{"service":"Castell · Open V2X PKI Testbed","tagline":"Built up. Taken down. Never fallen.","version":"0.9.12","release_date":"2026-08-30","operator":"SkyV2X","public_url":"https://pki.skyv2x.com","disclaimer":"ETSI / CCMS wire-aligned open testbed for V2X integrators. NOT a certified CCMS Trust Point. Best-effort operation.","spec_compliance":{"ts_102_940":"v2.1.1 architecture","ts_102_941":"v1.3.1 wire OER + v2.2.1 protocol semantics","ts_103_097":"v1.3.1 cert format COER","ts_103_759":"v2.1.1 misbehaviour reporting (MA-ready)","ieee_1609_2":"2016/2022 security services"},"curves_supported":[{"name":"NIST P-256","asn1":"ecdsaNistP256","rfc":"RFC 6090 / FIPS 186-5"},{"name":"Brainpool P-256r1","asn1":"ecdsaBrainpoolP256r1","rfc":"RFC 5639"},{"name":"Brainpool P-384r1","asn1":"ecdsaBrainpoolP384r1","rfc":"RFC 5639"}],"authorization_modes":{"supported":["single"],"butterfly_supported":false,"note":"Castell implements single authorization (one AT per request). Butterfly key authorization (batched, fleet-oriented) is not implemented. The spec allows either as a conformance path."},"tlm_rotation":{"link_certificate_endpoint":"/gettlmlinkcertificate[/{hashedId8}]","link_certificate_present":false,"current_tlm_hashedid8":"0A065E9D1B8D241A","note":"Castell publishes a TLM Link Certificate Message per TS 102 941 §6.4.2.1 when the TLM is rotated. Until then the endpoint returns 404 with a structured detail; clients should treat this as 'no rotation yet'."},"trust_anchors":{"tlm":{"url":"/tlm","hashedId8":"0A065E9D1B8D241A","sha256":"953eb171fc965501a9b4bd3cdbff5ae970a2e0add3b0ad510a065e9d1b8d241a","role":"Trust List Manager (top-of-trust)"},"root_ca":{"url":"/trustanchor","hashedId8":"FA8B241AD2E9DBE7","sha256":"f55a120810944269e20b59f83c2bb373824152309f255642fa8b241ad2e9dbe7","role":"Root Certificate Authority"},"ma":{"url":"/ma","hashedId8":"1051D873785C203B","sha256":"ed5b54899d36c56d44e3136aa93254282a5666d8b441152c1051d873785c203b","role":"Misbehaviour Authority (TS 103 759)"}},"endpoints":{"trust_material":{"GET /trustanchor":"RCA cert (COER)","GET /tlm":"TLM cert (COER, TS 102 940)","GET /ma":"MA cert (COER, TS 103 759)","GET /cert/{name}":"Cert by name (root/tlm/ea/aa/ma/at{1..5})","GET /ca/{hashedId8}":"CA cert lookup by HashedId8","GET /getcacertificate/{hashedId8}":"CPOC-style alias","GET /lookup/{hashedId8}":"Generic cert lookup"},"trust_lists":{"GET /getectl":"ECTL signed by TLM (TS 102 941)","GET /ectl/federation":"Federated RCA list (transparency)","GET /getctl/{hashedId8}":"RCA CTL (TS 102 941)","GET /getctl/{hashedId8}/{seq}":"Delta CTL by sequence","GET /getcrl/{hashedId8}":"CRL signed by RCA (TS 102 941)","GET /getcrl/{hashedId8}/{seq}":"Delta CRL by sequence","GET /gettlmlinkcertificate":"TLM Link Certificate (TS 102 941 §6.4.2.1) — 404 until TLM rotates","GET /gettlmlinkcertificate/{hashedId8}":"TLM Link Cert by OLD HID8 (CPOC v3.2 §I.5.3)"},"enrolment_authorization":{"POST /ec-request":"EnrolmentRequest (TS 102 941)","POST /at-request":"AuthorizationRequest (TS 102 941)","POST /v221/ec-request-decode":"Decode EC request debug (Pull-VPC-5)","POST /v221/at-request-decode":"Decode wire spec-strict TS 102 941 v2.2.1 (compliance proof)"},"misbehaviour":{"POST /mr":"Misbehaviour Report — testbed API (202 + JSON verification result)","POST /uploadMR-v1":"MR upload spec-strict TS 103 759 clause 5.3 (alias of /SignedAndEncrypted)","POST /uploadMR-v1/SignedAndEncrypted":"ECIES(signedData) canonical variant — 200 empty on success","POST /uploadMR-v1/Signed":"signedData variant — 200 empty on success","POST /uploadMR-v1/Plain":"unsigned variant NOT supported (400) — this MA requires signed MRs","reporter_requirements":"AT with PSID 1618 + BitmapSsp per clause 8.1.2 (2 octets, bits 80h/40h); signer digest; generationTime within AT validity","versions":{"v2.2.1":"EtsiTs103759Mbr (Time64 + ThreeDLocation) — CAM/DENM TemplateAsr containers structural, per-observation catalog captured opaque","v2.1.1":"EtsiTs103759Data — full structural ASR (legacy ecosystem)"},"version_negotiation":"try-decode v2.2.1 first, fallback v2.1.1; /uploadMR-v1 rejects payloads undecodable under both, /mr (debug) accepts and reports the error","reaction":"verified reports are counted per offender (from v2xPduEvidence); crossing the threshold flags the AT as revocation candidate — revocation itself is a manual authority decision, then published via CRL"},"transparency":{"GET /conformance":"Subset chain audit ULTRA-STRICT (IEEE 1609.2 §5.1.2) — gaps detection"},"scms_ieee_1609_2_1":{"POST /scms/eca/enroll":"ECA enrollment (IEEE 1609.2.1 §6.1 ScmsPdu)","POST /scms/aca/cert-request":"ACA butterfly cert request (IEEE 1609.2.1 §8.2 ScmsPdu)","POST /scms/decode":"Decode ScmsPdu OER → JSON (compliance proof)","GET /scms/discovery":"SCMS discovery (supported interfaces + wire formats)","GET /scms/bridge":"CCMS↔SCMS bridge mapping documentation"}},"rate_limits":{"GET endpoints":"60/min/IP","POST /ec-request":"10/min/IP","POST /at-request":"30/min/IP","POST /mr":"60/min/IP"}}