#1036769 lintian: Check for certificates .pem/.crt/.pkcs12 with expiry set

Package:
lintian
Source:
lintian
Submitter:
Florian Lohoff
Date:
2026-07-02 17:37:12 UTC
Severity:
normal
Tags:
#1036769#5
Date:
2023-05-25 15:27:48 UTC
From:
To:
Hi,
i am in the middle of a stretch rebuild for mipsel (Upgrade path from
jessie as stretch dropped 75% of supported systems with mips32)

A big issue are certificates, mostly for build tests which have an
expire date set. This causes the package to fail just because we are a
couple years behind schedule.

Flo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEdb9o7oebX2papQ/KkN1BIMsJ8i8FAmRvfnIACgkQkN1BIMsJ
8i8zNg/9Hn+BSGD5BFZbp5/afhzgM0MkJ+fdkJixiBMV9ETJ+39yjqQ9TBsDDwIV
P7uN3IeB+ndkXH3iY9XbuoUY0AyND3V5bWXKjj/Zf5iS+XWTcn5oVxRunh07LWd0
2dnIg5kekh5ls4Y0GqO7Zmx9KPUNpNtdwQS/O7/YIusyHOA1ExOCCE87bP8FRQOu
JtW9WeUVX84BhtVp76X47P2tLWmrgDSNFjI1Yb/JVJ3a9eI89n/y47O9GFjOd93r
lPOfFtFxpMTtzWV3k+3ks0miH+hqzYoFjG3fv8sgxE5FBvNAia99nieqIkyhTpx/
u+oLyCO1ZM7vDlIzOULKxHATSE9L2HsttD6ndhEi51VrKFGb4lBReJ5IvrL7ECBW
N//nI0TJ0TobuAjna0oKOAaYQW+h+oyH4nFJTMZu5jb+vf3MI98cxq18bSlk39c5
uX/nC2tRFkTtQvLRlVgozz+7InlsVtw62nhSiOCoTtOjU0tCiJWed4E4DKbzSLuw
j2J3vHg5pmQSN7AgbKUOqMW9QpN1VGvEa9z4xtW9Vjh4KjRcMMfDLvax0uWJ4ZFr
BJxFy3ppZMvmMsYxbuGfdxTQyP/Eo/+aM5aNu7bJZfckygVgt51+8eonyXYwOn5v
w2illtNp9OaJLSTH/bUeEajpHsVUDUFupzFi5YWMmUbEvrkcPyA=
=JBxn
-----END PGP SIGNATURE-----

#1036769#10
Date:
2024-05-13 07:40:25 UTC
From:
To:
Hi,
I am interested in taking this. I have been bitten by expired
certificates in tests previously, albeit not from standalone files, but
embedded in test runners. Checking of expiry of standalone certificates
should be pretty simple, whereas finding embedded certificates might
require a bit more magic.

I plan to employ a Perl module Net::SSL::ExpireDate to check the expiry
date. It should be easy to use it in lintian code. Of course, first of
all, Net::SSL::ExpireDate needs to be packaged (on salsa, no ITP yet).

Andrius