I think this question got lost in the shuffle. I am confused as to how to check the update time of the CRL (if the CRL has expired). Does this check happen in X509_CRL_verify(), or is there another way to do it? I've got a CRL that has an update time set to 7 days, but the verification is still succeeding even after 30 days. Can someone please tell me what I'm missing?

                  -David-
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to