Skip to content

Unexpected "certificate has expired or is not yet valid" #105

@t0rr3sp3dr0

Description

@t0rr3sp3dr0

I have a file and a CMS signature for it and I'm trying to verify them using ietf-cms, but it returns an error saying the certificate is expired. When performing the same check using openssl, it succeeds.

I'm not very familiar with CMS, so the only information I'm able to give you are both files, the code I wrote to check them using ietf-cms, and the command I used to validate them using openssl.

Files

Archive.zip

OpenSSL Command

openssl cms -verify -inform DER -in ./sig -content ./dat -purpose any

OpenSSL Output

CMS Verification successful

IETF-CMS Code

package main

import (
	"crypto/x509"
	"encoding/base64"
	"log"

	"github.com/github/smimesign/ietf-cms"
)

const (
	dat64 = "2TGNnpt9PwNF0Xxb4tQaU4gIW8U="
	sig64 = "
)

func main() {
	dat, err := base64.StdEncoding.DecodeString(dat64)
	if err != nil {
		log.Panic(err)
	}

	sig, err := base64.StdEncoding.DecodeString(sig64)
	if err != nil {
		log.Panic(err)
	}

	sd, err := cms.ParseSignedData(sig)
	if err != nil {
		log.Panic(err)
	}

	certs, err := sd.VerifyDetached(dat, x509.VerifyOptions{})
	if err != nil {
		log.Panic(err)
	}

	log.Print(certs)
}

IETF-CMS Output

2022/03/22 01:20:13 x509: certificate has expired or is not yet valid: current time 2022-03-22T01:20:13Z is after 2019-10-28T23:50:01Z
panic: x509: certificate has expired or is not yet valid: current time 2022-03-22T01:20:13Z is after 2019-10-28T23:50:01Z

goroutine 1 [running]:
log.Panic({0xc000199f60, 0x0, 0x0})
    /nix/store/d9rw46ym59cszc79n4vs60yqfz5rkps9-go-1.17.3/share/go/src/log/log.go:354 +0x65
main.main()
    /home/runner/IllustriousHandsomeComputeranimation/main.go:34 +0x1eb

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions