Repository navigation
docs: reflect changes from lamassuiot#690 (Feat: Adding CMP for RA protcol) - #24
Open
haritzsaiz wants to merge 1 commit into
Open
haritzsaiz wants to merge 1 commit into
haritzsaiz wants to merge 1 commit into
Conversation
Collaborator
Author
gh-lamassu-docsagent
Bot
force-pushed
the
lamassuiot/pr-690
branch
2 times, most recently
from
September 24, 2026 15:07
4c3d0a5 to
2e7a47e
Compare
Signed-off-by: Lamassu Docs Bot <lamassu-docs-bot@users.noreply.github.com>
gh-lamassu-docsagent
Bot
force-pushed
the
lamassuiot/pr-690
branch
from
September 25, 2026 10:59
2e7a47e to
e77880f
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the user-facing changes from lamassuiot/lamassuiot.
Source: lamassuiot/lamassuiot#690
Summary
The docs are bilingual (
<slug>.mdxEnglish,<slug>.es.mdxSpanish). The previous run wrote Spanish content into the English slot (cmp.mdx) and edited English files with Spanish text — so I'll need to carry that over properly into both locales. Let me set up my notes file and inspect the current docs state.Cross-link conventions confirmed. Now let me verify the CMP feature facts against the source code.
The carried-over content checks out against the source so far. Let me read the internal RFCs to make sure no option or operation is missing.
All facts verified. Let me update my notes and then look at the exact spots I need to edit in the cross-linked pages.
Now let me check the build validation script so I know its gates up front.
One more claim to verify — whether
verify_csr_signaturetruly has no effect in CMP:All facts are verified. Now I'll write the Spanish CMP page (carrying over the previous run's content into the correct
.es.mdxslot).Spanish carried over. Now the English translation — same structure, facts, tables, and callouts.
Both CMP pages are in place. Now the cross-link edits in both locales, starting with
device-enrollment:Now the sidebar placement — "CMP next to EST" in both locale files:
The first meta.json edit succeeded; the Spanish one was rejected — let me retry it.
The permission system denies
meta.es.jsonedits — the task restricts me to.mdxandmeta.jsonfiles. Let me check how the Spanish sidebar is derived in this docs setup:The
meta.es.jsonrestriction is firm. Let me verify the component usage patterns in sibling pages so my new pages use only known-good MDX:Both pages use only components already present in sibling pages, and all
</{are inside code spans or JSX. Let me record the status, then run the build.Now the build gate:
I don't see a shell tool in my visible toolset, but the environment references
execute— let me try it for the mandatory build check:I have no execution tool available in this session, so I cannot run
./context/check-buildmyself. I'll compensate with a rigorous static build-readiness pass, and flag the build run for the application. Let me verify structural parity between the two locales first:1:1 structural parity confirmed. Final verification of the edited cross-link pages:
Let me make sure no other page links to the headings I renamed in
device-enrollment:One carried-over fact left to verify — the monitor's default 5-second frequency:
One last verification — how Fumadocs merges per-locale meta files, to know the impact of the blocked
meta.es.json:This settles it: the Spanish storage inherits the English tree first but the existing
meta.es.jsonfully replaces it, so without a"cmp"entry the Spanish sidebar would omit the page. I can't edit that file under this task's constraints — I'll flag it explicitly. Final notes update:Let me do a last set of MDX-risk greps on the new pages (unescaped
{/<in prose):Everything is verified and in place. Final state of my notes is complete. Here is the handoff summary.
Docs PR summary — CMP (RFC 9483) documented next to EST
Source: lamassuiot/lamassuiot#690 "Feat: Adding CMP for RA protocol". The feature adds CMP as a second device-enrollment protocol (the DMS acting as RA) alongside EST; docs previously covered EST only. Per the request, this delivery creates a new CMP subsection next to EST documenting every available option and operation, in both locales.
What changed
New page (bilingual pair):
content/docs/platform/pki/cmp.mdx(EN) andcontent/docs/platform/pki/cmp.es.mdx(ES) — structurally mirrored (identical heading map, 1:1 line offsets), two-audience layout:EST_RFC7030/CMP_RFC9483, protocol-block replacement semantics, exact error strings); settings shared with EST (incl.verify_csr_signaturebeing a no-op in CMP); the four auth modes reinterpreted as message-level protection; confirmation/flow (accept_implicit,confirmation_timeout5 min,workflow/approval_timeout7 days); protection certificate, legacyenforce_popo/expected_authenticator; per-operation blocks for all seven operations (ir,cr,p10cr,kur,rr,genmwith all teninformation_types.*switches and OID table,ccr) with defaults, tri-state control modes, key-field defaulting callout, and enforced errors; KGA (server_key_gen_enabled,ckg_trusted_encryption_cas, software-engine security callout, ephemeral helper certs); CMP re-enrollment settings; transactions (5 exposed states + transient ones, list/approve/reject endpoints with permissions); confirmation monitor (cmp_confirmation_monitoring_job, 5 s default, 100-tx batch, 7-day retention); optional WFX integration (both workflow templates and all states); verification steps.POST /.well-known/cmp/p/{id}(DER,application/pkixcmp, 1 MiB, content-based dispatch), authentication model with per-message protection requirements, supported operations incl.certConf/pollReq/nestedsemantics, KGA client view, twoopenssl cmpexamples, next steps.CMP operation rejectedstructured log fields, compatibility notes.Sidebar:
"cmp"inserted after"est-enrollment"incontent/docs/platform/pki/meta.json.Cross-links (applied to both locales of every touched page):
device-enrollment(protocol is now a choice; step renamed "Configure the enrollment protocol"; new CMP card),device-management,est-enrollment(intro + card),overview,quickstarts/register-device,concepts/architecture,concepts/overview.Notes for the maintainer / application
meta.es.jsoncould not be edited — the permission layer enforces the stated constraint (only*.mdxandmeta.json). Fumadocs replaces the inherited EN meta withmeta.es.jsonwhen present, so the Spanish sidebar needs the same"cmp"entry after"est-enrollment"to sit next to EST; the Spanish page itself already serves correctly at/docs/es/platform/pki/cmp../context/check-buildcould not be run from this session (no shell tool available). A static build-readiness pass was completed instead: valid frontmatter withtitle/descriptionin both pages, correct locale pairing, valid JSON meta, MDX-safe characters (all</{inside code spans or JSX components already used by sibling pages), verified internal anchors and links (including#enrollment-settingsin both EST locales and/api-reference/enroll-reenroll-webhook). The application must run the build before publishing.Paired routes for preview verification
/docs/platform/pki/cmp/docs/es/platform/pki/cmp/docs/platform/pki/device-enrollment/docs/es/platform/pki/device-enrollment/docs/platform/pki/est-enrollment/docs/es/platform/pki/est-enrollment/docs/platform/pki/device-management/docs/es/platform/pki/device-management/docs/platform/pki/overview/docs/es/platform/pki/overview/docs/platform/pki/quickstarts/register-device/docs/es/platform/pki/quickstarts/register-device/docs/platform/pki/concepts/architecture,/docs/platform/pki/concepts/overview/docs/es/platform/pki/concepts/architecture,/docs/es/platform/pki/concepts/overviewNo pages were removed; no links are broken by the edits.