Files
MicrOBU/microbu-esp32c5/pki/uml-l0-rca/reference-generator/README.md
T
Ashin Walpola 0e9525162d Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
2026-09-23 17:46:40 +02:00

1.5 KiB

UML L0 RCA generation tools

Both tools use the Rust/c-its certificate path pinned to commit e3bb3b82480d6df4237e2a8c35ea0dd7eade25b4in https://github.com/TheEnbyperor/c-its. Requirements are Python 3.10+, cryptography, Git, Rust/Cargo, and internet access for the first build.

Rebuild the registered root

python rebuild\_registered\_rca.py

Uses private/UML\_L0\_RCA\_private\_encrypted.pem. It succeeds only when the result is byte-for-byte identical to the registered AFD566A8034ED5DB.oer. Use this to prove how the registered certificate was made or to verify the registered key. It never creates a key and does not alter the registered files.

Create a separate new root

python create\_new\_root.py

Creates a new P-256 key and candidate root certificate. It copies the registered root's reviewed TBS profile, including CertificateID, permissions, region and validity, but replaces the public key and signature. The result therefore has a different HashedId8 and is not EU-registered.

Use this only for an isolated test root or a deliberate EU registration/re-key process. Before submission, review the inherited validity/profile and coordinate revocation or registration with the EU CCMS CPOC. Files appear under a directory named CANDIDATE\_SUBMISSION\_NOT\_REGISTERED; that name is a warning, not approval.

In both workflows the private scalar is passed to the local Rust process through standard input and is never stored unencrypted by these tools.