Update atst/domain/authnid/crl/__init__.py

Co-Authored-By: montana-mil <42577527+montana-mil@users.noreply.github.com>
This commit is contained in:
dandds 2019-03-15 14:22:13 -04:00 committed by GitHub
parent ceee1f69d2
commit 4ec9ead1ac
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -182,6 +182,11 @@ class CRLCache(CRLInterface):
except crypto.X509StoreContextError as err:
if err.args[0][0] == CRL_EXPIRED_ERROR_CODE:
if app.config.get("CRL_FAIL_OPEN"):
self._log_info(
"Encountered expired CRL for certificate with CN {} and issuer CN {}, failing open.".format(
parsed.get_subject().CN, parsed.get_issuer().CN
)
)
return True
else:
raise CRLInvalidException("CRL expired. Args: {}".format(err.args))