Fix handling of CRL without next_update

We don't seem to have any CRL without a next_update field, but cryptography
40.0.2 supports that.

Signed-off-by: Gilles Peskine <[email protected]>
This commit is contained in:
Gilles Peskine
2026-08-21 13:49:56 +02:00
parent 8e5d04d5ca
commit 6e2dcf9bfd
+3 -1
View File
@@ -105,8 +105,10 @@ class AuditData:
# CertificateRevocationList expires after "next_update"
# CertificateRevocationList is invalid before "last_update"
elif self.data_type == DataType.CRL:
self.not_valid_after = x509_obj.next_update
assert isinstance(x509_obj, cryptography.x509.CertificateRevocationList)
self.not_valid_after = \
datetime.datetime.max if x509_obj.next_update is None else \
x509_obj.next_update
self.not_valid_before = x509_obj.last_update
# CertificateSigningRequest is always valid.
elif self.data_type == DataType.CSR: