Skip to content

Check expiry for trusted certs - #11465

Open
padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:ossl-compat-issue-31
Open

padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:ossl-compat-issue-31

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

This change adds checks on the before and after dates for certs in the trust store to match OpenSSL behavior. Note that the RTC-less mode is still respected and date checks are skipped.

Testing

Added unit tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@padelsbach
padelsbach force-pushed the ossl-compat-issue-31 branch 3 times, most recently from ded7ffd to bc689eb Compare September 29, 2026 17:11
@padelsbach

Copy link
Copy Markdown
Contributor Author

jenkins retest this please

Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:15
@padelsbach
padelsbach force-pushed the ossl-compat-issue-31 branch from bc689eb to 006d6cb Compare October 1, 2026 00:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Date-validation configuration and verification callback semantics regress, while the default test path does not exercise the new behavior.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Adds validity-period checks for trusted peer certificates while preserving RTC-less behavior.

Changes:

  • Validates trusted peers’ notBefore and notAfter dates.
  • Maps failures to OpenSSL-compatible verification errors.
  • Adds an expired-certificate API test.
File Description
src/​internal.c Adds trusted-peer date validation.
tests/​api/​test_certman.c Tests expired trusted-peer handling.
tests/​api/​test_certman.h Registers the new test.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/internal.c
Comment on lines +16839 to +16840
(wc_ValidateDate(&cert->beforeDate[2], cert->beforeDate[0],
ASN_BEFORE, cert->beforeDate[1]) == 0)) {
Comment thread src/internal.c
Comment on lines +18546 to +18547
WOLFSSL_ERROR_VERBOSE(ret);
goto exit_ppc;
Comment thread tests/api/test_certman.c
Comment on lines +4242 to +4254
ret = wolfSSL_CTX_trust_peer_cert(client_cb.ctx,
"certs/test/expired/expired-cert.pem", WOLFSSL_FILETYPE_PEM);
if (ret == WOLFSSL_SUCCESS) {
wolfSSL_CTX_set_verify(client_cb.ctx, WOLFSSL_VERIFY_PEER, NULL);

/* the pin must not revive an expired certificate */
ExpectIntNE(test_wolfSSL_client_server_nofail_memio(&client_cb,
&server_cb, NULL), TEST_SUCCESS);
ExpectIntEQ(client_cb.last_err, WC_NO_ERR_TRACE(ASN_AFTER_DATE_E));
}
else {
ExpectIntEQ(ret, WC_NO_ERR_TRACE(ASN_AFTER_DATE_E));
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants