certtool --p7-verify does not mention expired certificates

Description of problem:

If one of certificates in a chain is expired certtool --p7-verify will just print that

	Signature status: verification failed: Public key signature verification has failed.

without any additional information.

Compare this with certtool --verify output:

Chain verification output: Not verified. The certificate is NOT trusted. The certificate chain uses expired certificate. 

Which gives more precise information.

Version of gnutls used:

3.6.9

Distributor of gnutls (e.g., Ubuntu, Fedora, RHEL)

Debian

How reproducible:

Steps to Reproduce:

  • `certtool --p7-verify --infile outdated-data.sig --load-data outdated-data --inder -d 99 --load-ca-cert ../grfc.crt