Hello guys, I ran into this situation today: An RA operator approved a request few days a go while her
certificate was valid. When the CA operator tried to issue the signed CSRs by
that RA operator (which her certificate is now expired) the verification of the
signature failed. This should not happened because the signature was produced
while the certificate was valid and thus the signature is sound and good at the
time of the signature and it should keep being good even if the signing
certificate have expired later. I was wondering if this had been addressed
before in the code or not? If it is not then I will dig into the code to fix
it. Best regards, Bahaa Al-amood |
- [OpenCA-Devel] PKCS7 verification Alamood, Bahaaldin
- Re: [OpenCA-Devel] PKCS7 verification Ives Steglich