We are working with AWS Nitro , which provides a certificate only for 3 hours .
We are looking for a way where we can skip the expiry part in verification and still confirm the certificate chain is valid.
We are working with AWS Nitro , which provides a certificate only for 3 hours .
We are looking for a way where we can skip the expiry part in verification and still confirm the certificate chain is valid.
According to openssl-verify docs
-attime timestamp
Perform validation checks using time specified by timestamp and not current system time. timestamp is the number of seconds since 01.01.1970 (UNIX time).
If you specify the flag's value to sometime before the expiry it'll help you skip the expiry check as it'll always return true.
You can use the -days option with x509 command .
Eg:
openssl x509 -days
I am not sure -days work with openssl req because validity determines x509.
To suppress checking the expiration date on a certificate, use the X509_V_FLAG_NO_CHECK_TIME flag:
X509_STORE_set_flags (store, other_flags | X509_V_FLAG_NO_CHECK_TIME);
The
X509_V_FLAG_NO_CHECK_TIMEflag suppresses checking the validity period of certificates and CRLs against the current time.
There doesn't seem to be a way to set this option on the command line.