obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but that tree was gitignored, so a clone of this repository could not build the firmware it ships. It is now committed here as ordinary files in its own folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP bridge's signature verification (--trust) used on the bench. Nothing is fetched from or pushed to the colleague's repository; this repository and its remotes carry everything. The folder's own .gitignore keeps build output, downloaded components and private key material out, as it did there; the committed file set is identical to that repository's tracked files. The ESP32-C5 is still flashed from obu-firmware/, which only takes vanetza-idf from microbu-esp32c5/, so the two stay separate folders. FLASHING.md says how to take a newer version of the colleague's tree (copy it over the folder, rebuild, test, commit).
45 lines
1.5 KiB
C++
45 lines
1.5 KiB
C++
#pragma once
|
|
|
|
#include "security_module.hpp"
|
|
#include <boost/optional/optional.hpp>
|
|
|
|
namespace vanetza
|
|
{
|
|
namespace pki
|
|
{
|
|
|
|
class CredentialStorage;
|
|
|
|
class OpenSslSecurityModule : public SecurityModule
|
|
{
|
|
public:
|
|
OpenSslSecurityModule(std::shared_ptr<CredentialStorage>);
|
|
|
|
Sha256Hash calculate_sha256_hash(const std::uint8_t* buffer, std::size_t length) override;
|
|
Sha384Hash calculate_sha384_hash(const std::uint8_t* buffer, std::size_t length) override;
|
|
bool verify(const Sha256Hash&, const Signature&, const PublicKey&) override;
|
|
bool verify(const Sha384Hash&, const Signature&, const PublicKey&) override;
|
|
ByteBuffer generate_nonce(std::size_t length) override;
|
|
std::unique_ptr<EciesContext> create_ecies_context(const PublicKey& receiver, const Sha256Hash& info) override;
|
|
ByteBuffer calculate_hmac_sha256(const ByteBuffer& key, const ByteBuffer& data) override;
|
|
|
|
boost::optional<Signature> sign(const ByteBuffer& data, const PublicKey&) override;
|
|
|
|
/**
|
|
* Creates a new public and private key pair.
|
|
* The private key is intentionally not returned but only stored in the credential storage.
|
|
*/
|
|
PublicKey create_key(KeyType) override;
|
|
|
|
bool discard_key(const PublicKey&) override;
|
|
|
|
private:
|
|
bool verify(const uint8_t* digest, std::size_t dlen, const Signature&, const PublicKey&);
|
|
boost::optional<Signature> sign(const ByteBuffer&, const PrivateKey&);
|
|
|
|
std::shared_ptr<CredentialStorage> m_credential_storage;
|
|
};
|
|
|
|
} // namespace pki
|
|
} // namespace vanetza
|