menu "Vanetza-IDF" choice VANETZA_IDF_PROFILE prompt "Stack entry point" default VANETZA_IDF_PROFILE_NETWORK config VANETZA_IDF_PROFILE_ACCESS bool "Access: AL_DATA / IN-SAP" config VANETZA_IDF_PROFILE_NETWORK bool "Network: BTP-DATA / NF-SAP" config VANETZA_IDF_PROFILE_FACILITIES bool "Facilities endpoints (CAM, DENM, VAM)" endchoice config VANETZA_IDF_NETWORK bool default y if !VANETZA_IDF_PROFILE_ACCESS config VANETZA_IDF_CAM bool "Release 2 CAM codec and endpoint" default y if VANETZA_IDF_PROFILE_FACILITIES depends on VANETZA_IDF_NETWORK config VANETZA_IDF_DENM bool "Release 2 DENM codec and endpoint" default y if VANETZA_IDF_PROFILE_FACILITIES depends on VANETZA_IDF_NETWORK config VANETZA_IDF_VAM bool "Release 2 VAM codec and endpoint" default y if VANETZA_IDF_PROFILE_FACILITIES depends on VANETZA_IDF_NETWORK config VANETZA_IDF_SECURITY bool "TS 103 097 signing security entity and identifier-change service" default y depends on VANETZA_IDF_NETWORK help SN-SAP security entity: signs outgoing GeoNetworking packets with authorization tickets the application provisions (TS 103 097 V2.2.1, IEEE Std 1609.2) on the mbedTLS PSA backend and runs the TS 102 723-8 clause 6.3 identifier-change two-phase commit that the GN core, access adapter and facilities subscribe to. Without it a stack with itsGnSecurity enabled fails closed. config VANETZA_IDF_SECURITY_VERIFY bool "SN-DECAP verification of received secured packets" default y depends on VANETZA_IDF_SECURITY help Verify received EtsiTs103097Data-Signed packets (IEEE 1609.2 clause 5.2 with the TS 103 097 clause 7.1 profile checks, the certificate chain to the provisioned trust anchors, generation time plausibility and replay detection). Without it SN-DECAP reports Configuration_Problem and a strict GeoNetworking receiver drops every secured packet (docs/idf/conformance.md GAP-SEC-001). config VANETZA_IDF_NVS_CREDENTIALS bool "Credential store on NVS" default y depends on VANETZA_IDF_SECURITY help NvsCredentialStore keeps the station's provisioned credentials (root and CA certificates, authorization tickets with their private keys, credentials.hpp bundle) as one blob in the nvs_flash component's storage. The application initialises NVS and decides on NVS encryption; without this option the application supplies its own CredentialStore. config VANETZA_IDF_PKI bool "TS 102 941 enrolment and authorization request-response core" default n depends on VANETZA_IDF_SECURITY help Builds and parses EtsiTs102941Data enrolment/authorization requests and responses (TS 102 941 V2.2.1 clause 6.2.3). The transport to the EA/AA and credential storage are supplied by the application. config VANETZA_IDF_HIL bool "Upper/lower tester hooks" default n help Builds test control without enabling a UART, USB, BLE or network transport. Wire transports explicitly in the application. choice VANETZA_IDF_RADIO prompt "Access adapter" default VANETZA_IDF_RADIO_EXTERNAL config VANETZA_IDF_RADIO_EXTERNAL bool "Application-provided access adapter" config VANETZA_IDF_RADIO_C5 bool "Experimental integrated ESP32-C5 ITS-G5 radio" depends on IDF_TARGET_ESP32C5 help Uses OpenTrafficMap's private driver transmit path. Only the pinned ESP-IDF version is accepted. Hardware/RF and DCC qualification remain separate acceptance requirements. endchoice endmenu