Hi, I though this was already discussed, but I cannot find pointers.
When some entity verifies a certificate, finds a valid signature etc but the current date is not between "Valid From" to "Valid To", meaning the certificate seems "not yet valid" or "expired", what is recommended to do? I think, essentially, this should be application specific, but are there guide lines or common sense? In practice there could be issues with wrong sytem date / system clocks / time stamps, which could lead to bad situations, especially when users are not allowed to change the system date (for security reasons) and then failing to remotely administrate (because the peer rejects the actually valid certificate as "expired" or "not yet valid"). It cannot be assumed all entities are connected to the internet or any other external trusted time (except maybe an SSL protected one). Are there standards, recommendatations or any writings discussing such topics, in particular system date related topics? oki, Steffen About Ingenico: Ingenico is a leading provider of payment, transaction and business solutions, with over 15 million terminals deployed in more than 125 countries. Over 3,000 employees worldwide support merchants, banks and service providers to optimize and secure their electronic payments solutions, develop their offer of services and increase their point of sales revenue. http://www.ingenico.com/. This message may contain confidential and/or privileged information. If you are not the addressee or authorized to receive this for the addressee, you must not use, copy, disclose or take any action based on this message or any information herein. If you have received this message in error, please advise the sender immediately by reply e-mail and delete this message. Thank you for your cooperation. P Please consider the environment before printing this e-mail ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager majord...@openssl.org