Files
MicrOBU/obu-firmware/external/vanetza-idf/docs/idf/evidence/security-host-04/test.cfg
T
Ashin Walpola d107534eb2 Keep vanetza-idf in obu-firmware, so a plain clone builds the firmware
obu-firmware builds against the vanetza-idf C-ITS library, which until now
came from the colleague's microbu-esp32c5 tree beside the repository and was
not tracked here, so a clone of this repository could not build the firmware
it ships. The library alone is now part of obu-firmware, as
obu-firmware/external/vanetza-idf: their external/vanetza-idf at commit
cf4b99f, unchanged (9775 files; see its PROVENANCE.md). CMake takes it from
there by default; -DVANETZA_IDF_DIR still points the build elsewhere.

The rest of the colleague's tree (their own VAM firmware, PKI tooling,
station-link Python tools, the V2X2MAP bridge) stays out of this repository
and gitignored; nothing is pushed to their repository. NOTES.md, docs/06,
TODO.md and the pcap verifier's usage line point at the new location.
2026-09-24 10:56:05 +02:00

71 lines
3.5 KiB
INI

[MODULE_PARAMETERS]
// AtsSecurity, sending side of the IUT, CAM and DENM profiles (TS 103 097 clauses
// 7.1.1 and 7.1.2): the test application behind the upper tester emits a CAM
// carrier every second and a DENM carrier on UtDenmTrigger; both are signed by the
// SUT's security entity. The GN-MGMT profile cases live in etsi_security_gn.cfg.
// The test system verifies every transmission with the pool it loads from
// ./certificates (run_etsi.py --pool copies the generated pool there). Every PICS
// that would select receiving-side or unimplemented behaviour is disabled.
LibItsGeoNetworking_Pics.PICS_GN_LOCAL_GN_ADDR := {
typeOfAddress := e_initial,
stationType := e_unknown,
reserved := 0,
mid := '020000000001'O
}
LibItsGeoNetworking_Pics.PICS_GN_SECURITY := true
LibItsGeoNetworking_Pics.PICS_IS_IUT_SECURED := true
LibItsGeoNetworking_Pics.PICS_GN_BEACON_SRC := true
LibItsGeoNetworking_Pics.PICS_GN_BEACON_DST := false
LibItsGeoNetworking_Pics.PICS_GN_GUC := false
LibItsGeoNetworking_Pics.PICS_GN_GBC := false
LibItsGeoNetworking_Pics.PICS_GN_GAC := false
LibItsGeoNetworking_Pics.PICS_GN_TSB := false
LibItsGeoNetworking_Pics.PICS_GN_DAD := false
LibItsGeoNetworking_Pics.PICS_GN_SHB_DST := false
LibItsCommon_Pixits.PX_GNSS_SCENARIO_SUPPORT := false
// CAM and DENM are carried over BTP-B (TS 103 836-5-1 clause 7.2; ports 2001/2002).
LibItsGeoNetworking_Pixits.PX_GN_UPPER_LAYER := e_btpB
LibItsSecurity_Pixits.PX_CERTIFICATE_POOL_PATH := "."
LibItsSecurity_Pixits.PX_IUT_SEC_CONFIG_NAME := "certificates"
LibItsSecurity_Pixits.PX_IUT_DEFAULT_CERTIFICATE := "CERT_IUT_A_AT"
LibItsCommon_Pixits.PX_CERT_FOR_TS := "CERT_TS_A_AT"
LibItsSecurity_Pixits.PX_OTHER_ITS_AID := 141
LibItsSecurity_Pics.PICS_SEC_ITS_AID_OTHER := true
LibItsSecurity_Pics.PICS_SEC_SHA256 := true
LibItsSecurity_Pics.PICS_SEC_SHA384 := false
LibItsSecurity_Pics.PICS_SEC_NIST_P256 := true
LibItsSecurity_Pics.PICS_SEC_BRAINPOOL_P256R1 := false
LibItsSecurity_Pics.PICS_SEC_BRAINPOOL_P384R1 := false
// Receiving side and P2P distribution need SN-DECAP verification (GAP-SEC-001).
LibItsSecurity_Pics.PICS_SEC_P2P_AT_DISTRIBUTION := false
LibItsSecurity_Pics.PICS_SEC_P2P_AA_DISTRIBUTION := false
LibItsSecurity_Pics.PICS_SEC_CERTIFICATE_SELECTION := false
LibItsSecurity_Pics.PICS_SEC_CIRCULAR_REGION := false
LibItsSecurity_Pics.PICS_SEC_RECTANGULAR_REGION := false
LibItsSecurity_Pics.PICS_SEC_POLYGONAL_REGION := false
LibItsSecurity_Pics.PICS_SEC_IDENTIFIED_REGION := false
LibItsSecurity_Pics.PICS_SEC_BFK_AUTH := false
[TESTPORT_PARAMETERS]
// Official GN layer syntax; only the security keys are read by the adapter. Verification
// failures discard the IUT transmission (enable_security_checks=1) instead of passing it
// up with a warning, so a PASS below implies a signature the framework verified against
// the pool it loaded from ./certificates.
system.geoNetworkingPort.params := "GN(enable_security_checks=1,sec_db_path=./certificates)"
// CAM carrier period of the test application (TS 103 097 clause 7.1.1 profile).
system.utPort.params := "cam_carrier_ms=1000"
[LOGGING]
LogFile := "%e.%h-%r.%s"
FileMask := LOG_ALL
ConsoleMask := VERDICTOP | ERROR | WARNING | EXECUTOR
[EXECUTE]
ItsSecurity_TestCases.TC_SEC_ITSS_SND_CAM_01_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_CAM_02_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_CAM_03_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_CAM_04_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_DENM_01_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_DENM_02_BV
ItsSecurity_TestCases.TC_SEC_ITSS_SND_DENM_03_BV