Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but that tree was gitignored, so a clone of this repository could not build the firmware it ships. It is now committed here as ordinary files in its own folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP bridge's signature verification (--trust) used on the bench. Nothing is fetched from or pushed to the colleague's repository; this repository and its remotes carry everything. The folder's own .gitignore keeps build output, downloaded components and private key material out, as it did there; the committed file set is identical to that repository's tracked files. The ESP32-C5 is still flashed from obu-firmware/, which only takes vanetza-idf from microbu-esp32c5/, so the two stay separate folders. FLASHING.md says how to take a newer version of the colleague's tree (copy it over the folder, rebuild, test, commit).
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# UML L0 RCA generation tools
|
||||
|
||||
Both tools use the Rust/c-its certificate path pinned to commit
|
||||
`e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4`in https://github.com/TheEnbyperor/c-its. Requirements are Python 3.10+,
|
||||
`cryptography`, Git, Rust/Cargo, and internet access for the first build.
|
||||
|
||||
## Rebuild the registered root
|
||||
|
||||
```text
|
||||
python rebuild\_registered\_rca.py
|
||||
```
|
||||
|
||||
Uses `private/UML\_L0\_RCA\_private\_encrypted.pem`. It succeeds only when the result is
|
||||
byte-for-byte identical to the registered `AFD566A8034ED5DB.oer`. Use this to prove
|
||||
how the registered certificate was made or to verify the registered key. It never
|
||||
creates a key and does not alter the registered files.
|
||||
|
||||
## Create a separate new root
|
||||
|
||||
```text
|
||||
python create\_new\_root.py
|
||||
```
|
||||
|
||||
Creates a new P-256 key and candidate root certificate. It copies the registered
|
||||
root's reviewed TBS profile, including CertificateID, permissions, region and
|
||||
validity, but replaces the public key and signature. The result therefore has a
|
||||
different HashedId8 and is **not EU-registered**.
|
||||
|
||||
Use this only for an isolated test root or a deliberate EU registration/re-key
|
||||
process. Before submission, review the inherited validity/profile and coordinate
|
||||
revocation or registration with the EU CCMS CPOC. Files appear under a directory
|
||||
named `CANDIDATE\_SUBMISSION\_NOT\_REGISTERED`; that name is a warning, not approval.
|
||||
|
||||
In both workflows the private scalar is passed to the local Rust process through
|
||||
standard input and is never stored unencrypted by these tools.
|
||||
|
||||
Reference in New Issue
Block a user