Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but that tree was gitignored, so a clone of this repository could not build the firmware it ships. It is now committed here as ordinary files in its own folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP bridge's signature verification (--trust) used on the bench. Nothing is fetched from or pushed to the colleague's repository; this repository and its remotes carry everything. The folder's own .gitignore keeps build output, downloaded components and private key material out, as it did there; the committed file set is identical to that repository's tracked files. The ESP32-C5 is still flashed from obu-firmware/, which only takes vanetza-idf from microbu-esp32c5/, so the two stay separate folders. FLASHING.md says how to take a newer version of the colleague's tree (copy it over the folder, rebuild, test, commit).
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
db573e93234e36675bbdb49837b1c4d418029924973834525206c15f7f5fb08a private/UML_L0_RCA_private_encrypted.pem
|
||||
cd86499c5a5c48f82abd9424b0d8534a4e7a57761a7af189a998ee4387b07ec3 rca/AFD566A8034ED5DB_0_Urban-Mobility-Lab-Root-CA_L0_2026-09-11.txt
|
||||
7168e341764188e140ef591634a9d2488d7fdacda667ee53afd566a8034ed5db rca/AFD566A8034ED5DB.oer
|
||||
b75c6bac678f3a2351eebe74330fa9739428540cc3d8d439255f87cdf77febda rca/certificate_report.json
|
||||
6fbfc8c9e03610ece1dfd27f2edc63f3b1cf96237f26aa93e9e044eabeffb1e9 rca/UML_L0_RCA_public.pem
|
||||
36734132bcdd7b72068ee1ea2db2c38aa977066c2896f85c31a5249580e473b3 README.txt
|
||||
832aec95189f06b8813da7dcd3835c1471d6af1def110fc33b46829a0681c555 reference-generator/create_new_root.py
|
||||
4cb9fa6982d1f5bfa8a1495e97786df5543944e20a336fcd2899f151969e9b47 reference-generator/PROVENANCE.txt
|
||||
cdf955c247b4cbb9bb71f419fe087abbf3e8aa91fc51e02e8c882b952ff82e16 reference-generator/README.md
|
||||
fb833826404e5ba5f6643cf1d7113e280859155a0c84c693d47599f223f49b49 reference-generator/rebuild_registered_rca.py
|
||||
c821c147d786634f38e02d7c4750da0814d1b9487c8f030ac386589c81617e77 reference-generator/src/create_new_root.rs
|
||||
57e5aa94540e00e8d6cd9691cddc8672d8a9af3bdaed3dde386a0233682965f7 reference-generator/src/generate_root.rs
|
||||
@@ -0,0 +1,52 @@
|
||||
Urban Mobility Lab L0 RCA
|
||||
|
||||
!!THIS ROOT MUST NOT BE REGENERATED OR REPLACED.!!
|
||||
|
||||
The EU CCMS L0 ECTL registration is tied to this exact certificate and key:
|
||||
|
||||
certificate rca/AFD566A8034ED5DB.oer
|
||||
HashedId8 AFD566A8034ED5DB
|
||||
private key private/UML_L0_RCA_private_encrypted.pem
|
||||
algorithm NIST P-256; encrypted PKCS#8 PEM
|
||||
valid 2026-09-14 23:59:55 UTC through 2031-09-15
|
||||
|
||||
The certificate was submitted on 2026-09-11 and registered in the EU signing
|
||||
session on 2026-09-14. The private-key passphrase is in the separate physical
|
||||
envelope. Never put the key or passphrase in Git, cloud storage, Chat or email. If the key or passphrase is lost, contact the EU CCMS CPOC
|
||||
for revocation/re-keying; creating another local root will not restore this identity.
|
||||
|
||||
Files:
|
||||
|
||||
rca/AFD566A8034ED5DB.oer registered public COER certificate
|
||||
rca/UML_L0_RCA_public.pem matching public key
|
||||
rca/certificate_report.json decoded permissions/profile
|
||||
rca/*_2026-09-11.txt submitted descriptive information
|
||||
private/*.pem encrypted private key; keep offline
|
||||
reference-generator/ pinned Rust/c-its reproduction path
|
||||
CHECKSUMS.sha256 integrity values for the files above
|
||||
|
||||
The two workflows in `reference-generator/README.md` are intentionally separate:
|
||||
one reproduces the registered certificate with its registered key, the other creates
|
||||
a new, unregistered root key and candidate certificate for testing or a deliberate
|
||||
EU registration/re-key process.
|
||||
|
||||
Routine use:
|
||||
|
||||
Use the `vidf_issue` tool. Run these commands from this directory;
|
||||
OpenSSL asks for the root passphrase interactively.
|
||||
|
||||
vidf_issue show rca/AFD566A8034ED5DB.oer
|
||||
vidf_issue verify rca/AFD566A8034ED5DB.oer
|
||||
vidf_issue authority --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --name "Urban Mobility Lab L0 AA" --id UML_AA --years 3 --out chain
|
||||
vidf_issue ticket --issuer chain/UML_AA.oer --issuer-key chain/UML_AA.vkey --root rca/AFD566A8034ED5DB.oer --id UML_AT --hours 24 --permission 638:01 --permission 141 --permission 36:01FFFC --out chain
|
||||
vidf_issue verify chain/UML_AT.oer chain/UML_AA.oer rca/AFD566A8034ED5DB.oer
|
||||
|
||||
The `.vkey` files created in `chain/` are unencrypted private keys. Keep them
|
||||
offline and delete them when no longer required. Tickets last 24 hours by default.
|
||||
|
||||
Distribution lists:
|
||||
|
||||
vidf_issue ctl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --aa chain/UML_AA.oer=https://cits-dc.uml-hamburg.de/aa/ --dc https://cits-dc.uml-hamburg.de/ --sequence 1 --out lists/ctl-AFD566A8034ED5DB.oer
|
||||
vidf_issue crl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --out lists/crl-AFD566A8034ED5DB.oer
|
||||
|
||||
Increase the CTL sequence for every update. Reissue the CTL whenever the AA changes.
|
||||
@@ -0,0 +1,853 @@
|
||||
This file contains copies of the GNU Lesser General Public License as well
|
||||
as the GNU General Public License, both in their third version.
|
||||
|
||||
|
||||
# GNU Lesser General Public License (LGPL) v3
|
||||
|
||||
```
|
||||
GNU LESSER GENERAL PUBLIC LICENSE
|
||||
Version 3, 29 June 2007
|
||||
|
||||
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
|
||||
This version of the GNU Lesser General Public License incorporates
|
||||
the terms and conditions of version 3 of the GNU General Public
|
||||
License, supplemented by the additional permissions listed below.
|
||||
|
||||
0. Additional Definitions.
|
||||
|
||||
As used herein, "this License" refers to version 3 of the GNU Lesser
|
||||
General Public License, and the "GNU GPL" refers to version 3 of the GNU
|
||||
General Public License.
|
||||
|
||||
"The Library" refers to a covered work governed by this License,
|
||||
other than an Application or a Combined Work as defined below.
|
||||
|
||||
An "Application" is any work that makes use of an interface provided
|
||||
by the Library, but which is not otherwise based on the Library.
|
||||
Defining a subclass of a class defined by the Library is deemed a mode
|
||||
of using an interface provided by the Library.
|
||||
|
||||
A "Combined Work" is a work produced by combining or linking an
|
||||
Application with the Library. The particular version of the Library
|
||||
with which the Combined Work was made is also called the "Linked
|
||||
Version".
|
||||
|
||||
The "Minimal Corresponding Source" for a Combined Work means the
|
||||
Corresponding Source for the Combined Work, excluding any source code
|
||||
for portions of the Combined Work that, considered in isolation, are
|
||||
based on the Application, and not on the Linked Version.
|
||||
|
||||
The "Corresponding Application Code" for a Combined Work means the
|
||||
object code and/or source code for the Application, including any data
|
||||
and utility programs needed for reproducing the Combined Work from the
|
||||
Application, but excluding the System Libraries of the Combined Work.
|
||||
|
||||
1. Exception to Section 3 of the GNU GPL.
|
||||
|
||||
You may convey a covered work under sections 3 and 4 of this License
|
||||
without being bound by section 3 of the GNU GPL.
|
||||
|
||||
2. Conveying Modified Versions.
|
||||
|
||||
If you modify a copy of the Library, and, in your modifications, a
|
||||
facility refers to a function or data to be supplied by an Application
|
||||
that uses the facility (other than as an argument passed when the
|
||||
facility is invoked), then you may convey a copy of the modified
|
||||
version:
|
||||
|
||||
a) under this License, provided that you make a good faith effort to
|
||||
ensure that, in the event an Application does not supply the
|
||||
function or data, the facility still operates, and performs
|
||||
whatever part of its purpose remains meaningful, or
|
||||
|
||||
b) under the GNU GPL, with none of the additional permissions of
|
||||
this License applicable to that copy.
|
||||
|
||||
3. Object Code Incorporating Material from Library Header Files.
|
||||
|
||||
The object code form of an Application may incorporate material from
|
||||
a header file that is part of the Library. You may convey such object
|
||||
code under terms of your choice, provided that, if the incorporated
|
||||
material is not limited to numerical parameters, data structure
|
||||
layouts and accessors, or small macros, inline functions and templates
|
||||
(ten or fewer lines in length), you do both of the following:
|
||||
|
||||
a) Give prominent notice with each copy of the object code that the
|
||||
Library is used in it and that the Library and its use are
|
||||
covered by this License.
|
||||
|
||||
b) Accompany the object code with a copy of the GNU GPL and this license
|
||||
document.
|
||||
|
||||
4. Combined Works.
|
||||
|
||||
You may convey a Combined Work under terms of your choice that,
|
||||
taken together, effectively do not restrict modification of the
|
||||
portions of the Library contained in the Combined Work and reverse
|
||||
engineering for debugging such modifications, if you also do each of
|
||||
the following:
|
||||
|
||||
a) Give prominent notice with each copy of the Combined Work that
|
||||
the Library is used in it and that the Library and its use are
|
||||
covered by this License.
|
||||
|
||||
b) Accompany the Combined Work with a copy of the GNU GPL and this license
|
||||
document.
|
||||
|
||||
c) For a Combined Work that displays copyright notices during
|
||||
execution, include the copyright notice for the Library among
|
||||
these notices, as well as a reference directing the user to the
|
||||
copies of the GNU GPL and this license document.
|
||||
|
||||
d) Do one of the following:
|
||||
|
||||
0) Convey the Minimal Corresponding Source under the terms of this
|
||||
License, and the Corresponding Application Code in a form
|
||||
suitable for, and under terms that permit, the user to
|
||||
recombine or relink the Application with a modified version of
|
||||
the Linked Version to produce a modified Combined Work, in the
|
||||
manner specified by section 6 of the GNU GPL for conveying
|
||||
Corresponding Source.
|
||||
|
||||
1) Use a suitable shared library mechanism for linking with the
|
||||
Library. A suitable mechanism is one that (a) uses at run time
|
||||
a copy of the Library already present on the user's computer
|
||||
system, and (b) will operate properly with a modified version
|
||||
of the Library that is interface-compatible with the Linked
|
||||
Version.
|
||||
|
||||
e) Provide Installation Information, but only if you would otherwise
|
||||
be required to provide such information under section 6 of the
|
||||
GNU GPL, and only to the extent that such information is
|
||||
necessary to install and execute a modified version of the
|
||||
Combined Work produced by recombining or relinking the
|
||||
Application with a modified version of the Linked Version. (If
|
||||
you use option 4d0, the Installation Information must accompany
|
||||
the Minimal Corresponding Source and Corresponding Application
|
||||
Code. If you use option 4d1, you must provide the Installation
|
||||
Information in the manner specified by section 6 of the GNU GPL
|
||||
for conveying Corresponding Source.)
|
||||
|
||||
5. Combined Libraries.
|
||||
|
||||
You may place library facilities that are a work based on the
|
||||
Library side by side in a single library together with other library
|
||||
facilities that are not Applications and are not covered by this
|
||||
License, and convey such a combined library under terms of your
|
||||
choice, if you do both of the following:
|
||||
|
||||
a) Accompany the combined library with a copy of the same work based
|
||||
on the Library, uncombined with any other library facilities,
|
||||
conveyed under the terms of this License.
|
||||
|
||||
b) Give prominent notice with the combined library that part of it
|
||||
is a work based on the Library, and explaining where to find the
|
||||
accompanying uncombined form of the same work.
|
||||
|
||||
6. Revised Versions of the GNU Lesser General Public License.
|
||||
|
||||
The Free Software Foundation may publish revised and/or new versions
|
||||
of the GNU Lesser General Public License from time to time. Such new
|
||||
versions will be similar in spirit to the present version, but may
|
||||
differ in detail to address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the
|
||||
Library as you received it specifies that a certain numbered version
|
||||
of the GNU Lesser General Public License "or any later version"
|
||||
applies to it, you have the option of following the terms and
|
||||
conditions either of that published version or of any later version
|
||||
published by the Free Software Foundation. If the Library as you
|
||||
received it does not specify a version number of the GNU Lesser
|
||||
General Public License, you may choose any version of the GNU Lesser
|
||||
General Public License ever published by the Free Software Foundation.
|
||||
|
||||
If the Library as you received it specifies that a proxy can decide
|
||||
whether future versions of the GNU Lesser General Public License shall
|
||||
apply, that proxy's public statement of acceptance of any version is
|
||||
permanent authorization for you to choose that version for the
|
||||
Library.
|
||||
```
|
||||
|
||||
|
||||
# GNU General Public License (GPL) v3
|
||||
|
||||
```
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
Version 3, 29 June 2007
|
||||
|
||||
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The GNU General Public License is a free, copyleft license for
|
||||
software and other kinds of works.
|
||||
|
||||
The licenses for most software and other practical works are designed
|
||||
to take away your freedom to share and change the works. By contrast,
|
||||
the GNU General Public License is intended to guarantee your freedom to
|
||||
share and change all versions of a program--to make sure it remains free
|
||||
software for all its users. We, the Free Software Foundation, use the
|
||||
GNU General Public License for most of our software; it applies also to
|
||||
any other work released this way by its authors. You can apply it to
|
||||
your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
price. Our General Public Licenses are designed to make sure that you
|
||||
have the freedom to distribute copies of free software (and charge for
|
||||
them if you wish), that you receive source code or can get it if you
|
||||
want it, that you can change the software or use pieces of it in new
|
||||
free programs, and that you know you can do these things.
|
||||
|
||||
To protect your rights, we need to prevent others from denying you
|
||||
these rights or asking you to surrender the rights. Therefore, you have
|
||||
certain responsibilities if you distribute copies of the software, or if
|
||||
you modify it: responsibilities to respect the freedom of others.
|
||||
|
||||
For example, if you distribute copies of such a program, whether
|
||||
gratis or for a fee, you must pass on to the recipients the same
|
||||
freedoms that you received. You must make sure that they, too, receive
|
||||
or can get the source code. And you must show them these terms so they
|
||||
know their rights.
|
||||
|
||||
Developers that use the GNU GPL protect your rights with two steps:
|
||||
(1) assert copyright on the software, and (2) offer you this License
|
||||
giving you legal permission to copy, distribute and/or modify it.
|
||||
|
||||
For the developers' and authors' protection, the GPL clearly explains
|
||||
that there is no warranty for this free software. For both users' and
|
||||
authors' sake, the GPL requires that modified versions be marked as
|
||||
changed, so that their problems will not be attributed erroneously to
|
||||
authors of previous versions.
|
||||
|
||||
Some devices are designed to deny users access to install or run
|
||||
modified versions of the software inside them, although the manufacturer
|
||||
can do so. This is fundamentally incompatible with the aim of
|
||||
protecting users' freedom to change the software. The systematic
|
||||
pattern of such abuse occurs in the area of products for individuals to
|
||||
use, which is precisely where it is most unacceptable. Therefore, we
|
||||
have designed this version of the GPL to prohibit the practice for those
|
||||
products. If such problems arise substantially in other domains, we
|
||||
stand ready to extend this provision to those domains in future versions
|
||||
of the GPL, as needed to protect the freedom of users.
|
||||
|
||||
Finally, every program is threatened constantly by software patents.
|
||||
States should not allow patents to restrict development and use of
|
||||
software on general-purpose computers, but in those that do, we wish to
|
||||
avoid the special danger that patents applied to a free program could
|
||||
make it effectively proprietary. To prevent this, the GPL assures that
|
||||
patents cannot be used to render the program non-free.
|
||||
|
||||
The precise terms and conditions for copying, distribution and
|
||||
modification follow.
|
||||
|
||||
TERMS AND CONDITIONS
|
||||
|
||||
0. Definitions.
|
||||
|
||||
"This License" refers to version 3 of the GNU General Public License.
|
||||
|
||||
"Copyright" also means copyright-like laws that apply to other kinds of
|
||||
works, such as semiconductor masks.
|
||||
|
||||
"The Program" refers to any copyrightable work licensed under this
|
||||
License. Each licensee is addressed as "you". "Licensees" and
|
||||
"recipients" may be individuals or organizations.
|
||||
|
||||
To "modify" a work means to copy from or adapt all or part of the work
|
||||
in a fashion requiring copyright permission, other than the making of an
|
||||
exact copy. The resulting work is called a "modified version" of the
|
||||
earlier work or a work "based on" the earlier work.
|
||||
|
||||
A "covered work" means either the unmodified Program or a work based
|
||||
on the Program.
|
||||
|
||||
To "propagate" a work means to do anything with it that, without
|
||||
permission, would make you directly or secondarily liable for
|
||||
infringement under applicable copyright law, except executing it on a
|
||||
computer or modifying a private copy. Propagation includes copying,
|
||||
distribution (with or without modification), making available to the
|
||||
public, and in some countries other activities as well.
|
||||
|
||||
To "convey" a work means any kind of propagation that enables other
|
||||
parties to make or receive copies. Mere interaction with a user through
|
||||
a computer network, with no transfer of a copy, is not conveying.
|
||||
|
||||
An interactive user interface displays "Appropriate Legal Notices"
|
||||
to the extent that it includes a convenient and prominently visible
|
||||
feature that (1) displays an appropriate copyright notice, and (2)
|
||||
tells the user that there is no warranty for the work (except to the
|
||||
extent that warranties are provided), that licensees may convey the
|
||||
work under this License, and how to view a copy of this License. If
|
||||
the interface presents a list of user commands or options, such as a
|
||||
menu, a prominent item in the list meets this criterion.
|
||||
|
||||
1. Source Code.
|
||||
|
||||
The "source code" for a work means the preferred form of the work
|
||||
for making modifications to it. "Object code" means any non-source
|
||||
form of a work.
|
||||
|
||||
A "Standard Interface" means an interface that either is an official
|
||||
standard defined by a recognized standards body, or, in the case of
|
||||
interfaces specified for a particular programming language, one that
|
||||
is widely used among developers working in that language.
|
||||
|
||||
The "System Libraries" of an executable work include anything, other
|
||||
than the work as a whole, that (a) is included in the normal form of
|
||||
packaging a Major Component, but which is not part of that Major
|
||||
Component, and (b) serves only to enable use of the work with that
|
||||
Major Component, or to implement a Standard Interface for which an
|
||||
implementation is available to the public in source code form. A
|
||||
"Major Component", in this context, means a major essential component
|
||||
(kernel, window system, and so on) of the specific operating system
|
||||
(if any) on which the executable work runs, or a compiler used to
|
||||
produce the work, or an object code interpreter used to run it.
|
||||
|
||||
The "Corresponding Source" for a work in object code form means all
|
||||
the source code needed to generate, install, and (for an executable
|
||||
work) run the object code and to modify the work, including scripts to
|
||||
control those activities. However, it does not include the work's
|
||||
System Libraries, or general-purpose tools or generally available free
|
||||
programs which are used unmodified in performing those activities but
|
||||
which are not part of the work. For example, Corresponding Source
|
||||
includes interface definition files associated with source files for
|
||||
the work, and the source code for shared libraries and dynamically
|
||||
linked subprograms that the work is specifically designed to require,
|
||||
such as by intimate data communication or control flow between those
|
||||
subprograms and other parts of the work.
|
||||
|
||||
The Corresponding Source need not include anything that users
|
||||
can regenerate automatically from other parts of the Corresponding
|
||||
Source.
|
||||
|
||||
The Corresponding Source for a work in source code form is that
|
||||
same work.
|
||||
|
||||
2. Basic Permissions.
|
||||
|
||||
All rights granted under this License are granted for the term of
|
||||
copyright on the Program, and are irrevocable provided the stated
|
||||
conditions are met. This License explicitly affirms your unlimited
|
||||
permission to run the unmodified Program. The output from running a
|
||||
covered work is covered by this License only if the output, given its
|
||||
content, constitutes a covered work. This License acknowledges your
|
||||
rights of fair use or other equivalent, as provided by copyright law.
|
||||
|
||||
You may make, run and propagate covered works that you do not
|
||||
convey, without conditions so long as your license otherwise remains
|
||||
in force. You may convey covered works to others for the sole purpose
|
||||
of having them make modifications exclusively for you, or provide you
|
||||
with facilities for running those works, provided that you comply with
|
||||
the terms of this License in conveying all material for which you do
|
||||
not control copyright. Those thus making or running the covered works
|
||||
for you must do so exclusively on your behalf, under your direction
|
||||
and control, on terms that prohibit them from making any copies of
|
||||
your copyrighted material outside their relationship with you.
|
||||
|
||||
Conveying under any other circumstances is permitted solely under
|
||||
the conditions stated below. Sublicensing is not allowed; section 10
|
||||
makes it unnecessary.
|
||||
|
||||
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
||||
|
||||
No covered work shall be deemed part of an effective technological
|
||||
measure under any applicable law fulfilling obligations under article
|
||||
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
||||
similar laws prohibiting or restricting circumvention of such
|
||||
measures.
|
||||
|
||||
When you convey a covered work, you waive any legal power to forbid
|
||||
circumvention of technological measures to the extent such circumvention
|
||||
is effected by exercising rights under this License with respect to
|
||||
the covered work, and you disclaim any intention to limit operation or
|
||||
modification of the work as a means of enforcing, against the work's
|
||||
users, your or third parties' legal rights to forbid circumvention of
|
||||
technological measures.
|
||||
|
||||
4. Conveying Verbatim Copies.
|
||||
|
||||
You may convey verbatim copies of the Program's source code as you
|
||||
receive it, in any medium, provided that you conspicuously and
|
||||
appropriately publish on each copy an appropriate copyright notice;
|
||||
keep intact all notices stating that this License and any
|
||||
non-permissive terms added in accord with section 7 apply to the code;
|
||||
keep intact all notices of the absence of any warranty; and give all
|
||||
recipients a copy of this License along with the Program.
|
||||
|
||||
You may charge any price or no price for each copy that you convey,
|
||||
and you may offer support or warranty protection for a fee.
|
||||
|
||||
5. Conveying Modified Source Versions.
|
||||
|
||||
You may convey a work based on the Program, or the modifications to
|
||||
produce it from the Program, in the form of source code under the
|
||||
terms of section 4, provided that you also meet all of these conditions:
|
||||
|
||||
a) The work must carry prominent notices stating that you modified
|
||||
it, and giving a relevant date.
|
||||
|
||||
b) The work must carry prominent notices stating that it is
|
||||
released under this License and any conditions added under section
|
||||
7. This requirement modifies the requirement in section 4 to
|
||||
"keep intact all notices".
|
||||
|
||||
c) You must license the entire work, as a whole, under this
|
||||
License to anyone who comes into possession of a copy. This
|
||||
License will therefore apply, along with any applicable section 7
|
||||
additional terms, to the whole of the work, and all its parts,
|
||||
regardless of how they are packaged. This License gives no
|
||||
permission to license the work in any other way, but it does not
|
||||
invalidate such permission if you have separately received it.
|
||||
|
||||
d) If the work has interactive user interfaces, each must display
|
||||
Appropriate Legal Notices; however, if the Program has interactive
|
||||
interfaces that do not display Appropriate Legal Notices, your
|
||||
work need not make them do so.
|
||||
|
||||
A compilation of a covered work with other separate and independent
|
||||
works, which are not by their nature extensions of the covered work,
|
||||
and which are not combined with it such as to form a larger program,
|
||||
in or on a volume of a storage or distribution medium, is called an
|
||||
"aggregate" if the compilation and its resulting copyright are not
|
||||
used to limit the access or legal rights of the compilation's users
|
||||
beyond what the individual works permit. Inclusion of a covered work
|
||||
in an aggregate does not cause this License to apply to the other
|
||||
parts of the aggregate.
|
||||
|
||||
6. Conveying Non-Source Forms.
|
||||
|
||||
You may convey a covered work in object code form under the terms
|
||||
of sections 4 and 5, provided that you also convey the
|
||||
machine-readable Corresponding Source under the terms of this License,
|
||||
in one of these ways:
|
||||
|
||||
a) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by the
|
||||
Corresponding Source fixed on a durable physical medium
|
||||
customarily used for software interchange.
|
||||
|
||||
b) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by a
|
||||
written offer, valid for at least three years and valid for as
|
||||
long as you offer spare parts or customer support for that product
|
||||
model, to give anyone who possesses the object code either (1) a
|
||||
copy of the Corresponding Source for all the software in the
|
||||
product that is covered by this License, on a durable physical
|
||||
medium customarily used for software interchange, for a price no
|
||||
more than your reasonable cost of physically performing this
|
||||
conveying of source, or (2) access to copy the
|
||||
Corresponding Source from a network server at no charge.
|
||||
|
||||
c) Convey individual copies of the object code with a copy of the
|
||||
written offer to provide the Corresponding Source. This
|
||||
alternative is allowed only occasionally and noncommercially, and
|
||||
only if you received the object code with such an offer, in accord
|
||||
with subsection 6b.
|
||||
|
||||
d) Convey the object code by offering access from a designated
|
||||
place (gratis or for a charge), and offer equivalent access to the
|
||||
Corresponding Source in the same way through the same place at no
|
||||
further charge. You need not require recipients to copy the
|
||||
Corresponding Source along with the object code. If the place to
|
||||
copy the object code is a network server, the Corresponding Source
|
||||
may be on a different server (operated by you or a third party)
|
||||
that supports equivalent copying facilities, provided you maintain
|
||||
clear directions next to the object code saying where to find the
|
||||
Corresponding Source. Regardless of what server hosts the
|
||||
Corresponding Source, you remain obligated to ensure that it is
|
||||
available for as long as needed to satisfy these requirements.
|
||||
|
||||
e) Convey the object code using peer-to-peer transmission, provided
|
||||
you inform other peers where the object code and Corresponding
|
||||
Source of the work are being offered to the general public at no
|
||||
charge under subsection 6d.
|
||||
|
||||
A separable portion of the object code, whose source code is excluded
|
||||
from the Corresponding Source as a System Library, need not be
|
||||
included in conveying the object code work.
|
||||
|
||||
A "User Product" is either (1) a "consumer product", which means any
|
||||
tangible personal property which is normally used for personal, family,
|
||||
or household purposes, or (2) anything designed or sold for incorporation
|
||||
into a dwelling. In determining whether a product is a consumer product,
|
||||
doubtful cases shall be resolved in favor of coverage. For a particular
|
||||
product received by a particular user, "normally used" refers to a
|
||||
typical or common use of that class of product, regardless of the status
|
||||
of the particular user or of the way in which the particular user
|
||||
actually uses, or expects or is expected to use, the product. A product
|
||||
is a consumer product regardless of whether the product has substantial
|
||||
commercial, industrial or non-consumer uses, unless such uses represent
|
||||
the only significant mode of use of the product.
|
||||
|
||||
"Installation Information" for a User Product means any methods,
|
||||
procedures, authorization keys, or other information required to install
|
||||
and execute modified versions of a covered work in that User Product from
|
||||
a modified version of its Corresponding Source. The information must
|
||||
suffice to ensure that the continued functioning of the modified object
|
||||
code is in no case prevented or interfered with solely because
|
||||
modification has been made.
|
||||
|
||||
If you convey an object code work under this section in, or with, or
|
||||
specifically for use in, a User Product, and the conveying occurs as
|
||||
part of a transaction in which the right of possession and use of the
|
||||
User Product is transferred to the recipient in perpetuity or for a
|
||||
fixed term (regardless of how the transaction is characterized), the
|
||||
Corresponding Source conveyed under this section must be accompanied
|
||||
by the Installation Information. But this requirement does not apply
|
||||
if neither you nor any third party retains the ability to install
|
||||
modified object code on the User Product (for example, the work has
|
||||
been installed in ROM).
|
||||
|
||||
The requirement to provide Installation Information does not include a
|
||||
requirement to continue to provide support service, warranty, or updates
|
||||
for a work that has been modified or installed by the recipient, or for
|
||||
the User Product in which it has been modified or installed. Access to a
|
||||
network may be denied when the modification itself materially and
|
||||
adversely affects the operation of the network or violates the rules and
|
||||
protocols for communication across the network.
|
||||
|
||||
Corresponding Source conveyed, and Installation Information provided,
|
||||
in accord with this section must be in a format that is publicly
|
||||
documented (and with an implementation available to the public in
|
||||
source code form), and must require no special password or key for
|
||||
unpacking, reading or copying.
|
||||
|
||||
7. Additional Terms.
|
||||
|
||||
"Additional permissions" are terms that supplement the terms of this
|
||||
License by making exceptions from one or more of its conditions.
|
||||
Additional permissions that are applicable to the entire Program shall
|
||||
be treated as though they were included in this License, to the extent
|
||||
that they are valid under applicable law. If additional permissions
|
||||
apply only to part of the Program, that part may be used separately
|
||||
under those permissions, but the entire Program remains governed by
|
||||
this License without regard to the additional permissions.
|
||||
|
||||
When you convey a copy of a covered work, you may at your option
|
||||
remove any additional permissions from that copy, or from any part of
|
||||
it. (Additional permissions may be written to require their own
|
||||
removal in certain cases when you modify the work.) You may place
|
||||
additional permissions on material, added by you to a covered work,
|
||||
for which you have or can give appropriate copyright permission.
|
||||
|
||||
Notwithstanding any other provision of this License, for material you
|
||||
add to a covered work, you may (if authorized by the copyright holders of
|
||||
that material) supplement the terms of this License with terms:
|
||||
|
||||
a) Disclaiming warranty or limiting liability differently from the
|
||||
terms of sections 15 and 16 of this License; or
|
||||
|
||||
b) Requiring preservation of specified reasonable legal notices or
|
||||
author attributions in that material or in the Appropriate Legal
|
||||
Notices displayed by works containing it; or
|
||||
|
||||
c) Prohibiting misrepresentation of the origin of that material, or
|
||||
requiring that modified versions of such material be marked in
|
||||
reasonable ways as different from the original version; or
|
||||
|
||||
d) Limiting the use for publicity purposes of names of licensors or
|
||||
authors of the material; or
|
||||
|
||||
e) Declining to grant rights under trademark law for use of some
|
||||
trade names, trademarks, or service marks; or
|
||||
|
||||
f) Requiring indemnification of licensors and authors of that
|
||||
material by anyone who conveys the material (or modified versions of
|
||||
it) with contractual assumptions of liability to the recipient, for
|
||||
any liability that these contractual assumptions directly impose on
|
||||
those licensors and authors.
|
||||
|
||||
All other non-permissive additional terms are considered "further
|
||||
restrictions" within the meaning of section 10. If the Program as you
|
||||
received it, or any part of it, contains a notice stating that it is
|
||||
governed by this License along with a term that is a further
|
||||
restriction, you may remove that term. If a license document contains
|
||||
a further restriction but permits relicensing or conveying under this
|
||||
License, you may add to a covered work material governed by the terms
|
||||
of that license document, provided that the further restriction does
|
||||
not survive such relicensing or conveying.
|
||||
|
||||
If you add terms to a covered work in accord with this section, you
|
||||
must place, in the relevant source files, a statement of the
|
||||
additional terms that apply to those files, or a notice indicating
|
||||
where to find the applicable terms.
|
||||
|
||||
Additional terms, permissive or non-permissive, may be stated in the
|
||||
form of a separately written license, or stated as exceptions;
|
||||
the above requirements apply either way.
|
||||
|
||||
8. Termination.
|
||||
|
||||
You may not propagate or modify a covered work except as expressly
|
||||
provided under this License. Any attempt otherwise to propagate or
|
||||
modify it is void, and will automatically terminate your rights under
|
||||
this License (including any patent licenses granted under the third
|
||||
paragraph of section 11).
|
||||
|
||||
However, if you cease all violation of this License, then your
|
||||
license from a particular copyright holder is reinstated (a)
|
||||
provisionally, unless and until the copyright holder explicitly and
|
||||
finally terminates your license, and (b) permanently, if the copyright
|
||||
holder fails to notify you of the violation by some reasonable means
|
||||
prior to 60 days after the cessation.
|
||||
|
||||
Moreover, your license from a particular copyright holder is
|
||||
reinstated permanently if the copyright holder notifies you of the
|
||||
violation by some reasonable means, this is the first time you have
|
||||
received notice of violation of this License (for any work) from that
|
||||
copyright holder, and you cure the violation prior to 30 days after
|
||||
your receipt of the notice.
|
||||
|
||||
Termination of your rights under this section does not terminate the
|
||||
licenses of parties who have received copies or rights from you under
|
||||
this License. If your rights have been terminated and not permanently
|
||||
reinstated, you do not qualify to receive new licenses for the same
|
||||
material under section 10.
|
||||
|
||||
9. Acceptance Not Required for Having Copies.
|
||||
|
||||
You are not required to accept this License in order to receive or
|
||||
run a copy of the Program. Ancillary propagation of a covered work
|
||||
occurring solely as a consequence of using peer-to-peer transmission
|
||||
to receive a copy likewise does not require acceptance. However,
|
||||
nothing other than this License grants you permission to propagate or
|
||||
modify any covered work. These actions infringe copyright if you do
|
||||
not accept this License. Therefore, by modifying or propagating a
|
||||
covered work, you indicate your acceptance of this License to do so.
|
||||
|
||||
10. Automatic Licensing of Downstream Recipients.
|
||||
|
||||
Each time you convey a covered work, the recipient automatically
|
||||
receives a license from the original licensors, to run, modify and
|
||||
propagate that work, subject to this License. You are not responsible
|
||||
for enforcing compliance by third parties with this License.
|
||||
|
||||
An "entity transaction" is a transaction transferring control of an
|
||||
organization, or substantially all assets of one, or subdividing an
|
||||
organization, or merging organizations. If propagation of a covered
|
||||
work results from an entity transaction, each party to that
|
||||
transaction who receives a copy of the work also receives whatever
|
||||
licenses to the work the party's predecessor in interest had or could
|
||||
give under the previous paragraph, plus a right to possession of the
|
||||
Corresponding Source of the work from the predecessor in interest, if
|
||||
the predecessor has it or can get it with reasonable efforts.
|
||||
|
||||
You may not impose any further restrictions on the exercise of the
|
||||
rights granted or affirmed under this License. For example, you may
|
||||
not impose a license fee, royalty, or other charge for exercise of
|
||||
rights granted under this License, and you may not initiate litigation
|
||||
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
||||
any patent claim is infringed by making, using, selling, offering for
|
||||
sale, or importing the Program or any portion of it.
|
||||
|
||||
11. Patents.
|
||||
|
||||
A "contributor" is a copyright holder who authorizes use under this
|
||||
License of the Program or a work on which the Program is based. The
|
||||
work thus licensed is called the contributor's "contributor version".
|
||||
|
||||
A contributor's "essential patent claims" are all patent claims
|
||||
owned or controlled by the contributor, whether already acquired or
|
||||
hereafter acquired, that would be infringed by some manner, permitted
|
||||
by this License, of making, using, or selling its contributor version,
|
||||
but do not include claims that would be infringed only as a
|
||||
consequence of further modification of the contributor version. For
|
||||
purposes of this definition, "control" includes the right to grant
|
||||
patent sublicenses in a manner consistent with the requirements of
|
||||
this License.
|
||||
|
||||
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
||||
patent license under the contributor's essential patent claims, to
|
||||
make, use, sell, offer for sale, import and otherwise run, modify and
|
||||
propagate the contents of its contributor version.
|
||||
|
||||
In the following three paragraphs, a "patent license" is any express
|
||||
agreement or commitment, however denominated, not to enforce a patent
|
||||
(such as an express permission to practice a patent or covenant not to
|
||||
sue for patent infringement). To "grant" such a patent license to a
|
||||
party means to make such an agreement or commitment not to enforce a
|
||||
patent against the party.
|
||||
|
||||
If you convey a covered work, knowingly relying on a patent license,
|
||||
and the Corresponding Source of the work is not available for anyone
|
||||
to copy, free of charge and under the terms of this License, through a
|
||||
publicly available network server or other readily accessible means,
|
||||
then you must either (1) cause the Corresponding Source to be so
|
||||
available, or (2) arrange to deprive yourself of the benefit of the
|
||||
patent license for this particular work, or (3) arrange, in a manner
|
||||
consistent with the requirements of this License, to extend the patent
|
||||
license to downstream recipients. "Knowingly relying" means you have
|
||||
actual knowledge that, but for the patent license, your conveying the
|
||||
covered work in a country, or your recipient's use of the covered work
|
||||
in a country, would infringe one or more identifiable patents in that
|
||||
country that you have reason to believe are valid.
|
||||
|
||||
If, pursuant to or in connection with a single transaction or
|
||||
arrangement, you convey, or propagate by procuring conveyance of, a
|
||||
covered work, and grant a patent license to some of the parties
|
||||
receiving the covered work authorizing them to use, propagate, modify
|
||||
or convey a specific copy of the covered work, then the patent license
|
||||
you grant is automatically extended to all recipients of the covered
|
||||
work and works based on it.
|
||||
|
||||
A patent license is "discriminatory" if it does not include within
|
||||
the scope of its coverage, prohibits the exercise of, or is
|
||||
conditioned on the non-exercise of one or more of the rights that are
|
||||
specifically granted under this License. You may not convey a covered
|
||||
work if you are a party to an arrangement with a third party that is
|
||||
in the business of distributing software, under which you make payment
|
||||
to the third party based on the extent of your activity of conveying
|
||||
the work, and under which the third party grants, to any of the
|
||||
parties who would receive the covered work from you, a discriminatory
|
||||
patent license (a) in connection with copies of the covered work
|
||||
conveyed by you (or copies made from those copies), or (b) primarily
|
||||
for and in connection with specific products or compilations that
|
||||
contain the covered work, unless you entered into that arrangement,
|
||||
or that patent license was granted, prior to 28 March 2007.
|
||||
|
||||
Nothing in this License shall be construed as excluding or limiting
|
||||
any implied license or other defenses to infringement that may
|
||||
otherwise be available to you under applicable patent law.
|
||||
|
||||
12. No Surrender of Others' Freedom.
|
||||
|
||||
If conditions are imposed on you (whether by court order, agreement or
|
||||
otherwise) that contradict the conditions of this License, they do not
|
||||
excuse you from the conditions of this License. If you cannot convey a
|
||||
covered work so as to satisfy simultaneously your obligations under this
|
||||
License and any other pertinent obligations, then as a consequence you may
|
||||
not convey it at all. For example, if you agree to terms that obligate you
|
||||
to collect a royalty for further conveying from those to whom you convey
|
||||
the Program, the only way you could satisfy both those terms and this
|
||||
License would be to refrain entirely from conveying the Program.
|
||||
|
||||
13. Use with the GNU Affero General Public License.
|
||||
|
||||
Notwithstanding any other provision of this License, you have
|
||||
permission to link or combine any covered work with a work licensed
|
||||
under version 3 of the GNU Affero General Public License into a single
|
||||
combined work, and to convey the resulting work. The terms of this
|
||||
License will continue to apply to the part which is the covered work,
|
||||
but the special requirements of the GNU Affero General Public License,
|
||||
section 13, concerning interaction through a network will apply to the
|
||||
combination as such.
|
||||
|
||||
14. Revised Versions of this License.
|
||||
|
||||
The Free Software Foundation may publish revised and/or new versions of
|
||||
the GNU General Public License from time to time. Such new versions will
|
||||
be similar in spirit to the present version, but may differ in detail to
|
||||
address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the
|
||||
Program specifies that a certain numbered version of the GNU General
|
||||
Public License "or any later version" applies to it, you have the
|
||||
option of following the terms and conditions either of that numbered
|
||||
version or of any later version published by the Free Software
|
||||
Foundation. If the Program does not specify a version number of the
|
||||
GNU General Public License, you may choose any version ever published
|
||||
by the Free Software Foundation.
|
||||
|
||||
If the Program specifies that a proxy can decide which future
|
||||
versions of the GNU General Public License can be used, that proxy's
|
||||
public statement of acceptance of a version permanently authorizes you
|
||||
to choose that version for the Program.
|
||||
|
||||
Later license versions may give you additional or different
|
||||
permissions. However, no additional obligations are imposed on any
|
||||
author or copyright holder as a result of your choosing to follow a
|
||||
later version.
|
||||
|
||||
15. Disclaimer of Warranty.
|
||||
|
||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
||||
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
||||
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
||||
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
||||
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
||||
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
||||
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||
|
||||
16. Limitation of Liability.
|
||||
|
||||
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
||||
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
||||
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
||||
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
||||
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
||||
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
||||
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGES.
|
||||
|
||||
17. Interpretation of Sections 15 and 16.
|
||||
|
||||
If the disclaimer of warranty and limitation of liability provided
|
||||
above cannot be given local legal effect according to their terms,
|
||||
reviewing courts shall apply local law that most closely approximates
|
||||
an absolute waiver of all civil liability in connection with the
|
||||
Program, unless a warranty or assumption of liability accompanies a
|
||||
copy of the Program in return for a fee.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
How to Apply These Terms to Your New Programs
|
||||
|
||||
If you develop a new program, and you want it to be of the greatest
|
||||
possible use to the public, the best way to achieve this is to make it
|
||||
free software which everyone can redistribute and change under these terms.
|
||||
|
||||
To do so, attach the following notices to the program. It is safest
|
||||
to attach them to the start of each source file to most effectively
|
||||
state the exclusion of warranty; and each file should have at least
|
||||
the "copyright" line and a pointer to where the full notice is found.
|
||||
|
||||
<one line to give the program's name and a brief idea of what it does.>
|
||||
Copyright (C) <year> <name of author>
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
Also add information on how to contact you by electronic and paper mail.
|
||||
|
||||
If the program does terminal interaction, make it output a short
|
||||
notice like this when it starts in an interactive mode:
|
||||
|
||||
<program> Copyright (C) <year> <name of author>
|
||||
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||
This is free software, and you are welcome to redistribute it
|
||||
under certain conditions; type `show c' for details.
|
||||
|
||||
The hypothetical commands `show w' and `show c' should show the appropriate
|
||||
parts of the General Public License. Of course, your program's commands
|
||||
might be different; for a GUI interface, you would use an "about box".
|
||||
|
||||
You should also get your employer (if you work as a programmer) or school,
|
||||
if any, to sign a "copyright disclaimer" for the program, if necessary.
|
||||
For more information on this, and how to apply and follow the GNU GPL, see
|
||||
<http://www.gnu.org/licenses/>.
|
||||
|
||||
The GNU General Public License does not permit incorporating your program
|
||||
into proprietary programs. If your program is a subroutine library, you
|
||||
may consider it more useful to permit linking proprietary applications with
|
||||
the library. If this is what you want to do, use the GNU Lesser General
|
||||
Public License instead of this License. But first, please read
|
||||
<http://www.gnu.org/philosophy/why-not-lgpl.html>.
|
||||
```
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,3 @@
|
||||
C8BB336F2F49189F UML_AA.oer
|
||||
CDF1045B135A4E8F UML_AT.oer
|
||||
C06FBC0DE448E3BC UML_AT.oer
|
||||
Binary file not shown.
+55
@@ -0,0 +1,55 @@
|
||||
EU CCMS CPOC L0 ECTL — RCA descriptive information
|
||||
===================================================
|
||||
|
||||
Full Company Name / RCA Operator:
|
||||
Hochschule für Angewandte Wissenschaften Hamburg (HAW Hamburg)
|
||||
Urban Mobility Lab
|
||||
|
||||
RCA Name:
|
||||
Urban Mobility Lab L0 Root CA
|
||||
|
||||
RCA Distribution Centre URL:
|
||||
https://cits-dc.uml-hamburg.de
|
||||
|
||||
Contact:
|
||||
uml-haw@proton.me
|
||||
|
||||
CertificateID:
|
||||
0_Urban-Mobility-Lab-Root-CA_L0
|
||||
|
||||
Certificate HashedID8:
|
||||
AFD566A8034ED5DB
|
||||
|
||||
CertificateID / acronym explanation:
|
||||
- 0: CPA-ID reserved for the L0 environment.
|
||||
- Urban-Mobility-Lab-Root-CA: Root CA operated for the Urban Mobility Lab at HAW Hamburg.
|
||||
- L0: EU CCMS L0 research/test environment.
|
||||
|
||||
Purpose of testing:
|
||||
The RCA is used for research, field testing and proof-of-concept activities of the
|
||||
Urban Mobility Lab in the context of the micrOBU project. micrOBU investigates the
|
||||
integration of vulnerable road users into C-ITS through development of a lightweight,
|
||||
compact and low-cost VRU ITS-S using an MCU + mobile-phone architecture.
|
||||
|
||||
Contextual constraints / deviations:
|
||||
- This is a new RCA and the first L0 submission for this RCA. No existing L0 entry is
|
||||
intended to be replaced or revoked.
|
||||
- The implementation, including the C-ITS protocol stack, signing functionality and
|
||||
VRU Awareness Basic Service, is under active development. Full implementation
|
||||
conformity is not claimed.
|
||||
- The declared RCA Distribution Centre is the intended permanent DC URL. At the time
|
||||
of this submission, the cits-dc.uml-hamburg.de subdomain and the required /getctl
|
||||
and /getcrl endpoints are still being commissioned and are not yet operational.
|
||||
- The RCA intentionally includes ITS-AID 638 (VRU Awareness basic service) with
|
||||
bitmap SSP range 01/FF for L0 VAM/VBS research. ITS-AID 638 is a standardized ETSI
|
||||
ITS-AID but is not contained in the current CPOC Protocol Release 3.3 Table 4 list;
|
||||
its inclusion is therefore an intentional L0 profile deviation.
|
||||
- The RCA private key is generated and maintained locally as an encrypted PKCS#8
|
||||
NIST P-256 key for this L0 research environment. This software-based key storage is
|
||||
not claimed to satisfy production/L2 cryptographic-module requirements.
|
||||
|
||||
Re-key / revocation / relationship to existing certificates:
|
||||
New RCA / first submission. No existing L0 RCA certificate is affected.
|
||||
|
||||
Submission date:
|
||||
2026-09-11
|
||||
@@ -0,0 +1,4 @@
|
||||
-----BEGIN PUBLIC KEY-----
|
||||
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERRYsQMPF/6+MZf5Zg3hsnyMZR39W
|
||||
2i1rbusEm/7vDHX0OIzpTnfk2NZEGf/cRVLyrhOjtplgcqMzHdZ1bGr56A==
|
||||
-----END PUBLIC KEY-----
|
||||
@@ -0,0 +1,161 @@
|
||||
{
|
||||
"id8": "AFD566A8034ED5DB",
|
||||
"subject": {
|
||||
"type": "hostname",
|
||||
"hostname": "0_Urban-Mobility-Lab-Root-CA_L0"
|
||||
},
|
||||
"valid_from": "2026-09-14T23:58:51Z",
|
||||
"valid_until": "2031-09-15T05:04:51Z",
|
||||
"app_permissions": [
|
||||
{
|
||||
"type": "certificate_trust_list",
|
||||
"tlm": false,
|
||||
"root_ca": false,
|
||||
"enrollment_authority": true,
|
||||
"authorization_authority": true,
|
||||
"distribution_centre": true
|
||||
},
|
||||
{
|
||||
"type": "certificate_revocation_list"
|
||||
}
|
||||
],
|
||||
"cert_issue_permissions": [
|
||||
{
|
||||
"chain_length": {
|
||||
"start": 2,
|
||||
"end": 2
|
||||
},
|
||||
"end_entity_authorization": true,
|
||||
"end_entity_enrollment": true,
|
||||
"subject_permissions": {
|
||||
"type": "explicit",
|
||||
"permissions": [
|
||||
{
|
||||
"psid": "cam",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01FFFF",
|
||||
"subordinate_must_have": "FF0000"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "denm",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "02FFFFFFFF",
|
||||
"subordinate_must_have": "FF00000000"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "tlm",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01E0",
|
||||
"subordinate_must_have": "FF1F"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "rlt",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01C0",
|
||||
"subordinate_must_have": "FF3F"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "ivim",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01000000FFFF",
|
||||
"subordinate_must_have": "FF0000000000"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "tlc_req",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "02FFFFE0",
|
||||
"subordinate_must_have": "FF00001F"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "gm_mgmt",
|
||||
"auth": {
|
||||
"type": "all"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "cert_req",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01C0",
|
||||
"subordinate_must_have": "FF3F"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "tlc_stat",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01",
|
||||
"subordinate_must_have": "FF"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "vru",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01",
|
||||
"subordinate_must_have": "FF"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "cp",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01",
|
||||
"subordinate_must_have": "FF"
|
||||
}
|
||||
},
|
||||
{
|
||||
"psid": "poi",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "01",
|
||||
"subordinate_must_have": "FF"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"chain_length": {
|
||||
"start": 1,
|
||||
"end": 1
|
||||
},
|
||||
"end_entity_authorization": true,
|
||||
"end_entity_enrollment": false,
|
||||
"subject_permissions": {
|
||||
"type": "explicit",
|
||||
"permissions": [
|
||||
{
|
||||
"psid": "cert_req",
|
||||
"auth": {
|
||||
"type": "bitmap",
|
||||
"subordinate_may_have": "013E",
|
||||
"subordinate_must_have": "FFC1"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
],
|
||||
"cert_request_permissions": [],
|
||||
"signature": {
|
||||
"type": "self_signed",
|
||||
"verifies": true
|
||||
},
|
||||
"public_key": {
|
||||
"curve": "nistP256",
|
||||
"k": "0245162C40C3C5FFAF8C65FE5983786C9F2319477F56DA2D6B6EEB049BFEEF0C75"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
Reference notes
|
||||
===============
|
||||
|
||||
Pinned upstream commit:
|
||||
e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4
|
||||
|
||||
The upstream commit's root generator:
|
||||
1. constructs a ToBeSignedCertificate;
|
||||
2. serializes it using rasn::oer::encode();
|
||||
3. calls PrivateKey::sign(hash_alg, &tbs_bytes, None);
|
||||
4. inserts the returned IEEE 1609.2 Signature into an ExplicitCertificate.
|
||||
|
||||
The pinned c-its PrivateKey::sign() implementation for SHA-256 computes:
|
||||
|
||||
SHA256(
|
||||
SHA256(tbs_bytes)
|
||||
||
|
||||
SHA256(signer_info)
|
||||
)
|
||||
|
||||
For a self-signed root, signer_info is the empty byte string because the root
|
||||
generator passes None.
|
||||
|
||||
This bundle uses that exact upstream code for the cryptographic operation.
|
||||
`rebuild_registered_rca.py` keeps the registered TBS/public key unchanged and uses
|
||||
the registered encrypted key. `create_new_root.py` creates a new encrypted key and
|
||||
replaces the template public key for a separate, unregistered candidate root. In
|
||||
both cases the scalar reaches Rust only through standard input.
|
||||
@@ -0,0 +1,36 @@
|
||||
# UML L0 RCA generation tools
|
||||
|
||||
Both tools use the Rust/c-its certificate path pinned to commit
|
||||
`e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4`in https://github.com/TheEnbyperor/c-its. Requirements are Python 3.10+,
|
||||
`cryptography`, Git, Rust/Cargo, and internet access for the first build.
|
||||
|
||||
## Rebuild the registered root
|
||||
|
||||
```text
|
||||
python rebuild\_registered\_rca.py
|
||||
```
|
||||
|
||||
Uses `private/UML\_L0\_RCA\_private\_encrypted.pem`. It succeeds only when the result is
|
||||
byte-for-byte identical to the registered `AFD566A8034ED5DB.oer`. Use this to prove
|
||||
how the registered certificate was made or to verify the registered key. It never
|
||||
creates a key and does not alter the registered files.
|
||||
|
||||
## Create a separate new root
|
||||
|
||||
```text
|
||||
python create\_new\_root.py
|
||||
```
|
||||
|
||||
Creates a new P-256 key and candidate root certificate. It copies the registered
|
||||
root's reviewed TBS profile, including CertificateID, permissions, region and
|
||||
validity, but replaces the public key and signature. The result therefore has a
|
||||
different HashedId8 and is **not EU-registered**.
|
||||
|
||||
Use this only for an isolated test root or a deliberate EU registration/re-key
|
||||
process. Before submission, review the inherited validity/profile and coordinate
|
||||
revocation or registration with the EU CCMS CPOC. Files appear under a directory
|
||||
named `CANDIDATE\_SUBMISSION\_NOT\_REGISTERED`; that name is a warning, not approval.
|
||||
|
||||
In both workflows the private scalar is passed to the local Rust process through
|
||||
standard input and is never stored unencrypted by these tools.
|
||||
|
||||
@@ -0,0 +1,408 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Create a separate NEW UML L0 RCA keypair and candidate certificate
|
||||
using the exact TheEnbyperor/c-its reference commit e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4.
|
||||
|
||||
THIS DOES NOT REPLACE OR RECREATE THE EU-REGISTERED ROOT. The result is not trusted
|
||||
or registered until it completes a deliberate registration/re-key process.
|
||||
|
||||
The new private key never leaves this machine and is permanently stored only as
|
||||
encrypted PKCS#8 PEM. A 32-byte private scalar is passed to the already-built
|
||||
local Rust process over stdin and is never written to disk unencrypted.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import getpass
|
||||
import hashlib
|
||||
import os
|
||||
from pathlib import Path
|
||||
import re
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
import tarfile
|
||||
import zipfile
|
||||
from datetime import datetime
|
||||
|
||||
UPSTREAM_COMMIT = "e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4"
|
||||
TEMPLATE_SHA256 = "7168E341764188E140EF591634A9D2488D7FDACDA667EE53AFD566A8034ED5DB"
|
||||
CERTIFICATE_ID = "0_Urban-Mobility-Lab-Root-CA_L0"
|
||||
|
||||
HERE = Path(__file__).resolve().parent
|
||||
ROOT = HERE.parent
|
||||
TEMPLATE = ROOT / "rca" / "AFD566A8034ED5DB.oer"
|
||||
PATCH_SOURCE = HERE / "src" / "create_new_root.rs"
|
||||
BUNDLED_SOURCE = HERE / "vendor" / "c-its-source-e3bb3b8.zip"
|
||||
VENDORED_CRATES = HERE / "vendor" / "cargo-crates.tar.gz"
|
||||
UPSTREAM_DIR = HERE / "_build_cits"
|
||||
CARGO_VENDOR_DIR = HERE / "_cargo_vendor"
|
||||
|
||||
def die(msg: str) -> None:
|
||||
raise SystemExit("\nERROR: " + msg)
|
||||
|
||||
def run(cmd, *, cwd=None, input_bytes=None, capture=False, env=None):
|
||||
print("+", " ".join(str(x) for x in cmd))
|
||||
return subprocess.run(
|
||||
cmd,
|
||||
cwd=cwd,
|
||||
input=input_bytes,
|
||||
check=True,
|
||||
text=False,
|
||||
capture_output=capture,
|
||||
env=env,
|
||||
)
|
||||
|
||||
def require_program(name: str) -> None:
|
||||
if shutil.which(name) is None:
|
||||
die(
|
||||
f"'{name}' is not installed or not on PATH. "
|
||||
"Install Git and the Rust toolchain (cargo/rustc) first. "
|
||||
"On Windows, WSL2 Ubuntu is a good fallback if native compilation causes problems."
|
||||
)
|
||||
|
||||
def validate_submission_date(s: str) -> str:
|
||||
try:
|
||||
datetime.strptime(s, "%Y-%m-%d")
|
||||
except ValueError:
|
||||
die("Submission date must be YYYY-MM-DD.")
|
||||
return s
|
||||
|
||||
def prepare_upstream() -> None:
|
||||
"""Create a disposable build tree from the bundled pinned source."""
|
||||
if not BUNDLED_SOURCE.is_file() or not VENDORED_CRATES.is_file():
|
||||
die("Bundled c-its source or Cargo crate archive is missing.")
|
||||
if UPSTREAM_DIR.exists():
|
||||
shutil.rmtree(UPSTREAM_DIR)
|
||||
if CARGO_VENDOR_DIR.exists():
|
||||
shutil.rmtree(CARGO_VENDOR_DIR)
|
||||
UPSTREAM_DIR.mkdir()
|
||||
CARGO_VENDOR_DIR.mkdir()
|
||||
with zipfile.ZipFile(BUNDLED_SOURCE) as archive:
|
||||
archive.extractall(UPSTREAM_DIR)
|
||||
with tarfile.open(VENDORED_CRATES, "r:gz") as archive:
|
||||
archive.extractall(CARGO_VENDOR_DIR)
|
||||
|
||||
# Replace only the root-generator utility. Security/crypto/ASN.1 implementation
|
||||
# remains the pinned upstream commit.
|
||||
shutil.copy2(PATCH_SOURCE, UPSTREAM_DIR / "src" / "util" / "generate_root.rs")
|
||||
shutil.copy2(TEMPLATE, UPSTREAM_DIR / TEMPLATE.name)
|
||||
|
||||
# Host-build fix for Windows/native desktop targets:
|
||||
# ieee80211 pulls embedded defmt support through default features, but a
|
||||
# normal host executable has no defmt transport/logger providing symbols
|
||||
# such as _defmt_panic, _defmt_acquire and _defmt_write.
|
||||
cargo_toml = UPSTREAM_DIR / "Cargo.toml"
|
||||
cargo_text = cargo_toml.read_text(encoding="utf-8")
|
||||
original_ieee = 'ieee80211 = "0.5.9"'
|
||||
patched_ieee = 'ieee80211 = { version = "0.5.9", default-features = false }'
|
||||
if original_ieee in cargo_text:
|
||||
cargo_text = cargo_text.replace(original_ieee, patched_ieee, 1)
|
||||
cargo_toml.write_text(cargo_text, encoding="utf-8")
|
||||
print("Applied host-build patch: ieee80211 default features disabled (defmt removed).")
|
||||
elif patched_ieee in cargo_text:
|
||||
print("Host-build patch already present.")
|
||||
else:
|
||||
die("Expected ieee80211 dependency line not found in pinned Cargo.toml.")
|
||||
|
||||
cargo_config = UPSTREAM_DIR / ".cargo" / "config.toml"
|
||||
cargo_config.parent.mkdir()
|
||||
cargo_config.write_text(
|
||||
'[source.crates-io]\nreplace-with = "vendored-sources"\n\n'
|
||||
'[source.vendored-sources]\ndirectory = "../_cargo_vendor"\n\n'
|
||||
'[net]\noffline = true\n',
|
||||
encoding="utf-8",
|
||||
)
|
||||
|
||||
def build_generator() -> Path:
|
||||
print("\nBuilding the pinned c-its generator BEFORE generating any private key...")
|
||||
try:
|
||||
run(
|
||||
[
|
||||
"cargo", "build", "--offline", "--release",
|
||||
"--features", "build-binary",
|
||||
"--bin", "c-its-generate-root",
|
||||
],
|
||||
cwd=UPSTREAM_DIR,
|
||||
)
|
||||
except subprocess.CalledProcessError as exc:
|
||||
die(
|
||||
"The pinned c-its host build failed. No RCA private key has been generated. "
|
||||
"If the remaining linker error still mentions _defmt_*, delete the package's "
|
||||
"_upstream_cits directory and rerun this V2 script. "
|
||||
f"Cargo exit code: {exc.returncode}"
|
||||
)
|
||||
exe = UPSTREAM_DIR / "target" / "release" / (
|
||||
"c-its-generate-root.exe" if os.name == "nt" else "c-its-generate-root"
|
||||
)
|
||||
if not exe.exists():
|
||||
die(f"Build reported success but executable is missing: {exe}")
|
||||
return exe
|
||||
|
||||
def generate_keypair_and_certificate(exe: Path) -> Path:
|
||||
try:
|
||||
from cryptography.hazmat.primitives.asymmetric import ec, utils
|
||||
from cryptography.hazmat.primitives import hashes, serialization
|
||||
except ImportError:
|
||||
die("Python package 'cryptography' is required. Run: python -m pip install cryptography")
|
||||
|
||||
submission_date = validate_submission_date(
|
||||
input("\nActual submission date (YYYY-MM-DD): ").strip()
|
||||
)
|
||||
|
||||
while True:
|
||||
pw1 = getpass.getpass("Choose NEW RCA private-key passphrase: ")
|
||||
pw2 = getpass.getpass("Repeat passphrase: ")
|
||||
if pw1 != pw2:
|
||||
print("Passphrases do not match. Try again.")
|
||||
continue
|
||||
if len(pw1) < 12:
|
||||
print("Use at least 12 characters.")
|
||||
continue
|
||||
break
|
||||
|
||||
stamp = datetime.now().strftime("%Y%m%d_%H%M%S")
|
||||
root = HERE / f"UML_L0_RCA_NEW_{stamp}"
|
||||
submit = root / "CANDIDATE_SUBMISSION_NOT_REGISTERED"
|
||||
private_dir = root / "PRIVATE_DO_NOT_SHARE"
|
||||
public_dir = root / "PUBLIC_AND_VALIDATION"
|
||||
rust_out = root / "_rust_output"
|
||||
for d in (submit, private_dir, public_dir, rust_out):
|
||||
d.mkdir(parents=True, exist_ok=False)
|
||||
|
||||
print("\nGenerating a fresh NIST P-256 keypair locally...")
|
||||
key = ec.generate_private_key(ec.SECP256R1())
|
||||
|
||||
encrypted_pem = key.private_bytes(
|
||||
encoding=serialization.Encoding.PEM,
|
||||
format=serialization.PrivateFormat.PKCS8,
|
||||
encryption_algorithm=serialization.BestAvailableEncryption(pw1.encode("utf-8")),
|
||||
)
|
||||
public_pem = key.public_key().public_bytes(
|
||||
encoding=serialization.Encoding.PEM,
|
||||
format=serialization.PublicFormat.SubjectPublicKeyInfo,
|
||||
)
|
||||
|
||||
private_path = private_dir / "UML_L0_RCA_private_encrypted.pem"
|
||||
public_path = public_dir / "UML_L0_RCA_public.pem"
|
||||
private_path.write_bytes(encrypted_pem)
|
||||
public_path.write_bytes(public_pem)
|
||||
try:
|
||||
private_path.chmod(0o600)
|
||||
except OSError:
|
||||
pass
|
||||
|
||||
# The scalar is kept in RAM and sent only over stdin to the local Rust binary.
|
||||
scalar = bytearray(key.private_numbers().private_value.to_bytes(32, "big"))
|
||||
|
||||
env = os.environ.copy()
|
||||
env["UML_TEMPLATE"] = str(UPSTREAM_DIR / TEMPLATE.name)
|
||||
env["UML_OUTPUT_DIR"] = str(rust_out)
|
||||
|
||||
try:
|
||||
proc = run(
|
||||
[str(exe)],
|
||||
cwd=UPSTREAM_DIR,
|
||||
input_bytes=(bytes(scalar).hex().upper() + "\n").encode("ascii"),
|
||||
capture=True,
|
||||
env=env,
|
||||
)
|
||||
finally:
|
||||
for i in range(len(scalar)):
|
||||
scalar[i] = 0
|
||||
|
||||
stdout = proc.stdout.decode("utf-8", errors="replace")
|
||||
stderr = proc.stderr.decode("utf-8", errors="replace")
|
||||
print(stdout)
|
||||
if stderr.strip():
|
||||
print(stderr, file=sys.stderr)
|
||||
|
||||
m = re.search(r"^RESULT_ID8=([0-9A-F]{16})$", stdout, re.MULTILINE)
|
||||
if not m:
|
||||
die("Rust generator succeeded but RESULT_ID8 was not found.")
|
||||
id8 = m.group(1)
|
||||
|
||||
oer_src = rust_out / f"{id8}.oer"
|
||||
if not oer_src.exists():
|
||||
die(f"Expected certificate not found: {oer_src}")
|
||||
|
||||
cert_bytes = oer_src.read_bytes()
|
||||
cert_sha256 = hashlib.sha256(cert_bytes).hexdigest().upper()
|
||||
if cert_sha256[-16:] != id8:
|
||||
die("Independent Python HashedID8 check failed.")
|
||||
|
||||
# Independently reconstruct the IEEE/ETSI self-signed prehash from the TBS
|
||||
# emitted by rasn and verify the c-its ECDSA signature with Python cryptography.
|
||||
details = {}
|
||||
for line in (rust_out / "signing_details.txt").read_text(encoding="utf-8").splitlines():
|
||||
if "=" in line:
|
||||
k, v = line.split("=", 1)
|
||||
details[k] = v
|
||||
|
||||
tbs = (rust_out / "tbs.oer").read_bytes()
|
||||
h_tbs = hashlib.sha256(tbs).digest()
|
||||
h_empty = hashlib.sha256(b"").digest()
|
||||
prehash = hashlib.sha256(h_tbs + h_empty).digest()
|
||||
|
||||
if details.get("TBS_SHA256") != h_tbs.hex().upper():
|
||||
die("Independent TBS hash disagrees with Rust output.")
|
||||
if details.get("SIGNING_PREHASH_SHA256") != prehash.hex().upper():
|
||||
die("Independent IEEE/ETSI signing prehash disagrees with Rust output.")
|
||||
|
||||
r = int(details["ECDSA_R"], 16)
|
||||
s = int(details["ECDSA_S"], 16)
|
||||
der_sig = utils.encode_dss_signature(r, s)
|
||||
try:
|
||||
key.public_key().verify(
|
||||
der_sig,
|
||||
prehash,
|
||||
ec.ECDSA(utils.Prehashed(hashes.SHA256())),
|
||||
)
|
||||
except Exception as exc:
|
||||
die(f"Independent Python ECDSA verification FAILED: {exc}")
|
||||
|
||||
# Copy only the public submission certificate.
|
||||
oer_submit = submit / f"{id8}.oer"
|
||||
shutil.copy2(oer_src, oer_submit)
|
||||
|
||||
txt_name = f"{id8}_{CERTIFICATE_ID}_{submission_date}.txt"
|
||||
txt_submit = submit / txt_name
|
||||
txt_submit.write_text(f"""EU CCMS CPOC L0 ECTL — RCA descriptive information
|
||||
===================================================
|
||||
|
||||
Full Company Name / RCA Operator:
|
||||
Hochschule für Angewandte Wissenschaften Hamburg (HAW Hamburg)
|
||||
Urban Mobility Lab
|
||||
|
||||
RCA Name:
|
||||
Urban Mobility Lab L0 Root CA
|
||||
|
||||
RCA Distribution Centre URL:
|
||||
https://cits-dc.uml-hamburg.de
|
||||
|
||||
Contact:
|
||||
uml-haw@proton.me
|
||||
|
||||
CertificateID:
|
||||
{CERTIFICATE_ID}
|
||||
|
||||
Certificate HashedID8:
|
||||
{id8}
|
||||
|
||||
CertificateID / acronym explanation:
|
||||
- 0: CPA-ID reserved for the L0 environment.
|
||||
- Urban-Mobility-Lab-Root-CA: Root CA operated for the Urban Mobility Lab at HAW Hamburg.
|
||||
- L0: EU CCMS L0 research/test environment.
|
||||
|
||||
Purpose of testing:
|
||||
The RCA is used for research, field testing and proof-of-concept activities of the
|
||||
Urban Mobility Lab in the context of the micrOBU project. micrOBU investigates the
|
||||
integration of vulnerable road users into C-ITS through development of a lightweight,
|
||||
compact and low-cost VRU ITS-S using an MCU + mobile-phone architecture.
|
||||
|
||||
Contextual constraints / deviations:
|
||||
- This is a candidate new RCA. It is not registered and must not be deployed until
|
||||
the EU CCMS CPOC has completed the intended registration or re-key procedure.
|
||||
- The implementation, including the C-ITS protocol stack, signing functionality and
|
||||
VRU Awareness Basic Service, is under active development. Full implementation
|
||||
conformity is not claimed.
|
||||
- The declared RCA Distribution Centre is the intended permanent DC URL. At the time
|
||||
of this submission, the cits-dc.uml-hamburg.de subdomain and the required /getctl
|
||||
and /getcrl endpoints are still being commissioned and are not yet operational.
|
||||
- The RCA intentionally includes ITS-AID 638 (VRU Awareness basic service) with
|
||||
bitmap SSP range 01/FF for L0 VAM/VBS research. ITS-AID 638 is a standardized ETSI
|
||||
ITS-AID but is not contained in the current CPOC Protocol Release 3.3 Table 4 list;
|
||||
its inclusion is therefore an intentional L0 profile deviation.
|
||||
- The RCA private key is generated and maintained locally as an encrypted PKCS#8
|
||||
NIST P-256 key for this L0 research environment. This software-based key storage is
|
||||
not claimed to satisfy production/L2 cryptographic-module requirements.
|
||||
|
||||
Re-key / revocation / relationship to existing certificates:
|
||||
Candidate new RCA. Coordinate its relationship to existing registrations with the
|
||||
EU CCMS CPOC before submission or use.
|
||||
|
||||
Submission date:
|
||||
{submission_date}
|
||||
""", encoding="utf-8")
|
||||
|
||||
# Preserve public validation evidence.
|
||||
shutil.copy2(rust_out / "certificate_report.json", public_dir / "certificate_report.json")
|
||||
shutil.copy2(rust_out / "signing_details.txt", public_dir / "signing_details.txt")
|
||||
shutil.copy2(rust_out / "tbs.oer", public_dir / "tbs.oer")
|
||||
|
||||
spki_der = key.public_key().public_bytes(
|
||||
encoding=serialization.Encoding.DER,
|
||||
format=serialization.PublicFormat.SubjectPublicKeyInfo,
|
||||
)
|
||||
spki_sha256 = hashlib.sha256(spki_der).hexdigest().upper()
|
||||
|
||||
manifest = f"""UML L0 RCA generation manifest
|
||||
=============================
|
||||
|
||||
Reference implementation:
|
||||
https://github.com/TheEnbyperor/c-its
|
||||
Pinned commit:
|
||||
{UPSTREAM_COMMIT}
|
||||
|
||||
Reference root-generator behavior:
|
||||
- rasn::oer encoding
|
||||
- c_its::security::crypto::PrivateKey::sign()
|
||||
- self-signed signer-certificate input = empty byte string
|
||||
- NIST P-256 / SHA-256
|
||||
|
||||
Template certificate SHA-256:
|
||||
{TEMPLATE_SHA256}
|
||||
|
||||
NEW certificate:
|
||||
{id8}.oer
|
||||
|
||||
Certificate SHA-256:
|
||||
{cert_sha256}
|
||||
|
||||
HashedID8:
|
||||
{id8}
|
||||
|
||||
New public-key SPKI SHA-256:
|
||||
{spki_sha256}
|
||||
|
||||
Validation:
|
||||
PASS - c-its parsed final certificate
|
||||
PASS - c-its self-signature verification
|
||||
PASS - c-its parse/re-encode stability
|
||||
PASS - Python independently recomputed HashedID8
|
||||
PASS - Python independently recomputed IEEE/ETSI signing prehash
|
||||
PASS - Python cryptography independently verified ECDSA signature over that prehash
|
||||
|
||||
PRIVATE KEY:
|
||||
{private_path.name}
|
||||
Encrypted PKCS#8 PEM. DO NOT SUBMIT OR UPLOAD.
|
||||
"""
|
||||
(public_dir / "generation_manifest.txt").write_text(manifest, encoding="utf-8")
|
||||
|
||||
# Remove duplicate Rust certificate; the canonical submission copy is in SUBMIT.
|
||||
shutil.rmtree(rust_out)
|
||||
|
||||
print("\nSUCCESS")
|
||||
print("A NEW, UNREGISTERED keypair and candidate certificate were generated locally.")
|
||||
print("Do not deploy it as the registered root. EU registration/re-keying is required.")
|
||||
print(f"\nCANDIDATE SUBMISSION FILES (NOT REGISTERED):\n {oer_submit}\n {txt_submit}")
|
||||
print(f"\nKEEP PRIVATE:\n {private_path}")
|
||||
print(f"\nSAFE PUBLIC/VALIDATION FILES:\n {public_dir}")
|
||||
return root
|
||||
|
||||
def main() -> None:
|
||||
require_program("cargo")
|
||||
|
||||
if not TEMPLATE.exists():
|
||||
die(f"Missing bundled template: {TEMPLATE}")
|
||||
got = hashlib.sha256(TEMPLATE.read_bytes()).hexdigest().upper()
|
||||
if got != TEMPLATE_SHA256:
|
||||
die(f"Bundled template hash mismatch: {got}")
|
||||
|
||||
prepare_upstream()
|
||||
exe = build_generator()
|
||||
root = generate_keypair_and_certificate(exe)
|
||||
print(f"\nResult folder: {root}")
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,168 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Rebuild and verify the registered UML L0 RCA with its existing private key."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import getpass
|
||||
import hashlib
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
import tarfile
|
||||
import zipfile
|
||||
|
||||
UPSTREAM_COMMIT = "e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4"
|
||||
REGISTERED_SHA256 = "7168E341764188E140EF591634A9D2488D7FDACDA667EE53AFD566A8034ED5DB"
|
||||
REGISTERED_ID8 = "AFD566A8034ED5DB"
|
||||
|
||||
HERE = Path(__file__).resolve().parent
|
||||
ROOT = HERE.parent
|
||||
REGISTERED_CERT = ROOT / "rca" / f"{REGISTERED_ID8}.oer"
|
||||
REGISTERED_PUBLIC_KEY = ROOT / "rca" / "UML_L0_RCA_public.pem"
|
||||
REGISTERED_PRIVATE_KEY = ROOT / "private" / "UML_L0_RCA_private_encrypted.pem"
|
||||
PATCH_SOURCE = HERE / "src" / "generate_root.rs"
|
||||
BUNDLED_SOURCE = HERE / "vendor" / "c-its-source-e3bb3b8.zip"
|
||||
VENDORED_CRATES = HERE / "vendor" / "cargo-crates.tar.gz"
|
||||
UPSTREAM_DIR = HERE / "_build_cits"
|
||||
CARGO_VENDOR_DIR = HERE / "_cargo_vendor"
|
||||
OUTPUT_DIR = HERE / "rebuild-output"
|
||||
TEMPLATE_NAME = "registered_rca.oer"
|
||||
|
||||
|
||||
def die(message: str) -> None:
|
||||
raise SystemExit(f"\nERROR: {message}")
|
||||
|
||||
|
||||
def run(command: list[str], *, cwd: Path, input_bytes: bytes | None = None,
|
||||
capture: bool = False, env: dict[str, str] | None = None):
|
||||
print("+", " ".join(command))
|
||||
return subprocess.run(
|
||||
command, cwd=cwd, input=input_bytes, check=True, capture_output=capture, env=env
|
||||
)
|
||||
|
||||
|
||||
def require_program(name: str) -> None:
|
||||
if shutil.which(name) is None:
|
||||
die(f"'{name}' is required and was not found on PATH.")
|
||||
|
||||
|
||||
def verify_inputs() -> None:
|
||||
for path in (REGISTERED_CERT, REGISTERED_PUBLIC_KEY, REGISTERED_PRIVATE_KEY, PATCH_SOURCE):
|
||||
if not path.is_file():
|
||||
die(f"Required file is missing: {path}")
|
||||
actual = hashlib.sha256(REGISTERED_CERT.read_bytes()).hexdigest().upper()
|
||||
if actual != REGISTERED_SHA256:
|
||||
die(f"Registered certificate hash mismatch: {actual}")
|
||||
|
||||
|
||||
def prepare_upstream() -> None:
|
||||
if not BUNDLED_SOURCE.is_file() or not VENDORED_CRATES.is_file():
|
||||
die("Bundled c-its source or Cargo crate archive is missing.")
|
||||
if UPSTREAM_DIR.exists():
|
||||
shutil.rmtree(UPSTREAM_DIR)
|
||||
if CARGO_VENDOR_DIR.exists():
|
||||
shutil.rmtree(CARGO_VENDOR_DIR)
|
||||
UPSTREAM_DIR.mkdir()
|
||||
CARGO_VENDOR_DIR.mkdir()
|
||||
with zipfile.ZipFile(BUNDLED_SOURCE) as archive:
|
||||
archive.extractall(UPSTREAM_DIR)
|
||||
with tarfile.open(VENDORED_CRATES, "r:gz") as archive:
|
||||
archive.extractall(CARGO_VENDOR_DIR)
|
||||
|
||||
shutil.copy2(PATCH_SOURCE, UPSTREAM_DIR / "src" / "util" / "generate_root.rs")
|
||||
shutil.copy2(REGISTERED_CERT, UPSTREAM_DIR / TEMPLATE_NAME)
|
||||
|
||||
cargo_toml = UPSTREAM_DIR / "Cargo.toml"
|
||||
text = cargo_toml.read_text(encoding="utf-8")
|
||||
old = 'ieee80211 = "0.5.9"'
|
||||
new = 'ieee80211 = { version = "0.5.9", default-features = false }'
|
||||
if old in text:
|
||||
cargo_toml.write_text(text.replace(old, new, 1), encoding="utf-8")
|
||||
elif new not in text:
|
||||
die("Expected ieee80211 dependency was not found in the pinned source.")
|
||||
|
||||
cargo_config = UPSTREAM_DIR / ".cargo" / "config.toml"
|
||||
cargo_config.parent.mkdir()
|
||||
cargo_config.write_text(
|
||||
'[source.crates-io]\nreplace-with = "vendored-sources"\n\n'
|
||||
'[source.vendored-sources]\ndirectory = "../_cargo_vendor"\n\n'
|
||||
'[net]\noffline = true\n',
|
||||
encoding="utf-8",
|
||||
)
|
||||
|
||||
|
||||
def build_generator() -> Path:
|
||||
run(
|
||||
["cargo", "build", "--offline", "--release", "--features", "build-binary", "--bin", "c-its-generate-root"],
|
||||
cwd=UPSTREAM_DIR,
|
||||
)
|
||||
executable = UPSTREAM_DIR / "target" / "release" / (
|
||||
"c-its-generate-root.exe" if os.name == "nt" else "c-its-generate-root"
|
||||
)
|
||||
if not executable.is_file():
|
||||
die(f"Generator executable is missing: {executable}")
|
||||
return executable
|
||||
|
||||
|
||||
def load_registered_scalar() -> bytearray:
|
||||
try:
|
||||
from cryptography.hazmat.primitives import serialization
|
||||
from cryptography.hazmat.primitives.asymmetric import ec
|
||||
except ImportError:
|
||||
die("Install the Python package 'cryptography'.")
|
||||
|
||||
password = getpass.getpass("Registered RCA private-key passphrase: ").encode("utf-8")
|
||||
try:
|
||||
key = serialization.load_pem_private_key(REGISTERED_PRIVATE_KEY.read_bytes(), password=password)
|
||||
except Exception as exc:
|
||||
die(f"Could not unlock the registered private key: {exc}")
|
||||
|
||||
if not isinstance(key, ec.EllipticCurvePrivateKey) or not isinstance(key.curve, ec.SECP256R1):
|
||||
die("Registered key is not NIST P-256.")
|
||||
expected_public = serialization.load_pem_public_key(REGISTERED_PUBLIC_KEY.read_bytes())
|
||||
if key.public_key().public_numbers() != expected_public.public_numbers():
|
||||
die("Private key does not match the registered public key.")
|
||||
return bytearray(key.private_numbers().private_value.to_bytes(32, "big"))
|
||||
|
||||
|
||||
def rebuild(executable: Path) -> None:
|
||||
scalar = load_registered_scalar()
|
||||
if OUTPUT_DIR.exists():
|
||||
shutil.rmtree(OUTPUT_DIR)
|
||||
OUTPUT_DIR.mkdir()
|
||||
|
||||
env = os.environ.copy()
|
||||
env["UML_TEMPLATE"] = str(UPSTREAM_DIR / TEMPLATE_NAME)
|
||||
env["UML_OUTPUT_DIR"] = str(OUTPUT_DIR)
|
||||
try:
|
||||
result = run(
|
||||
[str(executable)], cwd=UPSTREAM_DIR,
|
||||
input_bytes=(bytes(scalar).hex().upper() + "\n").encode("ascii"),
|
||||
capture=True, env=env,
|
||||
)
|
||||
finally:
|
||||
for index in range(len(scalar)):
|
||||
scalar[index] = 0
|
||||
|
||||
sys.stdout.write(result.stdout.decode("utf-8", errors="replace"))
|
||||
sys.stderr.write(result.stderr.decode("utf-8", errors="replace"))
|
||||
rebuilt = OUTPUT_DIR / f"{REGISTERED_ID8}.oer"
|
||||
if not rebuilt.is_file():
|
||||
die(f"Expected rebuilt certificate is missing: {rebuilt}")
|
||||
if rebuilt.read_bytes() != REGISTERED_CERT.read_bytes():
|
||||
die("Rebuilt certificate is not byte-for-byte identical to the EU-registered certificate.")
|
||||
print("\nPASS: rebuilt certificate exactly matches the registered certificate.")
|
||||
print(f"Validation output: {OUTPUT_DIR}")
|
||||
|
||||
|
||||
def main() -> None:
|
||||
require_program("cargo")
|
||||
verify_inputs()
|
||||
prepare_upstream()
|
||||
rebuild(build_generator())
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,179 @@
|
||||
use std::io::{self, Read};
|
||||
use std::path::PathBuf;
|
||||
|
||||
use sha2::{Digest, Sha256};
|
||||
|
||||
const EXPECTED_TEMPLATE_SHA256: &str =
|
||||
"7168E341764188E140EF591634A9D2488D7FDACDA667EE53AFD566A8034ED5DB";
|
||||
|
||||
fn err(msg: impl Into<String>) -> io::Error {
|
||||
io::Error::new(io::ErrorKind::InvalidData, msg.into())
|
||||
}
|
||||
|
||||
fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
let template_path = PathBuf::from(
|
||||
std::env::var("UML_TEMPLATE")
|
||||
.unwrap_or_else(|_| "registered_rca.oer".to_string()),
|
||||
);
|
||||
let output_dir = PathBuf::from(
|
||||
std::env::var("UML_OUTPUT_DIR").unwrap_or_else(|_| "uml_output".to_string()),
|
||||
);
|
||||
|
||||
let template_bytes = std::fs::read(&template_path)?;
|
||||
let template_sha256 = hex::encode_upper(Sha256::digest(&template_bytes));
|
||||
if template_sha256 != EXPECTED_TEMPLATE_SHA256 {
|
||||
return Err(err(format!(
|
||||
"Template SHA-256 mismatch. Expected {}, got {}",
|
||||
EXPECTED_TEMPLATE_SHA256, template_sha256
|
||||
))
|
||||
.into());
|
||||
}
|
||||
|
||||
// Decode the registered certificate only as the reviewed profile template.
|
||||
let template: rasn_its::ts103097::EtsiTs103097Certificate =
|
||||
rasn::oer::decode(&template_bytes)?;
|
||||
|
||||
// The wrapper sends a newly generated P-256 scalar over stdin. It is never
|
||||
// written to disk unencrypted.
|
||||
let mut scalar_hex = String::new();
|
||||
std::io::stdin().read_to_string(&mut scalar_hex)?;
|
||||
let scalar = hex::decode(scalar_hex.trim())?;
|
||||
if scalar.len() != 32 {
|
||||
return Err(err(format!(
|
||||
"Expected a 32-byte NIST P-256 private scalar, received {} bytes",
|
||||
scalar.len()
|
||||
))
|
||||
.into());
|
||||
}
|
||||
|
||||
let secret_key = p256::SecretKey::from_slice(&scalar)
|
||||
.map_err(|_| err("Invalid NIST P-256 private scalar"))?;
|
||||
let private_key =
|
||||
c_its::security::crypto::PrivateKey::P256(secret_key.into());
|
||||
|
||||
let mut tbs_cert = template.to_be_signed.clone();
|
||||
tbs_cert.verify_key_indicator =
|
||||
rasn_its::ieee1609dot2::VerificationKeyIndicator::VerificationKey(
|
||||
private_key.public_key().encode(),
|
||||
);
|
||||
|
||||
// This is deliberately the exact encoding/signing route introduced by
|
||||
// TheEnbyperor/c-its commit e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4.
|
||||
let tbs_bytes = rasn::oer::encode(&tbs_cert)?;
|
||||
let hash_alg = c_its::security::crypto::HashAlgorithm::Sha256;
|
||||
let signature = private_key
|
||||
.sign(hash_alg, &tbs_bytes, None)
|
||||
.ok_or_else(|| err("c-its signing failed"))?;
|
||||
|
||||
let (r_hex, s_hex) = match &signature {
|
||||
c_its::security::crypto::Signature::P256(sig) => (
|
||||
hex::encode_upper(sig.r().to_bytes()),
|
||||
hex::encode_upper(sig.s().to_bytes()),
|
||||
),
|
||||
_ => return Err(err("Unexpected signature algorithm").into()),
|
||||
};
|
||||
|
||||
// Construct the certificate exactly like the upstream root generator.
|
||||
let raw_cert = rasn_its::ts103097::EtsiTs103097Certificate::try_from(
|
||||
rasn_its::ieee1609dot2::Certificate::from(
|
||||
rasn_its::ieee1609dot2::ExplicitCertificate::new(
|
||||
rasn_its::ieee1609dot2::CertificateBase {
|
||||
version: 3,
|
||||
r#type: rasn_its::ieee1609dot2::CertificateType::Explicit,
|
||||
issuer: rasn_its::ieee1609dot2::IssuerIdentifier::VSelf(
|
||||
hash_alg.into(),
|
||||
),
|
||||
to_be_signed: tbs_cert,
|
||||
signature: Some(signature.as_signature()),
|
||||
},
|
||||
)
|
||||
.map_err(|_| err("Could not construct ExplicitCertificate"))?,
|
||||
),
|
||||
)
|
||||
.map_err(|_| err("Certificate does not satisfy EtsiTs103097Certificate constraints"))?;
|
||||
|
||||
let cert = c_its::security::certs::Certificate::new(&raw_cert);
|
||||
let encoded = cert.to_bytes();
|
||||
|
||||
// Parse the actual final bytes from scratch and make the upstream c-its verifier
|
||||
// validate the self-signature.
|
||||
let reparsed = c_its::security::certs::Certificate::parse(&encoded)
|
||||
.map_err(err)?;
|
||||
let report = reparsed.report().map_err(err)?;
|
||||
|
||||
match report.signature() {
|
||||
c_its::security::certs::CertificateSignature::SelfSigned { verifies: true } => {}
|
||||
other => {
|
||||
return Err(err(format!(
|
||||
"FINAL CERTIFICATE SELF-SIGNATURE DID NOT VERIFY: {:?}",
|
||||
other
|
||||
))
|
||||
.into())
|
||||
}
|
||||
}
|
||||
|
||||
let reencoded = reparsed.to_bytes();
|
||||
if reencoded != encoded {
|
||||
return Err(err("Final certificate is not stable across parse/re-encode").into());
|
||||
}
|
||||
|
||||
let id8 = hex::encode_upper(report.id8());
|
||||
let cert_sha256 = hex::encode_upper(Sha256::digest(&encoded));
|
||||
if &cert_sha256[cert_sha256.len() - 16..] != id8 {
|
||||
return Err(err("HashedID8 does not match low-order 8 bytes of SHA-256").into());
|
||||
}
|
||||
|
||||
// Compute the IEEE/ETSI self-signed certificate signing prehash independently
|
||||
// from the signature object:
|
||||
// SHA256( SHA256(COER/OER-TBS) || SHA256(empty signer certificate) )
|
||||
let tbs_hash = Sha256::digest(&tbs_bytes);
|
||||
let empty_hash = Sha256::digest([]);
|
||||
let mut outer = Sha256::new();
|
||||
outer.update(&tbs_hash);
|
||||
outer.update(&empty_hash);
|
||||
let signing_prehash = outer.finalize();
|
||||
|
||||
std::fs::create_dir_all(&output_dir)?;
|
||||
std::fs::write(output_dir.join(format!("{}.oer", id8)), &encoded)?;
|
||||
std::fs::write(output_dir.join("tbs.oer"), &tbs_bytes)?;
|
||||
std::fs::write(
|
||||
output_dir.join("certificate_report.json"),
|
||||
serde_json::to_vec_pretty(&report)?,
|
||||
)?;
|
||||
|
||||
let signing_details = format!(
|
||||
concat!(
|
||||
"UPSTREAM_COMMIT=e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4\n",
|
||||
"TEMPLATE_SHA256={}\n",
|
||||
"CERTIFICATE_SHA256={}\n",
|
||||
"HASHEDID8={}\n",
|
||||
"TBS_LENGTH={}\n",
|
||||
"TBS_SHA256={}\n",
|
||||
"EMPTY_SHA256={}\n",
|
||||
"SIGNING_PREHASH_SHA256={}\n",
|
||||
"ECDSA_R={}\n",
|
||||
"ECDSA_S={}\n",
|
||||
"CITS_SELF_SIGNATURE_VERIFIES=true\n",
|
||||
"PARSE_REENCODE_STABLE=true\n"
|
||||
),
|
||||
template_sha256,
|
||||
cert_sha256,
|
||||
id8,
|
||||
tbs_bytes.len(),
|
||||
hex::encode_upper(tbs_hash),
|
||||
hex::encode_upper(empty_hash),
|
||||
hex::encode_upper(signing_prehash),
|
||||
r_hex,
|
||||
s_hex,
|
||||
);
|
||||
std::fs::write(output_dir.join("signing_details.txt"), signing_details)?;
|
||||
|
||||
println!("RESULT_ID8={}", id8);
|
||||
println!(
|
||||
"RESULT_CERT={}",
|
||||
output_dir.join(format!("{}.oer", id8)).display()
|
||||
);
|
||||
println!("CITS_SELF_SIGNATURE_VERIFIES=true");
|
||||
|
||||
Ok(())
|
||||
}
|
||||
@@ -0,0 +1,176 @@
|
||||
use std::io::{self, Read};
|
||||
use std::path::PathBuf;
|
||||
|
||||
use sha2::{Digest, Sha256};
|
||||
|
||||
const EXPECTED_TEMPLATE_SHA256: &str =
|
||||
"7168E341764188E140EF591634A9D2488D7FDACDA667EE53AFD566A8034ED5DB";
|
||||
|
||||
fn err(msg: impl Into<String>) -> io::Error {
|
||||
io::Error::new(io::ErrorKind::InvalidData, msg.into())
|
||||
}
|
||||
|
||||
fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
let template_path = PathBuf::from(
|
||||
std::env::var("UML_TEMPLATE")
|
||||
.unwrap_or_else(|_| "registered_rca.oer".to_string()),
|
||||
);
|
||||
let output_dir = PathBuf::from(
|
||||
std::env::var("UML_OUTPUT_DIR").unwrap_or_else(|_| "uml_output".to_string()),
|
||||
);
|
||||
|
||||
let template_bytes = std::fs::read(&template_path)?;
|
||||
let template_sha256 = hex::encode_upper(Sha256::digest(&template_bytes));
|
||||
if template_sha256 != EXPECTED_TEMPLATE_SHA256 {
|
||||
return Err(err(format!(
|
||||
"Template SHA-256 mismatch. Expected {}, got {}",
|
||||
EXPECTED_TEMPLATE_SHA256, template_sha256
|
||||
))
|
||||
.into());
|
||||
}
|
||||
|
||||
// Decode the registered certificate. Its TBS, including its public key, is kept
|
||||
// unchanged so this tool cannot silently create a different root identity.
|
||||
let template: rasn_its::ts103097::EtsiTs103097Certificate =
|
||||
rasn::oer::decode(&template_bytes)?;
|
||||
|
||||
// The wrapper unlocks the registered P-256 key and sends its scalar over stdin.
|
||||
// It is never written to disk unencrypted.
|
||||
let mut scalar_hex = String::new();
|
||||
std::io::stdin().read_to_string(&mut scalar_hex)?;
|
||||
let scalar = hex::decode(scalar_hex.trim())?;
|
||||
if scalar.len() != 32 {
|
||||
return Err(err(format!(
|
||||
"Expected a 32-byte NIST P-256 private scalar, received {} bytes",
|
||||
scalar.len()
|
||||
))
|
||||
.into());
|
||||
}
|
||||
|
||||
let secret_key = p256::SecretKey::from_slice(&scalar)
|
||||
.map_err(|_| err("Invalid NIST P-256 private scalar"))?;
|
||||
let private_key =
|
||||
c_its::security::crypto::PrivateKey::P256(secret_key.into());
|
||||
|
||||
let tbs_cert = template.to_be_signed.clone();
|
||||
|
||||
// This is deliberately the exact encoding/signing route introduced by
|
||||
// TheEnbyperor/c-its commit e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4.
|
||||
let tbs_bytes = rasn::oer::encode(&tbs_cert)?;
|
||||
let hash_alg = c_its::security::crypto::HashAlgorithm::Sha256;
|
||||
let signature = private_key
|
||||
.sign(hash_alg, &tbs_bytes, None)
|
||||
.ok_or_else(|| err("c-its signing failed"))?;
|
||||
|
||||
let (r_hex, s_hex) = match &signature {
|
||||
c_its::security::crypto::Signature::P256(sig) => (
|
||||
hex::encode_upper(sig.r().to_bytes()),
|
||||
hex::encode_upper(sig.s().to_bytes()),
|
||||
),
|
||||
_ => return Err(err("Unexpected signature algorithm").into()),
|
||||
};
|
||||
|
||||
// Construct the certificate exactly like the upstream root generator.
|
||||
let raw_cert = rasn_its::ts103097::EtsiTs103097Certificate::try_from(
|
||||
rasn_its::ieee1609dot2::Certificate::from(
|
||||
rasn_its::ieee1609dot2::ExplicitCertificate::new(
|
||||
rasn_its::ieee1609dot2::CertificateBase {
|
||||
version: 3,
|
||||
r#type: rasn_its::ieee1609dot2::CertificateType::Explicit,
|
||||
issuer: rasn_its::ieee1609dot2::IssuerIdentifier::VSelf(
|
||||
hash_alg.into(),
|
||||
),
|
||||
to_be_signed: tbs_cert,
|
||||
signature: Some(signature.as_signature()),
|
||||
},
|
||||
)
|
||||
.map_err(|_| err("Could not construct ExplicitCertificate"))?,
|
||||
),
|
||||
)
|
||||
.map_err(|_| err("Certificate does not satisfy EtsiTs103097Certificate constraints"))?;
|
||||
|
||||
let cert = c_its::security::certs::Certificate::new(&raw_cert);
|
||||
let encoded = cert.to_bytes();
|
||||
|
||||
// Parse the actual final bytes from scratch and make the upstream c-its verifier
|
||||
// validate the self-signature.
|
||||
let reparsed = c_its::security::certs::Certificate::parse(&encoded)
|
||||
.map_err(err)?;
|
||||
let report = reparsed.report().map_err(err)?;
|
||||
|
||||
match report.signature() {
|
||||
c_its::security::certs::CertificateSignature::SelfSigned { verifies: true } => {}
|
||||
other => {
|
||||
return Err(err(format!(
|
||||
"FINAL CERTIFICATE SELF-SIGNATURE DID NOT VERIFY: {:?}",
|
||||
other
|
||||
))
|
||||
.into())
|
||||
}
|
||||
}
|
||||
|
||||
let reencoded = reparsed.to_bytes();
|
||||
if reencoded != encoded {
|
||||
return Err(err("Final certificate is not stable across parse/re-encode").into());
|
||||
}
|
||||
|
||||
let id8 = hex::encode_upper(report.id8());
|
||||
let cert_sha256 = hex::encode_upper(Sha256::digest(&encoded));
|
||||
if &cert_sha256[cert_sha256.len() - 16..] != id8 {
|
||||
return Err(err("HashedID8 does not match low-order 8 bytes of SHA-256").into());
|
||||
}
|
||||
|
||||
// Compute the IEEE/ETSI self-signed certificate signing prehash independently
|
||||
// from the signature object:
|
||||
// SHA256( SHA256(COER/OER-TBS) || SHA256(empty signer certificate) )
|
||||
let tbs_hash = Sha256::digest(&tbs_bytes);
|
||||
let empty_hash = Sha256::digest([]);
|
||||
let mut outer = Sha256::new();
|
||||
outer.update(&tbs_hash);
|
||||
outer.update(&empty_hash);
|
||||
let signing_prehash = outer.finalize();
|
||||
|
||||
std::fs::create_dir_all(&output_dir)?;
|
||||
std::fs::write(output_dir.join(format!("{}.oer", id8)), &encoded)?;
|
||||
std::fs::write(output_dir.join("tbs.oer"), &tbs_bytes)?;
|
||||
std::fs::write(
|
||||
output_dir.join("certificate_report.json"),
|
||||
serde_json::to_vec_pretty(&report)?,
|
||||
)?;
|
||||
|
||||
let signing_details = format!(
|
||||
concat!(
|
||||
"UPSTREAM_COMMIT=e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4\n",
|
||||
"TEMPLATE_SHA256={}\n",
|
||||
"CERTIFICATE_SHA256={}\n",
|
||||
"HASHEDID8={}\n",
|
||||
"TBS_LENGTH={}\n",
|
||||
"TBS_SHA256={}\n",
|
||||
"EMPTY_SHA256={}\n",
|
||||
"SIGNING_PREHASH_SHA256={}\n",
|
||||
"ECDSA_R={}\n",
|
||||
"ECDSA_S={}\n",
|
||||
"CITS_SELF_SIGNATURE_VERIFIES=true\n",
|
||||
"PARSE_REENCODE_STABLE=true\n"
|
||||
),
|
||||
template_sha256,
|
||||
cert_sha256,
|
||||
id8,
|
||||
tbs_bytes.len(),
|
||||
hex::encode_upper(tbs_hash),
|
||||
hex::encode_upper(empty_hash),
|
||||
hex::encode_upper(signing_prehash),
|
||||
r_hex,
|
||||
s_hex,
|
||||
);
|
||||
std::fs::write(output_dir.join("signing_details.txt"), signing_details)?;
|
||||
|
||||
println!("RESULT_ID8={}", id8);
|
||||
println!(
|
||||
"RESULT_CERT={}",
|
||||
output_dir.join(format!("{}.oer", id8)).display()
|
||||
);
|
||||
println!("CITS_SELF_SIGNATURE_VERIFIES=true");
|
||||
|
||||
Ok(())
|
||||
}
|
||||
Reference in New Issue
Block a user