CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]    2026/10/09 02:34:39

Modified files:
        usr.sbin/rpki-client: cert.c extern.h filemode.c parser.c x509.c 

Log message:
rpki-client: rework handling of the expire time

The expire time for certificates was added as a hack for filemode and has
been unused in normal mode. We can use it to track the expiry time along
the validating chain of all objects by setting it when validating CAs.

TAs expire with their not after, intermediate CAs and EE certs expire at
the minimum of their notafter, their CRL's nextupdate and their issuer's
expire time. Signed objects inherit the expire time from their EE cert
(this can be handled more cleanly later on).

This way we do not need to grab a lock to determine the expire time of any
object and we can stop walking up the validation chain and look up the same
CRLs over and over again.

ok job

Reply via email to