Comment 2 for bug 2003701

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

The best we can do, is to take notAfter time of the signing certificate and add that as the signingTime, which will then be used by the Sign command as given.

This will ensure the signature is within valid time-series.

I don't see an easy openssl API to sign things without any signature timestamp.