@@ -190,6 +190,23 @@ void validateClientCertSucceedsWhenChainOmitsTrustAnchor() throws Exception {
190190 assertThat (result ).contains (leafCert );
191191 }
192192
193+ @ Test
194+ void validateClientCertRejectsExpiredLeafCertificate () throws Exception {
195+ KeyPair rootKp = generateKeyPair ();
196+ X500Name rootName = new X500Name ("CN=Test Root CA" );
197+ X509Certificate rootCert = signCert (rootName , rootName , rootKp .getPublic (), rootKp .getPrivate (), true , BigInteger .ONE );
198+
199+ KeyPair leafKp = generateKeyPair ();
200+ X509Certificate expiredLeafCert = signCertWithValidity (
201+ new X500Name ("CN=expired-leaf-instance" ), rootName , leafKp .getPublic (), rootKp .getPrivate (), false ,
202+ BigInteger .TWO , new Date (System .currentTimeMillis () - 7_200_000 ), new Date (System .currentTimeMillis () - 3_600_000 ));
203+
204+ TlsClientAuthConfiguration config = new TlsClientAuthConfiguration (toPem (rootCert ), null );
205+
206+ assertThatThrownBy (() -> service .validateClientCert (new X509Certificate []{expiredLeafCert }, config ))
207+ .hasMessageContaining ("tls_client_auth" );
208+ }
209+
193210 @ Test
194211 void validateClientCertSucceedsWhenChainIncludesTrustAnchor () throws Exception {
195212 // Reproduces the reviewer's concern (PR #3972 discussion on TlsClientAuthentication.java:113):
@@ -805,6 +822,17 @@ private static X509Certificate signCert(X500Name subject, X500Name issuer, Publi
805822 Integer keyUsageBits , List <KeyPurposeId > ekuPurposes ) throws Exception {
806823 Date notBefore = new Date (System .currentTimeMillis () - 60_000 );
807824 Date notAfter = new Date (System .currentTimeMillis () + 3_600_000 );
825+ return signCertWithValidity (subject , issuer , subjectKey , signerKey , isCa , serial , notBefore , notAfter , keyUsageBits , ekuPurposes );
826+ }
827+
828+ private static X509Certificate signCertWithValidity (X500Name subject , X500Name issuer , PublicKey subjectKey ,
829+ PrivateKey signerKey , boolean isCa , BigInteger serial , Date notBefore , Date notAfter ) throws Exception {
830+ return signCertWithValidity (subject , issuer , subjectKey , signerKey , isCa , serial , notBefore , notAfter , null , null );
831+ }
832+
833+ private static X509Certificate signCertWithValidity (X500Name subject , X500Name issuer , PublicKey subjectKey ,
834+ PrivateKey signerKey , boolean isCa , BigInteger serial , Date notBefore , Date notAfter ,
835+ Integer keyUsageBits , List <KeyPurposeId > ekuPurposes ) throws Exception {
808836 JcaX509v3CertificateBuilder builder = new JcaX509v3CertificateBuilder (
809837 issuer , serial , notBefore , notAfter , subject , subjectKey );
810838 builder .addExtension (Extension .basicConstraints , true , new BasicConstraints (isCa ));
0 commit comments