OpenSSL ASN.1 TIME parsing vs application local‑time conversion: timezone offset handling
26K reputation · 03 Jul 2024, 07:34 UTC
Goal
Ensure that OpenSSL’s ASN.1 TIME parsing consistently translates timezone offsets into a predictable representation for applications that convert the returned time to local civil time.
Constraints and uncertainty
OpenSSL currently returns the time as a time_t value interpreted as UTC, discarding any timezone offset present in the ASN.1 TIME field. Some applications expect the offset to be preserved or applied to yield local time, leading to interoperability gaps when integrating with systems that rely on local‑time semantics (e.g., certificate validity checks in regional PKIs). The library’s documentation does not specify whether the offset should be ignored, converted, or made available via an API, leaving the decision unresolved.
- Should OpenSSL provide an option to retain the original timezone offset from ASN.1 TIME fields?
- If retained, how should applications convert the offset‑aware value to local civil time without duplicating conversion logic?
- What version‑specific behavior (e.g., OpenSSL 3.0 vs 1.1.1) should be assumed when evaluating this interoperability?