Files
Ashin Walpola d107534eb2 Keep vanetza-idf in obu-firmware, so a plain clone builds the firmware
obu-firmware builds against the vanetza-idf C-ITS library, which until now
came from the colleague's microbu-esp32c5 tree beside the repository and was
not tracked here, so a clone of this repository could not build the firmware
it ships. The library alone is now part of obu-firmware, as
obu-firmware/external/vanetza-idf: their external/vanetza-idf at commit
cf4b99f, unchanged (9775 files; see its PROVENANCE.md). CMake takes it from
there by default; -DVANETZA_IDF_DIR still points the build elsewhere.

The rest of the colleague's tree (their own VAM firmware, PKI tooling,
station-link Python tools, the V2X2MAP bridge) stays out of this repository
and gitignored; nothing is pushed to their repository. NOTES.md, docs/06,
TODO.md and the pcap verifier's usage line point at the new location.
2026-09-24 10:56:05 +02:00

56 lines
1.5 KiB
C++

#pragma once
#include <vanetza/security/hashed_id.hpp>
#include <unordered_map>
#include <unordered_set>
namespace vanetza
{
namespace security
{
namespace v3
{
/**
* Lookup for HashedId8-style certificate revocation.
*
* Backs the chain-walk performed by DefaultCertificateValidator: for every
* non-root certificate the validator encounters while walking up the chain,
* it asks whether that certificate has been revoked by a CRL signed by its
* issuer.
*
* Linkage-value CRLs (TS 102 941 ToBeSignedLinkageValueCrl) are out of scope:
* the European C-ITS Certificate Policy does not revoke ATs, and revoking CAs
* only ever needs HashedId8 entries.
*/
class RevocationLookup
{
public:
virtual ~RevocationLookup() = default;
/**
* \param issuer HashedId8 of the CA whose CRL is consulted
* \param cert HashedId8 of the certificate being checked
* \return true iff the CRL signed by \p issuer lists \p cert as revoked
*/
virtual bool is_revoked(const HashedId8& issuer, const HashedId8& cert) const = 0;
};
/**
* In-memory RevocationLookup, indexed by issuer HashedId8.
*/
class RevocationMemoryLookup : public RevocationLookup
{
public:
void revoke(const HashedId8& issuer, const HashedId8& cert);
void clear(const HashedId8& issuer);
bool is_revoked(const HashedId8& issuer, const HashedId8& cert) const override;
private:
std::unordered_map<HashedId8, std::unordered_set<HashedId8>> m_revoked;
};
} // namespace v3
} // namespace security
} // namespace vanetza