Skip to content

[C] SU: trust root key ADU.241112.R - #408

Merged
Ewerton Scaboro da Silva (ewertons) merged 2 commits into
mainfrom
ewertons/su-root-adu-241112
Oct 10, 2026
Merged

Ewerton Scaboro da Silva (ewertons) merged 2 commits into
mainfrom
ewertons/su-root-adu-241112

Conversation

@ewertons

@ewertons Ewerton Scaboro da Silva (ewertons) commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

What

  • Add Microsoft production root key ADU.241112.R (RSA-3072, e=65537) to az_iot_su_microsoft_root_keys(), after ADU.200702.R and ADU.200703.R.
  • Raise the AZ_IOT_SU_MAX_ROOT_KEYS default from 4 to 8. With 3 Microsoft roots, 4 left room for only one more root, and the SU e2e suite passes 3 Microsoft roots and 2 test roots (5).
  • Unit tests:
    • The root list is exactly these 3 kids, in order, each with a 3072-bit modulus.
    • A manifest whose signing key chains to ADU.241112.R is verified with that root's modulus.
  • Known-answer test (crypto contract suite, every crypto backend): each compiled-in root verifies its signature on the published root key package; a modulus with one byte changed is rejected.
  • Docs updated (client-configuration.md, software-updates.md, test-coverage.md).

Why

Updates signed with a signing key that chains to ADU.241112.R fail verification: the SDK does not have that root.

How the key was verified

  • The key comes from Microsoft's published production root key package (version 2, isTest: false, 3 roots, 3 signatures).
  • Before the key was used, the package's RS256 signatures over the serialized protected object were checked against the existing roots. They verify under ADU.200702.R and ADU.200703.R, using the key bytes already in the SDK. The serialization is the same compact form the Device Update agent uses.
  • The C arrays in this change were then checked with OpenSSL: each of the 3 roots verifies its package signature.

Testing

  • Local Linux gcc debug build.
  • ctest: 44/44 passed; az_iot_tests_crypto_openssl: 15/15 passed.
  • az_iot_tests_su_client: 152/152 passed.
  • eng/code-style.sh check (clang-format 18): clean.

Add Microsoft's production root key ADU.241112.R to
az_iot_su_microsoft_root_keys(), so updates signed under it verify.
The key comes from Microsoft's published root key package (version 2);
that package's signatures verify under ADU.200702.R and ADU.200703.R.

Raise the AZ_IOT_SU_MAX_ROOT_KEYS default from 4 to 8: with three
Microsoft roots, 4 left room for only one more root.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The security-critical modulus is not validated by a real cryptographic known-answer test.

1 open finding
What changed in this PR

Adds Microsoft’s ADU.241112.R production trust root for Software Update manifest verification.

Changes:

  • Embeds the new RSA-3072 root and increases trust-store capacity to eight.
  • Adds root-selection tests and updates configuration documentation.
  • Documents the expanded Microsoft root set.
File Description
c/​src/​features/​su/​su_root_keys_microsoft.c Adds the new root key.
c/​src/​features/​su/​su_client.c Updates root-key commentary.
c/​inc/​azure/​iot/​az_iot_su.h Raises default root capacity.
c/​tests/​unit/​su_client_test.c Tests root enumeration and selection.
c/​docs/​client-configuration.md Documents the new capacity.
c/​docs/​eng/​software-updates.md Updates the design documentation.
c/​docs/​eng/​test-coverage.md Records the added tests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread c/tests/unit/su_client_test.c
Add the published root key package's signed bytes and RS256 signatures as
known answers. The crypto contract suite verifies each compiled-in
Microsoft root against its signature with every crypto backend, and
rejects a modulus with one byte changed.
Copilot AI balanced review requested due to automatic review settings October 10, 2026 17:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The implementation is consistent and tested, but adding a production trust anchor warrants final human provenance review.

1 open finding

🧠 Review effort: Balanced

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@ewertons
Ewerton Scaboro da Silva (ewertons) merged commit 8aaf81f into main Oct 10, 2026
54 checks passed
@ewertons
Ewerton Scaboro da Silva (ewertons) deleted the ewertons/su-root-adu-241112 branch October 10, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants