pki: Avoid integer overflow when calculating certificate lifetimes.
This only works properly if sizeof(time_t) > 4.
This commit is contained in:
@@ -67,11 +67,11 @@ static int issue()
|
||||
char *error = NULL, *keyid = NULL;
|
||||
identification_t *id = NULL;
|
||||
linked_list_t *san, *cdps, *ocsp, *permitted, *excluded, *policies, *mappings;
|
||||
int lifetime = 1095;
|
||||
int pathlen = X509_NO_CONSTRAINT, inhibit_any = X509_NO_CONSTRAINT;
|
||||
int inhibit_mapping = X509_NO_CONSTRAINT, require_explicit = X509_NO_CONSTRAINT;
|
||||
chunk_t serial = chunk_empty;
|
||||
chunk_t encoding = chunk_empty;
|
||||
time_t lifetime = 1095;
|
||||
time_t not_before, not_after;
|
||||
x509_flag_t flags = 0;
|
||||
x509_t *x509;
|
||||
|
||||
@@ -55,11 +55,11 @@ static int self()
|
||||
char *file = NULL, *dn = NULL, *hex = NULL, *error = NULL, *keyid = NULL;
|
||||
identification_t *id = NULL;
|
||||
linked_list_t *san, *ocsp, *permitted, *excluded, *policies, *mappings;
|
||||
int lifetime = 1095;
|
||||
int pathlen = X509_NO_CONSTRAINT, inhibit_any = X509_NO_CONSTRAINT;
|
||||
int inhibit_mapping = X509_NO_CONSTRAINT, require_explicit = X509_NO_CONSTRAINT;
|
||||
chunk_t serial = chunk_empty;
|
||||
chunk_t encoding = chunk_empty;
|
||||
time_t lifetime = 1095;
|
||||
time_t not_before, not_after;
|
||||
x509_flag_t flags = 0;
|
||||
x509_cert_policy_t *policy = NULL;
|
||||
|
||||
@@ -124,7 +124,7 @@ static int sign_crl()
|
||||
int serial_len = 0;
|
||||
crl_reason_t reason = CRL_REASON_UNSPECIFIED;
|
||||
time_t thisUpdate, nextUpdate, date = time(NULL);
|
||||
int lifetime = 15;
|
||||
time_t lifetime = 15;
|
||||
linked_list_t *list, *cdps;
|
||||
enumerator_t *enumerator, *lastenum = NULL;
|
||||
x509_cdp_t *cdp;
|
||||
|
||||
Reference in New Issue
Block a user