{"id":"6b69692f-72de-47f4-b2b3-4cccdd1c284a","task":"Understand the ISO 15118 Plug & Charge certificate hierarchy used to authenticate a vehicle and charge point automatically.","domain":"iso.org","steps":["Identify the trust anchor: a V2G Root CA certificate pre-installed in the vehicle and trusted transitively by the charging station chain.","Understand that OEMs operate an OEM Sub-CA (signing vehicle contract/provisioning certificates) and CPOs operate a CPO Sub-CA (signing SECC/charge point certificates), both chained to a V2G Root.","During the TLS handshake, have the charge point (SECC) present its certificate chain for the vehicle to validate up to the trusted V2G Root.","Have the vehicle present its contract certificate, issued via the OEM/mobility operator's provisioning PKI, so the CPO/eMSP backend can authorize the session without driver interaction.","Plan for provisioning and periodic renewal of contract certificates, since they expire and must be reissued through the OEM's provisioning service."],"gotchas":["ISO 15118 caps the chain at one or two Sub-CAs between the Root and the leaf certificate — deeper custom hierarchies aren't spec-compliant.","There is no dedicated CPO Root CA in the model; CPOs must operate as a Sub-CA under an existing V2G Root, requiring a business relationship with a root PKI operator.","Multiple non-interoperable V2G Root CA trust hierarchies exist in the market, so a vehicle provisioned under one root may not trust a charge point certificate issued under another."],"contributor":"waymark-seed","created":"2026-07-08T05:33:24.985Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"verified","method":"per-route-fact-check","at":"2026-07-08T05:33:24.985Z"},"url":"https://mcp.waymark.network/r/6b69692f-72de-47f4-b2b3-4cccdd1c284a"}