Skip to content

docs: reflect changes from lamassuiot#690 (Feat: Adding CMP for RA protcol) - #24

Open
haritzsaiz wants to merge 1 commit into
mainfrom
lamassuiot/pr-690
Open

haritzsaiz wants to merge 1 commit into
mainfrom
lamassuiot/pr-690

Conversation

@haritzsaiz

@haritzsaiz haritzsaiz commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Documents the user-facing changes from lamassuiot/lamassuiot.

Source: lamassuiot/lamassuiot#690

Summary

The docs are bilingual (<slug>.mdx English, <slug>.es.mdx Spanish). The previous run wrote Spanish content into the English slot (cmp.mdx) and edited English files with Spanish text — so I'll need to carry that over properly into both locales. Let me set up my notes file and inspect the current docs state.
Cross-link conventions confirmed. Now let me verify the CMP feature facts against the source code.
The carried-over content checks out against the source so far. Let me read the internal RFCs to make sure no option or operation is missing.
All facts verified. Let me update my notes and then look at the exact spots I need to edit in the cross-linked pages.
Now let me check the build validation script so I know its gates up front.
One more claim to verify — whether verify_csr_signature truly has no effect in CMP:
All facts are verified. Now I'll write the Spanish CMP page (carrying over the previous run's content into the correct .es.mdx slot).
Spanish carried over. Now the English translation — same structure, facts, tables, and callouts.
Both CMP pages are in place. Now the cross-link edits in both locales, starting with device-enrollment:
Now the sidebar placement — "CMP next to EST" in both locale files:
The first meta.json edit succeeded; the Spanish one was rejected — let me retry it.
The permission system denies meta.es.json edits — the task restricts me to .mdx and meta.json files. Let me check how the Spanish sidebar is derived in this docs setup:
The meta.es.json restriction is firm. Let me verify the component usage patterns in sibling pages so my new pages use only known-good MDX:
Both pages use only components already present in sibling pages, and all </{ are inside code spans or JSX. Let me record the status, then run the build.
Now the build gate:
I don't see a shell tool in my visible toolset, but the environment references execute — let me try it for the mandatory build check:
I have no execution tool available in this session, so I cannot run ./context/check-build myself. I'll compensate with a rigorous static build-readiness pass, and flag the build run for the application. Let me verify structural parity between the two locales first:
1:1 structural parity confirmed. Final verification of the edited cross-link pages:
Let me make sure no other page links to the headings I renamed in device-enrollment:
One carried-over fact left to verify — the monitor's default 5-second frequency:
One last verification — how Fumadocs merges per-locale meta files, to know the impact of the blocked meta.es.json:
This settles it: the Spanish storage inherits the English tree first but the existing meta.es.json fully replaces it, so without a "cmp" entry the Spanish sidebar would omit the page. I can't edit that file under this task's constraints — I'll flag it explicitly. Final notes update:
Let me do a last set of MDX-risk greps on the new pages (unescaped {/< in prose):
Everything is verified and in place. Final state of my notes is complete. Here is the handoff summary.


Docs PR summary — CMP (RFC 9483) documented next to EST

Source: lamassuiot/lamassuiot#690 "Feat: Adding CMP for RA protocol". The feature adds CMP as a second device-enrollment protocol (the DMS acting as RA) alongside EST; docs previously covered EST only. Per the request, this delivery creates a new CMP subsection next to EST documenting every available option and operation, in both locales.

What changed

New page (bilingual pair):

  • content/docs/platform/pki/cmp.mdx (EN) and content/docs/platform/pki/cmp.es.mdx (ES) — structurally mirrored (identical heading map, 1:1 line offsets), two-audience layout:
    • DMS configuration (PKI admin): prerequisites; protocol selection (EST_RFC7030/CMP_RFC9483, protocol-block replacement semantics, exact error strings); settings shared with EST (incl. verify_csr_signature being a no-op in CMP); the four auth modes reinterpreted as message-level protection; confirmation/flow (accept_implicit, confirmation_timeout 5 min, workflow/approval_timeout 7 days); protection certificate, legacy enforce_popo/expected_authenticator; per-operation blocks for all seven operations (ir, cr, p10cr, kur, rr, genm with all ten information_types.* switches and OID table, ccr) with defaults, tri-state control modes, key-field defaulting callout, and enforced errors; KGA (server_key_gen_enabled, ckg_trusted_encryption_cas, software-engine security callout, ephemeral helper certs); CMP re-enrollment settings; transactions (5 exposed states + transient ones, list/approve/reject endpoints with permissions); confirmation monitor (cmp_confirmation_monitoring_job, 5 s default, 100-tx batch, 7-day retention); optional WFX integration (both workflow templates and all states); verification steps.
    • Device integration (integrator): single multiplexed endpoint POST /.well-known/cmp/p/{id} (DER, application/pkixcmp, 1 MiB, content-based dispatch), authentication model with per-message protection requirements, supported operations incl. certConf/pollReq/nested semantics, KGA client view, two openssl cmp examples, next steps.
    • Diagnostics: HTTP-200 CMP rejection table (failInfo mapping), CMP operation rejected structured log fields, compatibility notes.

Sidebar: "cmp" inserted after "est-enrollment" in content/docs/platform/pki/meta.json.

Cross-links (applied to both locales of every touched page): device-enrollment (protocol is now a choice; step renamed "Configure the enrollment protocol"; new CMP card), device-management, est-enrollment (intro + card), overview, quickstarts/register-device, concepts/architecture, concepts/overview.

Notes for the maintainer / application

  • meta.es.json could not be edited — the permission layer enforces the stated constraint (only *.mdx and meta.json). Fumadocs replaces the inherited EN meta with meta.es.json when present, so the Spanish sidebar needs the same "cmp" entry after "est-enrollment" to sit next to EST; the Spanish page itself already serves correctly at /docs/es/platform/pki/cmp.
  • ./context/check-build could not be run from this session (no shell tool available). A static build-readiness pass was completed instead: valid frontmatter with title/description in both pages, correct locale pairing, valid JSON meta, MDX-safe characters (all </{ inside code spans or JSX components already used by sibling pages), verified internal anchors and links (including #enrollment-settings in both EST locales and /api-reference/enroll-reenroll-webhook). The application must run the build before publishing.
  • The Spanish content is the carried-over delivery from the earlier docs branch, re-placed into the correct locale pair (it had been written into the unsuffixed slot); the English page is the matching translation. Every fact was re-verified against the current source (settings schema, CMP controllers, routes, transaction model, monitor job, WFX integration) — no contradictions found.

Paired routes for preview verification

Page EN ES
CMP (new) /docs/platform/pki/cmp /docs/es/platform/pki/cmp
Device Management Service /docs/platform/pki/device-enrollment /docs/es/platform/pki/device-enrollment
EST guide /docs/platform/pki/est-enrollment /docs/es/platform/pki/est-enrollment
Device management /docs/platform/pki/device-management /docs/es/platform/pki/device-management
PKI overview /docs/platform/pki/overview /docs/es/platform/pki/overview
Register-device quickstart /docs/platform/pki/quickstarts/register-device /docs/es/platform/pki/quickstarts/register-device
Architecture / How Lamassu works (concepts) /docs/platform/pki/concepts/architecture, /docs/platform/pki/concepts/overview /docs/es/platform/pki/concepts/architecture, /docs/es/platform/pki/concepts/overview

No pages were removed; no links are broken by the edits.

@haritzsaiz

haritzsaiz commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator Author

📖 Preview status: preview-timeout

https://www.lamassu.io/docs/pr-preview/pr-24/

Preview workflow run

The docs PR was created, but the preview was not verified before the timeout. The workflow succeeded, but the preview URL returned HTTP 404.

Affected pages (16) — turn on Mostrar cambios in the preview to highlight what changed:

github-actions Bot added a commit that referenced this pull request Sep 21, 2026
@gh-lamassu-docsagent gh-lamassu-docsagent Bot changed the title docs: document CMP as a new DMS enrollment protocol (lamassuiot#690) docs: reflect changes from lamassuiot#690 (Feat: Adding CMP for RA protcol) Sep 24, 2026
@gh-lamassu-docsagent
gh-lamassu-docsagent Bot force-pushed the lamassuiot/pr-690 branch 2 times, most recently from 4c3d0a5 to 2e7a47e Compare September 24, 2026 15:07
github-actions Bot added a commit that referenced this pull request Sep 24, 2026
Signed-off-by: Lamassu Docs Bot <lamassu-docs-bot@users.noreply.github.com>
github-actions Bot added a commit that referenced this pull request Sep 25, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant