identification_t *subject = certificate->get_subject(certificate);
identification_t *issuer = certificate->get_issuer(certificate);
chunk_t authKeyID = x509->get_authKeyIdentifier(x509);
+ time_t not_before, not_after;
DBG(DBG_CONTROL,
DBG_log("subject: '%Y'", subject);
}
)
- if (!certificate->get_validity(certificate, NULL, NULL, NULL))
+ if (!certificate->get_validity(certificate, NULL, ¬_before, ¬_after))
{
+ plog("certificate is invalid (valid from %T to %T)",
+ ¬_before, FALSE, ¬_after, FALSE);
+
unlock_authcert_list("valid_ocsp_response");
return FALSE;
}