Skip to content

pyhanko.sign.validation.status - WARNING - The path could not be validated because the end-entity certificate expired 2022-05-25 04:17:25Z #129

Discussion options

You must be logged in to vote

Hi @thomasgundlach,

This is a common issue in document signing, and common practice dictates that, if possible, one should attempt to ascertain the validity of the certificate at the time the signature was produced. The catch is that to allow that to be done more or less securely, the signer needs to supply a whole lot of additional data to ensure that

(a) there's a proper record of the signature's existence at (or close to) the claimed time of signing, witnessed by a trusted time stamping authority, and
(b) the revocation status of the certificate at that time can be checked.

Long story short, (a) is necessary because you generally can't trust signers to accurately report the time of sig…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@thomasgundlach
Comment options

@MatthiasValvekens
Comment options

@MatthiasValvekens
Comment options

Answer selected by thomasgundlach
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants