Files
MicrOBU/microbu-esp32c5/external/vanetza-idf/docs/idf/evidence/security-host-03/test.cfg
T
Ashin Walpola 0e9525162d Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
2026-09-23 17:46:40 +02:00

71 lines
3.4 KiB
INI

[MODULE_PARAMETERS]
// AtsSecurity, sending side of the IUT, GN-MGMT profile (TS 103 097 clause 7.1.3):
// the SUT (vidf_sut --security-pool) signs its own beacons through the GN core. No
// facilities traffic is stimulated because an SHB restarts the beacon timer
// (TS 103 836-4-1 clause 10.3.5) and the CAM/DENM profile cases live in
// etsi_security_facilities.cfg. The test system verifies every transmission with
// the pool it loads from ./certificates (run_etsi.py --pool copies the generated
// pool there). Every PICS that would select receiving-side or unimplemented
// behaviour is disabled.
LibItsGeoNetworking_Pics.PICS_GN_LOCAL_GN_ADDR := {
typeOfAddress := e_initial,
stationType := e_unknown,
reserved := 0,
mid := '020000000001'O
}
LibItsGeoNetworking_Pics.PICS_GN_SECURITY := true
LibItsGeoNetworking_Pics.PICS_IS_IUT_SECURED := true
LibItsGeoNetworking_Pics.PICS_GN_BEACON_SRC := true
LibItsGeoNetworking_Pics.PICS_GN_BEACON_DST := false
LibItsGeoNetworking_Pics.PICS_GN_GUC := false
LibItsGeoNetworking_Pics.PICS_GN_GBC := false
LibItsGeoNetworking_Pics.PICS_GN_GAC := false
LibItsGeoNetworking_Pics.PICS_GN_TSB := false
LibItsGeoNetworking_Pics.PICS_GN_DAD := false
LibItsGeoNetworking_Pics.PICS_GN_SHB_DST := false
LibItsCommon_Pixits.PX_GNSS_SCENARIO_SUPPORT := false
LibItsSecurity_Pixits.PX_CERTIFICATE_POOL_PATH := "."
LibItsSecurity_Pixits.PX_IUT_SEC_CONFIG_NAME := "certificates"
LibItsSecurity_Pixits.PX_IUT_DEFAULT_CERTIFICATE := "CERT_IUT_A_AT"
LibItsCommon_Pixits.PX_CERT_FOR_TS := "CERT_TS_A_AT"
LibItsSecurity_Pixits.PX_OTHER_ITS_AID := 141
LibItsSecurity_Pics.PICS_SEC_ITS_AID_OTHER := true
LibItsSecurity_Pics.PICS_SEC_SHA256 := true
LibItsSecurity_Pics.PICS_SEC_SHA384 := false
LibItsSecurity_Pics.PICS_SEC_NIST_P256 := true
LibItsSecurity_Pics.PICS_SEC_BRAINPOOL_P256R1 := false
LibItsSecurity_Pics.PICS_SEC_BRAINPOOL_P384R1 := false
// Receiving side and P2P distribution need SN-DECAP verification (GAP-SEC-001).
LibItsSecurity_Pics.PICS_SEC_P2P_AT_DISTRIBUTION := false
LibItsSecurity_Pics.PICS_SEC_P2P_AA_DISTRIBUTION := false
LibItsSecurity_Pics.PICS_SEC_CERTIFICATE_SELECTION := false
LibItsSecurity_Pics.PICS_SEC_CIRCULAR_REGION := false
LibItsSecurity_Pics.PICS_SEC_RECTANGULAR_REGION := false
LibItsSecurity_Pics.PICS_SEC_POLYGONAL_REGION := false
LibItsSecurity_Pics.PICS_SEC_IDENTIFIED_REGION := false
LibItsSecurity_Pics.PICS_SEC_BFK_AUTH := false
[TESTPORT_PARAMETERS]
// Official GN layer syntax; only the security keys are read by the adapter. Verification
// failures discard the IUT transmission (enable_security_checks=1) instead of passing it
// up with a warning, so a PASS below implies a signature the framework verified against
// the pool it loaded from ./certificates.
system.geoNetworkingPort.params := "GN(enable_security_checks=1,sec_db_path=./certificates)"
// No CAM carrier: the IUT is requested to send secured beacons only.
system.utPort.params := "cam_carrier_ms=0"
[LOGGING]
LogFile := "%e.%h-%r.%s"
FileMask := LOG_ALL
ConsoleMask := VERDICTOP | ERROR | WARNING | EXECUTOR
[EXECUTE]
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_01_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_02_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_03_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_04_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_05_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_06_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_07_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_GENMSG_08_BV