Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NTS initial certificate verification #20

Open
aaronbojarski opened this issue Jul 26, 2023 · 0 comments
Open

NTS initial certificate verification #20

aaronbojarski opened this issue Jul 26, 2023 · 0 comments

Comments

@aaronbojarski
Copy link
Contributor

aaronbojarski commented Jul 26, 2023

In case the local clock is out of sync by multiple days NTS has a problem. It might not be possible to validate the server certificate since it appears not to be valid.

https://www.rfc-editor.org/rfc/rfc8915.html#name-initial-verification-of-ser

Right now our implementations fails in that case and it is not possible to synchronize. One approach to change that in the future is to synchronize over NTP if the certificate is not valid due to the validity period and then use NTS afterwards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant