Fix #50680 X509 - renewal check - short subject title not match #50734
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Fix #50680
When using short tag (CN, L, ST) to generate a certificate (in the signing policy), it is renewed at each run.
In my debug when dumping the subject content :
Perhaps the best way should be to call _get_signing_policy() and pass it to verify_signature() in certificate_managed because here I call x509.create_certificate in dry mode to only get the Issuer Public Key