Req #67500 [Opn->Wfx]: Allow to define time in openssl_x509_checkpurpose

From: Date: Wed, 04 Mar 2015 21:22:24 +0000
Subject: Req #67500 [Opn->Wfx]: Allow to define time in openssl_x509_checkpurpose
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191166@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67500&edit=1

 ID:                 67500
 Updated by:         rdlowrey@php.net
 Reported by:        dominic dot tubach at to dot com
 Summary:            Allow to define time in openssl_x509_checkpurpose
-Status:             Open
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            OpenSSL related
 PHP Version:        5.5.13
 Block user comment: N
 Private report:     N

 New Comment:

I don't believe that is the correct place to check for this type of thing.

The functionality you're looking for is already available using openssl_x509_parse() to
determine if the certificate is valid at a given timestamp as shown here:

<?php
$cert = ...; // get the cert from somewhere
$info = openssl_x509_parse($cert);
$time = time(); // or any other timestamp;
$isValid = ($info['validFrom_time_t'] < $time && $time <
$info['validTo_time_t']);


Previous Comments:
------------------------------------------------------------------------
[2014-06-23 09:03:22] dominic dot tubach at to dot com

Description:
------------
The OpenSSL verify command allows to specify a timestamp to use for the check instead of the current
system time (option -attime). Can this possibility be added to the openssl_x509_checkpurpose
function?



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67500&edit=1


Thread (2 messages)

« previous php.bugs (#191166) next »