Grabbed a new Mac App Store receipt. They are back to using SHA1 and it now has an expiration date in 2023.pic.twitter.com/HgenGzPLaB
When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more
@mattstevens Right. My question is, does Apple's sample code implicitly use the current date? (Guess: No. So this wouldn't be a problem.)
@mjtsai Looks like no and you’re right, it’s not an issue if you don’t check the validity period at all.
@mjtsai I was wrong, after testing that code will verify the chain against the current time unless otherwise configured.
@mattstevens curious: how to you tell PKCS7_verify() to check (or not) the creation date? Can't find that in the docs :-(
@rbrockerhoff Through the X509_STORE’s verification parameters: https://gist.github.com/mattstevens/fa099d99f2fa7247c65e …
@mattstevens great, thanks a lot. Will try to implement that now.
@mattstevens OK, my version of OpenSSL doesn't have X509_V_FLAG_NO_CHECK_TIME yet, but no problem; it works now. Thanks again!
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.