Re: Fencepost errors in certificate and OCSP validity

2020-10-28 Thread Viktor Dukhovni
On Wed, Oct 28, 2020 at 04:32:56PM +0100, Jakob Bohm via openssl-users wrote: > Recently, the EJBCA developers publicly warned (via the Mozilla root store > policy mailing list) other CA vendors that they had incorrectly implemented > the handling of the "notAfter" X509 field, resulting in

Fencepost errors in certificate and OCSP validity

2020-10-28 Thread Jakob Bohm via openssl-users
Recently, the EJBCA developers publicly warned (via the Mozilla root store policy mailing list) other CA vendors that they had incorrectly implemented the handling of the "notAfter" X509 field, resulting in certificates that lasted 1 second longer than intended. Prompted by this warning, I