Allow outdated and cert chain bug fixes #109
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Feature: Exposing the "AllowOutdated" option to the command line tool, which enables successful validation of COSE signatures with a certificate chain containing one or more expired nodes. This option has no effect if the signing certificate has the lifetime eku (1.3.6.1.4.1.311.10.3.13).
BugFix: The X509ChainTrustValidator now can use all of the certificates included in the x5t header of the COSE message when attempting to build a chain of trust from the signing certificate. Previously, the validator would only use the signing certificate and certificates already installed on machine.