You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In my experience, time zones generally just cause problems for certificates, so let's use UTC by default for not_before and not_after. Also, I've found it useful to round such values to the nearest previous hour, capping minute and second to 0.
So at the moment when you do assignment of not_before or not_after it should convert whatever's provided directly into UTC. Is this not what you want?
I don't want to round validity periods in r509's primary signer (one of its design goals is to still allow low level behaviors for my own testing purposes), but it might make sense to start trying to spec out a "friendly signer" that does some of this behavior (such as #59 )
In my experience, time zones generally just cause problems for certificates, so let's use UTC by default for not_before and not_after. Also, I've found it useful to round such values to the nearest previous hour, capping minute and second to 0.
This is an example of how I currently do it:
The text was updated successfully, but these errors were encountered: