Re-add default NotBefore duration in PKI (#5482)

Fixes #5481
This commit is contained in:
Jeff Mitchell 2018-10-10 09:42:37 -04:00 committed by GitHub
parent dfb0974369
commit 4217ced72d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 0 deletions

View File

@ -1178,6 +1178,7 @@ func createCertificate(data *dataBundle) (*certutil.ParsedCertBundle, error) {
certTemplate := &x509.Certificate{
SerialNumber: serialNumber,
NotBefore: time.Now().Add(-30 * time.Second),
NotAfter: data.params.NotAfter,
IsCA: false,
SubjectKeyId: subjKeyID,
@ -1380,6 +1381,7 @@ func signCertificate(data *dataBundle) (*certutil.ParsedCertBundle, error) {
certTemplate := &x509.Certificate{
SerialNumber: serialNumber,
Subject: data.params.Subject,
NotBefore: time.Now().Add(-30 * time.Second),
NotAfter: data.params.NotAfter,
SubjectKeyId: subjKeyID[:],
AuthorityKeyId: caCert.SubjectKeyId,