Repository navigation
[C] SU: trust root key ADU.241112.R - #408
Merged
Ewerton Scaboro da Silva (ewertons) merged 2 commits intoOct 10, 2026
Merged
Conversation
Add Microsoft's production root key ADU.241112.R to az_iot_su_microsoft_root_keys(), so updates signed under it verify. The key comes from Microsoft's published root key package (version 2); that package's signatures verify under ADU.200702.R and ADU.200703.R. Raise the AZ_IOT_SU_MAX_ROOT_KEYS default from 4 to 8: with three Microsoft roots, 4 left room for only one more root.
Ewerton Scaboro da Silva (ewertons)
requested review from
Avishek (avishekpant) and
Maxim Semenov (maximsemenov80)
as code owners
October 10, 2026 16:59
Copilot started reviewing on behalf of
Ewerton Scaboro da Silva (ewertons)
October 10, 2026 16:59
View session
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The security-critical modulus is not validated by a real cryptographic known-answer test.
1 open finding
What changed in this PR
Adds Microsoft’s ADU.241112.R production trust root for Software Update manifest verification.
Changes:
- Embeds the new RSA-3072 root and increases trust-store capacity to eight.
- Adds root-selection tests and updates configuration documentation.
- Documents the expanded Microsoft root set.
| File | Description |
|---|---|
c/src/features/su/su_root_keys_microsoft.c |
Adds the new root key. |
c/src/features/su/su_client.c |
Updates root-key commentary. |
c/inc/azure/iot/az_iot_su.h |
Raises default root capacity. |
c/tests/unit/su_client_test.c |
Tests root enumeration and selection. |
c/docs/client-configuration.md |
Documents the new capacity. |
c/docs/eng/software-updates.md |
Updates the design documentation. |
c/docs/eng/test-coverage.md |
Records the added tests. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Add the published root key package's signed bytes and RS256 signatures as known answers. The crypto contract suite verifies each compiled-in Microsoft root against its signature with every crypto backend, and rejects a modulus with one byte changed.
Copilot started reviewing on behalf of
Ewerton Scaboro da Silva (ewertons)
October 10, 2026 17:07
View session
Ewerton Scaboro da Silva (ewertons)
left a comment
Contributor
Author
There was a problem hiding this comment.
Approved
Ewerton Scaboro da Silva (ewertons)
deleted the
ewertons/su-root-adu-241112
branch
October 10, 2026 18:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What
ADU.241112.R(RSA-3072, e=65537) toaz_iot_su_microsoft_root_keys(), afterADU.200702.RandADU.200703.R.AZ_IOT_SU_MAX_ROOT_KEYSdefault from 4 to 8. With 3 Microsoft roots, 4 left room for only one more root, and the SU e2e suite passes 3 Microsoft roots and 2 test roots (5).ADU.241112.Ris verified with that root's modulus.client-configuration.md,software-updates.md,test-coverage.md).Why
Updates signed with a signing key that chains to
ADU.241112.Rfail verification: the SDK does not have that root.How the key was verified
isTest: false, 3 roots, 3 signatures).protectedobject were checked against the existing roots. They verify underADU.200702.RandADU.200703.R, using the key bytes already in the SDK. The serialization is the same compact form the Device Update agent uses.Testing
az_iot_tests_crypto_openssl: 15/15 passed.az_iot_tests_su_client: 152/152 passed.eng/code-style.sh check(clang-format 18): clean.