# UML L0 RCA generation tools Both tools use the Rust/c-its certificate path pinned to commit `e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4`in https://github.com/TheEnbyperor/c-its. Requirements are Python 3.10+, `cryptography`, Git, Rust/Cargo, and internet access for the first build. ## Rebuild the registered root ```text python rebuild\_registered\_rca.py ``` Uses `private/UML\_L0\_RCA\_private\_encrypted.pem`. It succeeds only when the result is byte-for-byte identical to the registered `AFD566A8034ED5DB.oer`. Use this to prove how the registered certificate was made or to verify the registered key. It never creates a key and does not alter the registered files. ## Create a separate new root ```text python create\_new\_root.py ``` Creates a new P-256 key and candidate root certificate. It copies the registered root's reviewed TBS profile, including CertificateID, permissions, region and validity, but replaces the public key and signature. The result therefore has a different HashedId8 and is **not EU-registered**. Use this only for an isolated test root or a deliberate EU registration/re-key process. Before submission, review the inherited validity/profile and coordinate revocation or registration with the EU CCMS CPOC. Files appear under a directory named `CANDIDATE\_SUBMISSION\_NOT\_REGISTERED`; that name is a warning, not approval. In both workflows the private scalar is passed to the local Rust process through standard input and is never stored unencrypted by these tools.