[openssl-users] Building OpenSSL: OpenSSL-Release, expired certificates

Rob Hermann rhermann at centurioncares.com
Mon Feb 29 17:01:18 UTC 2016


I'm running in a linux-elf environment as the su.

when I run "make tests"   at the tail end of  the tests I get some 
errors about expired certificates:


testing pkcs7 conversions
p -> d
p -> p
d -> d
p -> d
d -> p
p -> p
testing pkcs7 conversions (2)
p -> d
p -> p
d -> d
p -> d
d -> p
p -> p
The following command should have some OK's and some failures
There are definitly a few expired certificates
../util/shlib_wrap.sh ../apps/openssl verify -CApath ../certs/demo 
../certs/demo/*.pem
../certs/demo/ca-cert.pem: C = AU, ST = Queensland, O = CryptSoft Pty 
Ltd, CN = Test CA (1024 bit)
error 20 at 0 depth lookup:unable to get local issuer certificate
../certs/demo/dsa-ca.pem: C = AU, ST = Some-State, O = Internet Widgits 
Pty Ltd, CN = CA
error 20 at 0 depth lookup:unable to get local issuer certificate
3077822616:error:0B06E06B:x509 certificate 
routines:X509_get_pubkey_parameters:unable to find parameters in 
chain:x509_vfy.c:1966:
../certs/demo/dsa-pca.pem: C = AU, ST = Some-State, O = Internet Widgits 
Pty Ltd, CN = PCA
error 18 at 0 depth lookup:self signed certificate
C = AU, ST = Some-State, O = Internet Widgits Pty Ltd, CN = PCA
error 10 at 0 depth lookup:certificate has expired
OK
../certs/demo/pca-cert.pem: C = AU, ST = Queensland, O = CryptSoft Pty 
Ltd, CN = Test PCA (1024 bit)
error 18 at 0 depth lookup:self signed certificate
C = AU, ST = Queensland, O = CryptSoft Pty Ltd, CN = Test PCA (1024 bit)
error 10 at 0 depth lookup:certificate has expired
OK
_make[1]: *** [test_verify] Error 2__
__make[1]: Leaving directory `/home/rhermann/src/OpenSSLWork/test'__
__make: *** [tests] Error 2__
_[root at rhlinuxdev OpenSSLWork]#



what do the underlined statements mean ? is there an expired certificate 
that needs to get updated ?


Rob Hermann




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20160229/f7d66553/attachment-0001.html>


More information about the openssl-users mailing list