||||
************/
|
||||
|
||||
EnrolmentRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentRequest PRESENT})})}
|
||||
EnrolmentResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{enrolmentResponse PRESENT})})}
|
||||
AuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationRequestMessageWithPop ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationRequest PRESENT})})}
|
||||
AuthorizationResponseMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{authorizationResponse PRESENT})})}
|
||||
CertificateRevocationListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateRevocationList PRESENT})})}
|
||||
TlmCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListTlm PRESENT})})}
|
||||
RcaCertificateTrustListMessage ::= EtsiTs103097Data-Signed{EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{certificateTrustListRca PRESENT})})}
|
||||
TlmLinkCertificateMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{linkCertificateTlm PRESENT})})}
|
||||
ButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationRequest PRESENT})})}
|
||||
X509SignedButterflyAuthorizationRequestMessage ::= EtsiTs103097Data-Encrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{x509SignedbutterflyAuthorizationRequest PRESENT})})}
|
||||
ButterflyAuthorizationResponseMessage ::= EtsiTs103097Data-Signed {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAuthorizationResponse PRESENT})})}
|
||||
ButterflyAtDownloadRequestMessage ::= EtsiTs103097Data-SignedAndEncrypted-Unicast {EtsiTs102941Data (WITH COMPONENTS{..., content (WITH COMPONENTS{butterflyAtDownloadRequest PRESENT})})}
|
||||
|
||||
/************
|
||||
-- EtsiTs102941Data
|
||||
************/
|
||||
|
||||
EtsiTs102941Data::= SEQUENCE {
|
||||
version Version (v1),
|
||||
content EtsiTs102941DataContent
|
||||
}
|
||||
|
||||
EtsiTs102941DataContent ::= CHOICE {
|
||||
enrolmentRequest InnerEcRequestSignedForPop,
|
||||
enrolmentResponse InnerEcResponse,
|
||||
authorizationRequest InnerAtRequest,
|
||||
authorizationResponse InnerAtResponse,
|
||||
certificateRevocationList ToBeSignedCrl,
|
||||
certificateTrustListTlm ToBeSignedTlmCtl,
|
||||
certificateTrustListRca ToBeSignedRcaCtl,
|
||||
authorizationValidationRequest NULL,
|
||||
authorizationValidationResponse NULL,
|
||||
caCertificateRequest NULL,
|
||||
...,
|
||||
linkCertificateTlm ToBeSignedLinkCertificateTlm,
|
||||
singleSignedLinkCertificateRca NULL,
|
||||
doubleSignedlinkCertificateRca NULL,
|
||||
/* Extension for butterfly key provisioning */
|
||||
[[butterflyAuthorizationRequest EeRaCertRequest,
|
||||
x509SignedbutterflyAuthorizationRequest EtsiTs102941ButterflyAuthorizationRequest-X509Signed,
|
||||
butterflyAuthorizationResponse RaEeCertInfo,
|
||||
butterflyCertificateRequest NULL,
|
||||
butterflyCertificateResponse NULL,
|
||||
butterflyAtDownloadRequest EeRaDownloadRequest]]
|
||||
} (WITH COMPONENTS{...,
|
||||
authorizationRequest (WITH COMPONENTS{...,
|
||||
ecSignature (WITH COMPONENTS{...,
|
||||
encryptedEcSignature PRESENT
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
END
|
||||
@@ -0,0 +1,3 @@
|
||||
The TS 102941 v2.2.1 PKI ASN1 files are copied from its [ETSI repository](https://forge.etsi.org/rep/ITS/asn1/pki_ts102941/-/tree/v2.2.1).
|
||||
|
||||
See [ETSI License](https://forge.etsi.org/rep/ITS/asn1/pki_ts102941/-/blob/v2.2.1/LICENSE) for copyright details.
|
||||
+143
@@ -0,0 +1,143 @@
|
||||
EtsiTs102941TrustLists
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) trustLists(6) major-version-3(3) minor-version-1(1)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Certificate, EtsiTs103097Data-SignedAndEncrypted, EtsiTs103097Data-Signed
|
||||
FROM
|
||||
EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
HashedId8, Time32, Version --, CertificateAuthorityConstraints
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- CRL
|
||||
************/
|
||||
ToBeSignedCrl ::= SEQUENCE {
|
||||
version Version,
|
||||
thisUpdate Time32,
|
||||
nextUpdate Time32,
|
||||
entries SEQUENCE OF CrlEntry,
|
||||
...
|
||||
}
|
||||
|
||||
CrlEntry ::= HashedId8
|
||||
|
||||
/************
|
||||
-- TLM CTL
|
||||
************/
|
||||
|
||||
ToBeSignedTlmCtl ::= CtlFormat (FullCtl | DeltaCtl) (WITH COMPONENTS {...,
|
||||
ctlCommands ( WITH COMPONENT(
|
||||
( WITH COMPONENTS {...,
|
||||
add ( WITH COMPONENTS {...,
|
||||
ea ABSENT,
|
||||
aa ABSENT
|
||||
})
|
||||
})
|
||||
))
|
||||
})
|
||||
|
||||
/************
|
||||
-- RCA CTL
|
||||
************/
|
||||
|
||||
ToBeSignedRcaCtl ::= CtlFormat (FullCtl | DeltaCtl) ( WITH COMPONENTS {...,
|
||||
ctlCommands ( WITH COMPONENT(
|
||||
( WITH COMPONENTS {...,
|
||||
add ( WITH COMPONENTS {...,
|
||||
rca ABSENT,
|
||||
tlm ABSENT
|
||||
})
|
||||
})
|
||||
))
|
||||
})
|
||||
|
||||
/************
|
||||
-- CTL
|
||||
************/
|
||||
|
||||
FullCtl::= CtlFormat ( WITH COMPONENTS {...,
|
||||
isFullCtl ( TRUE ),
|
||||
ctlCommands ( WITH COMPONENT(
|
||||
( WITH COMPONENTS {...,
|
||||
delete ABSENT
|
||||
})
|
||||
))
|
||||
})
|
||||
|
||||
DeltaCtl::= CtlFormat (WITH COMPONENTS {...,
|
||||
isFullCtl(FALSE)
|
||||
})
|
||||
|
||||
|
||||
CtlFormat ::= SEQUENCE {
|
||||
version Version,
|
||||
nextUpdate Time32,
|
||||
isFullCtl BOOLEAN,
|
||||
ctlSequence INTEGER (0..255),
|
||||
ctlCommands SEQUENCE OF CtlCommand,
|
||||
...
|
||||
}
|
||||
|
||||
CtlCommand ::= CHOICE {
|
||||
add CtlEntry,
|
||||
delete CtlDelete,
|
||||
...
|
||||
}
|
||||
|
||||
CtlEntry ::= CHOICE {
|
||||
rca RootCaEntry,
|
||||
ea EaEntry,
|
||||
aa AaEntry,
|
||||
dc DcEntry,
|
||||
tlm TlmEntry,
|
||||
...
|
||||
}
|
||||
|
||||
CtlDelete ::= CHOICE {
|
||||
cert HashedId8,
|
||||
dc DcDelete,
|
||||
...
|
||||
}
|
||||
|
||||
TlmEntry::= SEQUENCE {
|
||||
selfSignedTLMCertificate EtsiTs103097Certificate,
|
||||
successorTo EtsiTs103097Certificate OPTIONAL,
|
||||
accessPoint Url
|
||||
}
|
||||
|
||||
RootCaEntry ::= SEQUENCE {
|
||||
selfsignedRootCa EtsiTs103097Certificate,
|
||||
successorTo EtsiTs103097Certificate OPTIONAL
|
||||
}
|
||||
|
||||
EaEntry ::= SEQUENCE {
|
||||
eaCertificate EtsiTs103097Certificate,
|
||||
aaAccessPoint Url,
|
||||
itsAccessPoint Url OPTIONAL
|
||||
}
|
||||
|
||||
AaEntry ::= SEQUENCE {
|
||||
aaCertificate EtsiTs103097Certificate,
|
||||
accessPoint Url
|
||||
}
|
||||
|
||||
DcEntry ::= SEQUENCE {
|
||||
url Url,
|
||||
cert SEQUENCE OF HashedId8
|
||||
}
|
||||
|
||||
DcDelete ::= Url
|
||||
|
||||
Url::= IA5String
|
||||
|
||||
END
|
||||
+105
@@ -0,0 +1,105 @@
|
||||
EtsiTs102941TypesAuthorization
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authorization(5) major-version-3(3) minor-version-3(3)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Certificate,
|
||||
EtsiTs103097Data-Signed
|
||||
FROM EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
CertificateFormat, CertificateSubjectAttributes, EcSignature, HashedId8, PublicKeys, Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
EeRaInterfacePdu
|
||||
FROM Ieee1609Dot2Dot1EeRaInterface
|
||||
{ iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) ee-ra(11) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
Ieee1609Dot2Data-SignedX509AuthenticatedCertRequest, ScmsPdu-Scoped, SignerSingleX509Cert
|
||||
FROM Ieee1609Dot2Dot1Protocol
|
||||
{ iso(1) identified-organization(3) ieee(111) standards-association-numbered-series-standards(2) wave-stds(1609) dot2(2) extension-standards(255) dot1(1) interfaces(1) protocol(17) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
;
|
||||
|
||||
/************
|
||||
-- AuthorizationRequest/Response
|
||||
************/
|
||||
|
||||
AuthorizationResponseCode ::= ENUMERATED {
|
||||
ok(0),
|
||||
-- ITS->AA
|
||||
its-aa-cantparse, -- valid for any structure
|
||||
its-aa-badcontenttype, -- not encrypted, not signed, not authorizationrequest
|
||||
its-aa-imnottherecipient, -- the "recipients" of the outermost encrypted data doesn't include me
|
||||
its-aa-unknownencryptionalgorithm, -- either kexalg or contentencryptionalgorithm
|
||||
its-aa-decryptionfailed, -- works for ECIES-HMAC and AES-CCM
|
||||
its-aa-keysdontmatch, -- HMAC keyTag verification fails
|
||||
its-aa-incompleterequest, -- some elements are missing
|
||||
its-aa-invalidencryptionkey, -- the responseEncryptionKey is bad
|
||||
its-aa-outofsyncrequest, -- signingTime is outside acceptable limits
|
||||
its-aa-unknownea, -- the EA identified by eaId is unknown to me
|
||||
its-aa-invalidea, -- the EA certificate is revoked
|
||||
its-aa-deniedpermissions, -- I, the AA, deny the requested permissions
|
||||
-- AA->EA
|
||||
aa-ea-cantreachea, -- the EA is unreachable (network error?)
|
||||
-- EA->AA
|
||||
ea-aa-cantparse, -- valid for any structure
|
||||
ea-aa-badcontenttype, -- not encrypted, not signed, not authorizationrequest
|
||||
ea-aa-imnottherecipient, -- the "recipients" of the outermost encrypted data doesn't include me
|
||||
ea-aa-unknownencryptionalgorithm, -- either kexalg or contentencryptionalgorithm
|
||||
ea-aa-decryptionfailed, -- works for ECIES-HMAC and AES-CCM
|
||||
-- TODO: to be continued...
|
||||
invalidaa, -- the AA certificate presented is invalid/revoked/whatever
|
||||
invalidaasignature, -- the AA certificate presented can't validate the request signature
|
||||
wrongea, -- the encrypted signature doesn't designate me as the EA
|
||||
unknownits, -- can't retrieve the EC/ITS in my DB
|
||||
invalidsignature, -- signature verification of the request by the EC fails
|
||||
invalidencryptionkey, -- signature is good, but the key is bad
|
||||
deniedpermissions, -- permissions not granted
|
||||
deniedtoomanycerts, -- parallel limit
|
||||
... }
|
||||
|
||||
|
||||
InnerAtRequest ::= SEQUENCE {
|
||||
publicKeys PublicKeys,
|
||||
hmacKey OCTET STRING (SIZE(32)),
|
||||
sharedAtRequest SharedAtRequest,
|
||||
ecSignature EcSignature,
|
||||
...
|
||||
}
|
||||
|
||||
SharedAtRequest ::= SEQUENCE {
|
||||
eaId HashedId8,
|
||||
keyTag OCTET STRING (SIZE(16)),
|
||||
certificateFormat CertificateFormat,
|
||||
requestedSubjectAttributes CertificateSubjectAttributes (WITH COMPONENTS{..., certIssuePermissions ABSENT}),
|
||||
...
|
||||
}
|
||||
|
||||
InnerAtResponse ::= SEQUENCE {
|
||||
requestHash OCTET STRING (SIZE(16)),
|
||||
responseCode AuthorizationResponseCode,
|
||||
certificate EtsiTs103097Certificate OPTIONAL,
|
||||
...
|
||||
}
|
||||
(WITH COMPONENTS { responseCode (ok), certificate PRESENT }
|
||||
| WITH COMPONENTS { responseCode (ALL EXCEPT ok), certificate ABSENT }
|
||||
)
|
||||
|
||||
EtsiTs102941ButterflyAuthorizationRequest-X509Signed ::= Ieee1609Dot2Data-SignedX509AuthenticatedCertRequest {
|
||||
ScmsPdu-Scoped {
|
||||
EeRaInterfacePdu (WITH COMPONENTS {
|
||||
eeRaCertRequest})
|
||||
},
|
||||
SignerSingleX509Cert
|
||||
}
|
||||
|
||||
END
|
||||
Vendored
+63
@@ -0,0 +1,63 @@
|
||||
EtsiTs102941TypesAuthorizationValidation
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authValidation(7) major-version-3(3) minor-version-1(1)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Certificate
|
||||
FROM EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
CertificateFormat, CertificateSubjectAttributes,EcSignature, HashedId8, PublicKeys, Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
SharedAtRequest
|
||||
FROM EtsiTs102941TypesAuthorization
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) authorization(5) major-version-3(3) minor-version-2(2) }
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- AuthorizationValidationRequest/Response
|
||||
************/
|
||||
|
||||
AuthorizationValidationResponseCode ::= ENUMERATED {
|
||||
ok(0),
|
||||
cantparse, -- valid for any structure
|
||||
badcontenttype, -- not encrypted, not signed, not permissionsverificationrequest
|
||||
imnottherecipient, -- the "recipients" of the outermost encrypted data doesn't include me
|
||||
unknownencryptionalgorithm, -- either kexalg or contentencryptionalgorithm
|
||||
decryptionfailed, -- works for ECIES-HMAC and AES-CCM
|
||||
invalidaa, -- the AA certificate presented is invalid/revoked/whatever
|
||||
invalidaasignature, -- the AA certificate presented can't validate the request signature
|
||||
wrongea, -- the encrypted signature doesn't designate me as the EA
|
||||
unknownits, -- can't retrieve the EC/ITS in my DB
|
||||
invalidsignature, -- signature verification of the request by the EC fails
|
||||
invalidencryptionkey, -- signature is good, but the responseEncryptionKey is bad
|
||||
deniedpermissions, -- requested permissions not granted
|
||||
deniedtoomanycerts, -- parallel limit
|
||||
deniedrequest, -- any other reason?
|
||||
... }
|
||||
|
||||
AuthorizationValidationRequest ::= SEQUENCE {
|
||||
sharedAtRequest SharedAtRequest,
|
||||
ecSignature EcSignature,
|
||||
...
|
||||
}
|
||||
|
||||
AuthorizationValidationResponse ::= SEQUENCE {
|
||||
requestHash OCTET STRING (SIZE(16)),
|
||||
responseCode AuthorizationValidationResponseCode,
|
||||
confirmedSubjectAttributes CertificateSubjectAttributes (WITH COMPONENTS{..., certIssuePermissions ABSENT}) OPTIONAL,
|
||||
...
|
||||
}
|
||||
(WITH COMPONENTS { responseCode (ok), confirmedSubjectAttributes PRESENT }
|
||||
| WITH COMPONENTS { responseCode (ALL EXCEPT ok), confirmedSubjectAttributes ABSENT }
|
||||
)
|
||||
|
||||
END
|
||||
+31
@@ -0,0 +1,31 @@
|
||||
EtsiTs102941TypesCaManagement
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) caManagement(8) major-version-3(3) minor-version-1(1)}
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Certificate, EtsiTs103097Data-Signed
|
||||
FROM
|
||||
EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
PublicKeys, CertificateSubjectAttributes
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- CA certificate request
|
||||
************/
|
||||
|
||||
CaCertificateRequest ::= SEQUENCE {
|
||||
publicKeys PublicKeys,
|
||||
requestedSubjectAttributes CertificateSubjectAttributes,
|
||||
...
|
||||
}
|
||||
|
||||
END
|
||||
+62
@@ -0,0 +1,62 @@
|
||||
EtsiTs102941TypesEnrolment
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) enrolment(4) major-version-3(3) minor-version-1(1) }
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
EtsiTs103097Certificate,
|
||||
EtsiTs103097Data-Signed
|
||||
FROM EtsiTs103097Module
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) secHeaders(103097) core(1) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
|
||||
CertificateFormat, CertificateSubjectAttributes, EcSignature, HashedId8, PublicKeys, Version
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1) }
|
||||
WITH SUCCESSORS
|
||||
;
|
||||
|
||||
/************
|
||||
-- EnrolmentRequest/Response
|
||||
************/
|
||||
|
||||
EnrolmentResponseCode ::= ENUMERATED {
|
||||
ok(0),
|
||||
cantparse, -- valid for any structure
|
||||
badcontenttype, -- not encrypted, not signed, not enrolmentrequest
|
||||
imnottherecipient, -- the "recipients" doesn't include me
|
||||
unknownencryptionalgorithm, -- either kexalg or contentencryptionalgorithm
|
||||
decryptionfailed, -- works for ECIES-HMAC and AES-CCM
|
||||
unknownits, -- can't retrieve the ITS from the itsId
|
||||
invalidsignature, -- signature verification of the request fails
|
||||
invalidencryptionkey, -- signature is good, but the responseEncryptionKey is bad
|
||||
baditsstatus, -- revoked, not yet active
|
||||
incompleterequest, -- some elements are missing
|
||||
deniedpermissions, -- requested permissions are not granted
|
||||
invalidkeys, -- either the verification_key of the encryption_key is bad
|
||||
deniedrequest, -- any other reason?
|
||||
... }
|
||||
|
||||
InnerEcRequestSignedForPop::= EtsiTs103097Data-Signed{InnerEcRequest}
|
||||
|
||||
InnerEcRequest ::= SEQUENCE {
|
||||
itsId OCTET STRING,
|
||||
certificateFormat CertificateFormat,
|
||||
publicKeys PublicKeys,
|
||||
requestedSubjectAttributes CertificateSubjectAttributes (WITH COMPONENTS{..., certIssuePermissions ABSENT}),
|
||||
...
|
||||
}
|
||||
|
||||
InnerEcResponse ::= SEQUENCE {
|
||||
requestHash OCTET STRING (SIZE(16)),
|
||||
responseCode EnrolmentResponseCode,
|
||||
certificate EtsiTs103097Certificate OPTIONAL,
|
||||
...
|
||||
}
|
||||
(WITH COMPONENTS { responseCode (ok), certificate PRESENT }
|
||||
| WITH COMPONENTS { responseCode (ALL EXCEPT ok), certificate ABSENT }
|
||||
)
|
||||
|
||||
END
|
||||
+30
@@ -0,0 +1,30 @@
|
||||
EtsiTs102941TypesLinkCertificate
|
||||
{ itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) linkCertificate(9) major-version-3(3) minor-version-1(1) }
|
||||
|
||||
DEFINITIONS AUTOMATIC TAGS ::=
|
||||
BEGIN
|
||||
|
||||
IMPORTS
|
||||
|
||||
Time32, HashedData
|
||||
FROM EtsiTs102941BaseTypes
|
||||
{itu-t(0) identified-organization(4) etsi(0) itsDomain(5) wg5(5) ts(102941) baseTypes(3) major-version-3(3) minor-version-1(1)}
|
||||
WITH SUCCESSORS
|
||||
|
||||
;
|
||||
|
||||
/************
|
||||
-- Link certificate messages
|
||||
************/
|
||||
|
||||
ToBeSignedLinkCertificate ::= SEQUENCE {
|
||||
expiryTime Time32,
|
||||
certificateHash HashedData,
|
||||
...
|
||||
}
|
||||
|
||||
ToBeSignedLinkCertificateTlm ::= ToBeSignedLinkCertificate
|
||||
ToBeSignedLinkCertificateRca ::= ToBeSignedLinkCertificate
|
||||
|
||||
END
|
||||
|
||||
Reference in New Issue
Block a user