certtool --p7-verify does not mention expired certificates
Description of problem:
If one of certificates in a chain is expired certtool --p7-verify
will just print that
Signature status: verification failed: Public key signature verification has failed.
without any additional information.
Compare this with certtool --verify
output:
Chain verification output: Not verified. The certificate is NOT trusted. The certificate chain uses expired certificate.
Which gives more precise information.
Version of gnutls used:
3.6.9
Distributor of gnutls (e.g., Ubuntu, Fedora, RHEL)
Debian
How reproducible:
Steps to Reproduce:
- `certtool --p7-verify --infile outdated-data.sig --load-data outdated-data --inder -d 99 --load-ca-cert ../grfc.crt