Skip to content

Commit 9fed11d

Browse files
committed
Stamp generated certificates with aware UTC datetimes
datetime.utcnow() returns a naive datetime holding UTC numbers, which reads as local time to anything that later calls .timestamp() on it — a silent offset equal to the host's UTC offset, invisible on a UTC machine. Python 3.12 already warns on it, and cryptography has been steering callers off naive datetimes, so certificate generation would eventually stop working rather than merely warn. Nothing changes today: cryptography treats a naive datetime as UTC, and utcnow() supplied UTC numbers, so the two mistakes cancelled. Verified under TZ=America/New_York with -W error::DeprecationWarning that generation is silent and that both certificates carry aware UTC bounds, a 1825-day span, and a signature that verifies against the CA. Signed-off-by: Honglin Cao <hocao@nvidia.com>
1 parent 258dce0 commit 9fed11d

1 file changed

Lines changed: 5 additions & 5 deletions

File tree

‎centml/sdk/utils/client_certs.py‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
import os
22
from dataclasses import dataclass
3-
from datetime import datetime, timedelta
3+
from datetime import datetime, timedelta, timezone
44

55
import click
66
from cryptography import x509
@@ -31,9 +31,9 @@ def generate_ca_client_triplet(service_name: str) -> CAClientCertTriplet:
3131
.issuer_name(ca_subject)
3232
.public_key(ca_private_key.public_key())
3333
.serial_number(x509.random_serial_number())
34-
.not_valid_before(datetime.utcnow())
34+
.not_valid_before(datetime.now(timezone.utc))
3535
# Certificate valid for 5 years (give or take leap years)
36-
.not_valid_after(datetime.utcnow() + timedelta(days=365 * 5))
36+
.not_valid_after(datetime.now(timezone.utc) + timedelta(days=365 * 5))
3737
.add_extension(x509.BasicConstraints(ca=True, path_length=None), critical=True)
3838
# We are using SHA384 as it's often paired with secpr384r1, ie
3939
# the weak link isn't the hash algorithm.
@@ -53,9 +53,9 @@ def generate_ca_client_triplet(service_name: str) -> CAClientCertTriplet:
5353
.issuer_name(ca_certificate.subject)
5454
.public_key(client_private_key.public_key())
5555
.serial_number(x509.random_serial_number())
56-
.not_valid_before(datetime.utcnow())
56+
.not_valid_before(datetime.now(timezone.utc))
5757
# Certificate valid for 5 years (give or take leap years)
58-
.not_valid_after(datetime.utcnow() + timedelta(days=365 * 5))
58+
.not_valid_after(datetime.now(timezone.utc) + timedelta(days=365 * 5))
5959
.add_extension(x509.BasicConstraints(ca=False, path_length=None), critical=True)
6060
# We are using SHA384 as it's often paired with secpr384r1, ie
6161
# the weak link isn't the hash algorithm.

0 commit comments

Comments
 (0)