Re: [go-nuts] Checking for expired certificates

2017-07-09 Thread Matt Harden
To detect revoked certificates, you have to either have a current CRL for the CA that issued the cert, or use OSCP. This doesn't appear to be easy to do in Go yet, but https://godoc.org/golang.org/x/crypto/ocsp may help. On Sat, Jul 8, 2017 at 1:06 AM gwhelbig via golang-nuts < golang-nuts@googleg

Re: [go-nuts] Checking for expired certificates

2017-07-08 Thread gwhelbig via golang-nuts
Shawn, I'm a little confused. Your program prints 'Certificate for "revoked.badssl.com" from "DigiCert Inc" expires 2019-09-11 12:00:00 + UTC (795 days).' for the revoked certificate. How do I tell that it has been revoked? Gary. Cr@p. I just realized that I titled the post "expired" wh

Re: [go-nuts] Checking for expired certificates

2017-07-07 Thread Shawn Milochik
Happy Friday. https://play.golang.org/p/gU-wTqYqlv -- You received this message because you are subscribed to the Google Groups "golang-nuts" group. To unsubscribe from this group and stop receiving emails from it, send an email to golang-nuts+unsubscr...@googlegroups.com. For more options, vi

[go-nuts] Checking for expired certificates

2017-07-07 Thread gwhelbig via golang-nuts
The golang net/http package currently does not detect an expired SSL certificate. I need to detect and expired certificate (it's used in an http.Put fuction eventually) and report an error (flag the data back from the put as not secure) Any idea how to go about doing this? TIA, Gary. For ex