Define valid after as 1m before now.

It avoids errors with immediate use of cert.
This commit is contained in:
Mariano Cano 2019-09-19 12:37:41 -07:00
parent 81093c3080
commit adc1d54b0d

View file

@ -216,7 +216,7 @@ func (m *sshCertificateValidityModifier) Modify(cert *ssh.Certificate) error {
}
if cert.ValidAfter == 0 {
cert.ValidAfter = uint64(now().Unix())
cert.ValidAfter = uint64(now().Add(-1 * time.Minute).Unix())
}
if cert.ValidBefore == 0 {
t := time.Unix(int64(cert.ValidAfter), 0)