You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

X509_get0_notBefore与X509_get0_notAfter作用及证书过期日期获取问题

Hey there, let's work through your certificate expiration check issues and clarify those function availability questions!

Troubleshooting Certificate Expiration Check & Function Availability

First: Are X509_get0_notBefore and X509_get0_notAfter available in your scope?

These functions are part of OpenSSL's 1.0.2 and newer releases. They belong to the "get0" family, which return pointers to the certificate's internal data (you shouldn't modify or free these pointers directly).

To confirm if your environment supports them:

  • Check your OpenSSL version via terminal with openssl version.
  • Add a compile-time check in your code to avoid build errors:
    #if OPENSSL_VERSION_NUMBER >= 0x10002000L
        // Safe to use X509_get0_notBefore/X509_get0_notAfter
    #else
        // Fall back to older non-get0 functions: X509_get_notBefore and X509_get_notAfter
        // Note: These return modifiable pointers, but don't free them unless you duplicate first
    #endif
    

If you're using an OpenSSL version older than 1.0.2, the get0 functions won't be defined—this is a common cause of compile failures.

Fixing Your Certificate Expiration Check Code

Looking at your snippet, here are key issues to address:

1. Validate the Certificate Pointer First

Before calling any X509 functions, ensure server_cert isn't NULL (this causes crashes or undefined behavior):

if (!server_cert) {
    fprintf(stderr, "Error: Invalid server certificate pointer!\n");
    return -1;
}

2. Properly Format ptime for Comparison

X509_cmp_time expects the second argument to be an ASN.1-formatted time string (either YYMMDDHHMMSSZ for UTCTime or YYYYMMDDHHMMSSZ for GeneralizedTime). If your ptime isn't in this format, comparisons will fail. Here's how to generate a valid current time string:

#include <time.h>
#include <openssl/asn1.h>

// Get current time in valid ASN.1 format
time_t now = time(NULL);
ASN1_TIME *asn1_now = ASN1_TIME_set(NULL, now);
char ptime[256];

if (!ASN1_TIME_to_string(ptime, sizeof(ptime), asn1_now)) {
    fprintf(stderr, "Error: Failed to format current time!\n");
    ASN1_TIME_free(asn1_now);
    return -1;
}
ASN1_TIME_free(asn1_now);

3. Interpret X509_cmp_time Return Values Correctly

The return value indicates the relationship between the two times:

  • -1: Certificate time is earlier than ptime
  • 0: Times are identical
  • 1: Certificate time is later than ptime

Use this logic to check expiration status:

// Check if certificate is expired
int expire_check = X509_cmp_time(X509_get0_notAfter(server_cert), ptime);
if (expire_check < 0) {
    printf("Certificate has expired!\n");
} else if (expire_check == 0) {
    printf("Certificate expires today!\n");
} else {
    printf("Certificate is still valid.\n");
}

// Optional: Check if certificate isn't yet active
int activate_check = X509_cmp_time(X509_get0_notBefore(server_cert), ptime);
if (activate_check > 0) {
    printf("Certificate is not yet valid!\n");
}

4. Debugging Tips

  • Uncomment your printf statement to see raw return values—this helps verify if comparisons are working as expected.
  • Use ASN1_TIME_print to print the actual notBefore/notAfter dates from the certificate, so you can cross-check against your current time.

内容的提问来源于stack exchange,提问作者BitByte

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:59:20