On Tue, 25 Sep 2012 16:35:20 +0100 David Howells <dhowe...@redhat.com> wrote:
> Alan Cox <a...@lxorguk.ukuu.org.uk> wrote: > > > Generate a certificate that is valid from a few minutes before the > > wallclock time. It's a certificate policy question not a kernel hackery > > one. > > That doesn't seem to be possible with openssl req. What would you recommend? LD_PRELOAD ? or fixing it if GNUTLS certtool can't do the needed. We shouldn't botch security checks in kernel code to work around crappy userspace tools. Alan -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/