X509_get0_notBefore与X509_get0_notAfter作用及证书过期日期获取问题
Hey there, let's work through your certificate expiration check issues and clarify those function availability questions!
First: Are X509_get0_notBefore and X509_get0_notAfter available in your scope?
These functions are part of OpenSSL's 1.0.2 and newer releases. They belong to the "get0" family, which return pointers to the certificate's internal data (you shouldn't modify or free these pointers directly).
To confirm if your environment supports them:
- Check your OpenSSL version via terminal with
openssl version. - Add a compile-time check in your code to avoid build errors:
#if OPENSSL_VERSION_NUMBER >= 0x10002000L // Safe to use X509_get0_notBefore/X509_get0_notAfter #else // Fall back to older non-get0 functions: X509_get_notBefore and X509_get_notAfter // Note: These return modifiable pointers, but don't free them unless you duplicate first #endif
If you're using an OpenSSL version older than 1.0.2, the get0 functions won't be defined—this is a common cause of compile failures.
Fixing Your Certificate Expiration Check Code
Looking at your snippet, here are key issues to address:
1. Validate the Certificate Pointer First
Before calling any X509 functions, ensure server_cert isn't NULL (this causes crashes or undefined behavior):
if (!server_cert) { fprintf(stderr, "Error: Invalid server certificate pointer!\n"); return -1; }
2. Properly Format ptime for Comparison
X509_cmp_time expects the second argument to be an ASN.1-formatted time string (either YYMMDDHHMMSSZ for UTCTime or YYYYMMDDHHMMSSZ for GeneralizedTime). If your ptime isn't in this format, comparisons will fail. Here's how to generate a valid current time string:
#include <time.h> #include <openssl/asn1.h> // Get current time in valid ASN.1 format time_t now = time(NULL); ASN1_TIME *asn1_now = ASN1_TIME_set(NULL, now); char ptime[256]; if (!ASN1_TIME_to_string(ptime, sizeof(ptime), asn1_now)) { fprintf(stderr, "Error: Failed to format current time!\n"); ASN1_TIME_free(asn1_now); return -1; } ASN1_TIME_free(asn1_now);
3. Interpret X509_cmp_time Return Values Correctly
The return value indicates the relationship between the two times:
-1: Certificate time is earlier thanptime0: Times are identical1: Certificate time is later thanptime
Use this logic to check expiration status:
// Check if certificate is expired int expire_check = X509_cmp_time(X509_get0_notAfter(server_cert), ptime); if (expire_check < 0) { printf("Certificate has expired!\n"); } else if (expire_check == 0) { printf("Certificate expires today!\n"); } else { printf("Certificate is still valid.\n"); } // Optional: Check if certificate isn't yet active int activate_check = X509_cmp_time(X509_get0_notBefore(server_cert), ptime); if (activate_check > 0) { printf("Certificate is not yet valid!\n"); }
4. Debugging Tips
- Uncomment your
printfstatement to see raw return values—this helps verify if comparisons are working as expected. - Use
ASN1_TIME_printto print the actualnotBefore/notAfterdates from the certificate, so you can cross-check against your current time.
内容的提问来源于stack exchange,提问作者BitByte

