HomeFreeBSD

Add -S option to veriexec

Description

Add -S option to veriexec

During software installation, use veriexec -S to strictly
enforce certificate validity checks (notBefore, notAfter).

Otherwise ignore certificate validity period.
It is generally unacceptible for the Internet to stop working
just because someone did not upgrade their infrastructure for a decade.

Sponsored by: Juniper Networks, Inc.

Reviewed by: sebastien.bini_stormshield.eu
Differential Revision: https://reviews.freebsd.org/D35758

(cherry picked from commit ab4f0a15188087e407426aac2a720035fd2a3b0a)

Details

Provenance
sjgAuthored on Jul 19 2022, 3:59 PM
gbeCommitted on Apr 14 2023, 7:25 AM
Reviewer
sebastien.bini_stormshield.eu
Differential Revision
D35758: Add -S option to veriexec
Parents
rG9c95cd930378: libsecureboot: Do not propagate empty string
Branches
Unknown
Tags
Unknown