Urban Mobility Lab L0 RCA !!THIS ROOT MUST NOT BE REGENERATED OR REPLACED.!! The EU CCMS L0 ECTL registration is tied to this exact certificate and key: certificate rca/AFD566A8034ED5DB.oer HashedId8 AFD566A8034ED5DB private key private/UML_L0_RCA_private_encrypted.pem algorithm NIST P-256; encrypted PKCS#8 PEM valid 2026-09-14 23:59:55 UTC through 2031-09-15 The certificate was submitted on 2026-09-11 and registered in the EU signing session on 2026-09-14. The private-key passphrase is in the separate physical envelope. Never put the key or passphrase in Git, cloud storage, Chat or email. If the key or passphrase is lost, contact the EU CCMS CPOC for revocation/re-keying; creating another local root will not restore this identity. Files: rca/AFD566A8034ED5DB.oer registered public COER certificate rca/UML_L0_RCA_public.pem matching public key rca/certificate_report.json decoded permissions/profile rca/*_2026-09-11.txt submitted descriptive information private/*.pem encrypted private key; keep offline reference-generator/ pinned Rust/c-its reproduction path CHECKSUMS.sha256 integrity values for the files above The two workflows in `reference-generator/README.md` are intentionally separate: one reproduces the registered certificate with its registered key, the other creates a new, unregistered root key and candidate certificate for testing or a deliberate EU registration/re-key process. Routine use: Use the `vidf_issue` tool. Run these commands from this directory; OpenSSL asks for the root passphrase interactively. vidf_issue show rca/AFD566A8034ED5DB.oer vidf_issue verify rca/AFD566A8034ED5DB.oer vidf_issue authority --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --name "Urban Mobility Lab L0 AA" --id UML_AA --years 3 --out chain vidf_issue ticket --issuer chain/UML_AA.oer --issuer-key chain/UML_AA.vkey --root rca/AFD566A8034ED5DB.oer --id UML_AT --hours 24 --permission 638:01 --permission 141 --permission 36:01FFFC --out chain vidf_issue verify chain/UML_AT.oer chain/UML_AA.oer rca/AFD566A8034ED5DB.oer The `.vkey` files created in `chain/` are unencrypted private keys. Keep them offline and delete them when no longer required. Tickets last 24 hours by default. Distribution lists: vidf_issue ctl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --aa chain/UML_AA.oer=https://cits-dc.uml-hamburg.de/aa/ --dc https://cits-dc.uml-hamburg.de/ --sequence 1 --out lists/ctl-AFD566A8034ED5DB.oer vidf_issue crl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --out lists/crl-AFD566A8034ED5DB.oer Increase the CTL sequence for every update. Reissue the CTL whenever the AA changes.