Files
MicrOBU/microbu-esp32c5/pki/uml-l0-rca
Ashin Walpola 0e9525162d Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
2026-09-23 17:46:40 +02:00
..

Urban Mobility Lab L0 RCA

!!THIS ROOT MUST NOT BE REGENERATED OR REPLACED.!!

The EU CCMS L0 ECTL registration is tied to this exact certificate and key:

  certificate  rca/AFD566A8034ED5DB.oer
  HashedId8    AFD566A8034ED5DB
  private key  private/UML_L0_RCA_private_encrypted.pem
  algorithm    NIST P-256; encrypted PKCS#8 PEM
  valid        2026-09-14 23:59:55 UTC through 2031-09-15

The certificate was submitted on 2026-09-11 and registered in the EU signing
session on 2026-09-14. The private-key passphrase is in the separate physical
envelope. Never put the key or passphrase in Git, cloud storage, Chat or email. If the key or passphrase is lost, contact the EU CCMS CPOC
for revocation/re-keying; creating another local root will not restore this identity.

Files:

  rca/AFD566A8034ED5DB.oer       registered public COER certificate
  rca/UML_L0_RCA_public.pem      matching public key
  rca/certificate_report.json    decoded permissions/profile
  rca/*_2026-09-11.txt           submitted descriptive information
  private/*.pem                  encrypted private key; keep offline
  reference-generator/           pinned Rust/c-its reproduction path
  CHECKSUMS.sha256               integrity values for the files above

The two workflows in `reference-generator/README.md` are intentionally separate:
one reproduces the registered certificate with its registered key, the other creates
a new, unregistered root key and candidate certificate for testing or a deliberate
EU registration/re-key process.

Routine use:

Use the `vidf_issue` tool. Run these commands from this directory;
OpenSSL asks for the root passphrase interactively.

  vidf_issue show rca/AFD566A8034ED5DB.oer
  vidf_issue verify rca/AFD566A8034ED5DB.oer
  vidf_issue authority --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --name "Urban Mobility Lab L0 AA" --id UML_AA --years 3 --out chain
  vidf_issue ticket --issuer chain/UML_AA.oer --issuer-key chain/UML_AA.vkey --root rca/AFD566A8034ED5DB.oer --id UML_AT --hours 24 --permission 638:01 --permission 141 --permission 36:01FFFC --out chain
  vidf_issue verify chain/UML_AT.oer chain/UML_AA.oer rca/AFD566A8034ED5DB.oer

The `.vkey` files created in `chain/` are unencrypted private keys. Keep them
offline and delete them when no longer required. Tickets last 24 hours by default.

Distribution lists:

  vidf_issue ctl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --aa chain/UML_AA.oer=https://cits-dc.uml-hamburg.de/aa/ --dc https://cits-dc.uml-hamburg.de/ --sequence 1 --out lists/ctl-AFD566A8034ED5DB.oer
  vidf_issue crl --issuer rca/AFD566A8034ED5DB.oer --issuer-key private/UML_L0_RCA_private_encrypted.pem --out lists/crl-AFD566A8034ED5DB.oer

Increase the CTL sequence for every update. Reissue the CTL whenever the AA changes.