baffled on old Red Hat Enterprise Linux 6 with OpenSSL 3.0.3

Viktor Dukhovni openssl-users at dukhovni.org
Fri Jun 10 14:54:03 UTC 2022


On Fri, Jun 10, 2022 at 09:43:45AM -0400, Dennis Clarke via openssl-users wrote:

> I am surprised that people are not hitting this wall on all
> platforms. Pushing out a new release jsut for an expired test
> certificate seems a tad silly but perhaps ALL the test certs can
> be updated at the same time. Whatever works.

Most of the test certificates were generated via my "mkcert" script,
which creates 100-year certificates, and will not expire until some time
after 2316.

The particular problem certificates were generated manually, by the
author of the SCT (certificate transparency) code, and sadly were not
created with nearly as long a lifetime.  I hope their replacements don't
have that issue.

-- 
    Viktor.


More information about the openssl-users mailing list