Public Access
- scripts/ota_keygen.sh: ECDSA P-256 key pair; the private key goes to ~/.config/roro9stack/ (0600), the public key to keys/ and src/platform/ota_public_key.h; .gitignore refuses *key.pem - scripts/make_ota.py: wraps firmware.bin into a signed .ota (openssl) - scripts/ota_push.py: sends it over TCP 3232, prints the device's answer - scripts/flash.sh --ota <host>: build, sign, push Checked: a generated .ota has the documented layout and its signature verifies with openssl against the committed public key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
13 lines
474 B
C++
13 lines
474 B
C++
#pragma once
|
|
|
|
// Public key that Firmware Updates must be signed for (ECDSA P-256). Generated by
|
|
// scripts/ota_keygen.sh; the private key is not in this repository (ADR 0003).
|
|
namespace roro {
|
|
inline constexpr char kOtaPublicKeyPem[] =
|
|
"-----BEGIN PUBLIC KEY-----\n"
|
|
"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEIWzT07fvTpQxWjTdewMipYH6f42+\n"
|
|
"mM8niHm+T8y+Mvjanb3H8hpYXg3VjuJGFtcHw/hFX0Q2f2AiSHMF0DhMbQ==\n"
|
|
"-----END PUBLIC KEY-----\n"
|
|
;
|
|
} // namespace roro
|