Editorial question80.8K views2,824 votes0 answers830 following
AI-generatedOpenSSL default handling of expired client certificates during mutual TLS
The goal is to enforce least‑privilege authentication by ensuring that a TLS server rejects connections when the client presents an expired certificate, even when SSL_VERIFY_PEER is set. OpenSSL completes the handshake and stores the error X509_V_ERR_CERT_HAS_EXPIRED in the verification result, but it does not automatically abort the connection. The applicat