On Thu, Feb 03, 2022 at 03:42:39PM +0100, Matus UHLAR - fantomas wrote:

Certificate chain
 0 s:CN = darwin.bork.org
   i:C = US, O = Let's Encrypt, CN = R3
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
   i:O = Digital Signature Trust Co., CN = DST Root CA X3

the third certificate is expired, but the second one is already trusted by
root CA, so the third should not be evaluated.

On 03.02.22 09:51, Viktor Dukhovni wrote:
I don't see an expired third certificate.  If you do, perhaps that
originates in your trust store.

sorry, the third one is not expired:

       Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3
       Validity
           Not Before: Jan 20 19:14:03 2021 GMT
           Not After : Sep 30 18:14:03 2024 GMT
       Subject: C = US, O = Internet Security Research Group, CN = ISRG Root X1

the root that signs it is expired:

       Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3
       Validity
           Not Before: Sep 30 21:12:19 2000 GMT
           Not After : Sep 30 14:01:15 2021 GMT
       Subject: O = Digital Signature Trust Co., CN = DST Root CA X3

I was writing from memory.


--
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
He who laughs last thinks slowest.

Reply via email to