Commit 9fed11d
committed
Stamp generated certificates with aware UTC datetimes
datetime.utcnow() returns a naive datetime holding UTC numbers, which reads as
local time to anything that later calls .timestamp() on it — a silent offset
equal to the host's UTC offset, invisible on a UTC machine. Python 3.12 already
warns on it, and cryptography has been steering callers off naive datetimes, so
certificate generation would eventually stop working rather than merely warn.
Nothing changes today: cryptography treats a naive datetime as UTC, and
utcnow() supplied UTC numbers, so the two mistakes cancelled. Verified under
TZ=America/New_York with -W error::DeprecationWarning that generation is silent
and that both certificates carry aware UTC bounds, a 1825-day span, and a
signature that verifies against the CA.
Signed-off-by: Honglin Cao <hocao@nvidia.com>1 parent 258dce0 commit 9fed11d
1 file changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
| |||
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
56 | | - | |
| 56 | + | |
57 | 57 | | |
58 | | - | |
| 58 | + | |
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
| |||
0 commit comments