Conversation
The ASN.1 time was converted to a timestamp with mktime() and a manual time zone correction. MSVC's 64-bit mktime() cannot represent dates after 23:59:59 on 31 December 3000 UTC and returns -1, which then had the local time zone adjustment added to it, producing values like 7199 or 32399. Decode the string with ASN1_TIME_to_tm() and compute the timestamp directly from the UTC civil date, so the result no longer depends on the C library's mktime() range or on the local time zone. Closes phpGH-21545
Member
Author
|
I target just 8.5+ as I can't be bothered to deal with conflict for this sort of "not real" issue (who would be using certs valid longer than year 3000...? :) ) |
LamentXU123
reviewed
Oct 2, 2026
|
|
||
| if (ASN1_STRING_type(timestr) == V_ASN1_GENERALIZEDTIME && timestr_len < 15) { | ||
| /* Validates the string and fills in the broken-down time in UTC. */ | ||
| if (!ASN1_TIME_to_tm(timestr, &thetime)) { |
Member
There was a problem hiding this comment.
While at it, why not use ASN1_TIME_diff for the whole algo?
https://manpages.opensuse.org/Leap-15.6/openssl-3-doc/ASN1_TIME_diff.33ssl.en.html
So you don't need to maintain the date algo yourself. But at the cost that there might be one more allocation/free for ASN1_TIME in each call.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The ASN.1 time was converted to a timestamp with mktime() and a manual time zone correction. MSVC's 64-bit mktime() cannot represent dates after 23:59:59 on 31 December 3000 UTC and returns -1, which then had the local time zone adjustment added to it, producing values like 7199 or 32399.
Decode the string with ASN1_TIME_to_tm() and compute the timestamp directly from the UTC civil date, so the result no longer depends on the C library's mktime() range or on the local time zone.
Closes GH-21545