@@ -85,7 +85,7 @@ encInvitationSize = 900
85
85
86
86
newRCHostPairing :: TVar ChaChaDRG -> IO RCHostPairing
87
87
newRCHostPairing drg = do
88
- ((_, caKey), caCert) <- genCredentials drg Nothing (- 25 , 24 * 999999 ) " ca"
88
+ ((_, caKey), caCert) <- genCredentials drg Nothing (25 , 24 * 999999 ) " ca"
89
89
(_, idPrivKey) <- atomically $ C. generateKeyPair drg
90
90
pure RCHostPairing {caKey, caCert, idPrivKey, knownHost = Nothing }
91
91
@@ -193,7 +193,7 @@ connectRCHost drg pairing@RCHostPairing {caKey, caCert, idPrivKey, knownHost} ct
193
193
genTLSCredentials :: TVar ChaChaDRG -> C. APrivateSignKey -> X. SignedCertificate -> IO TLS. Credential
194
194
genTLSCredentials drg caKey caCert = do
195
195
let caCreds = (C. signatureKeyPair caKey, caCert)
196
- leaf <- genCredentials drg (Just caCreds) (0 , 24 * 999999 ) " localhost" -- session-signing cert
196
+ leaf <- genCredentials drg (Just caCreds) (1 , 24 * 999999 ) " localhost" -- session-signing cert
197
197
pure . snd $ tlsCredentials (leaf :| [caCreds])
198
198
199
199
certFingerprint :: X. SignedCertificate -> C. KeyHash
@@ -259,7 +259,7 @@ connectRCCtrl drg (RCVerifiedInvitation inv@RCInvitation {ca, idkey}) pairing_ h
259
259
where
260
260
newCtrlPairing :: IO RCCtrlPairing
261
261
newCtrlPairing = do
262
- ((_, caKey), caCert) <- genCredentials drg Nothing (0 , 24 * 999999 ) " ca"
262
+ ((_, caKey), caCert) <- genCredentials drg Nothing (1 , 24 * 999999 ) " ca"
263
263
(_, dhPrivKey) <- atomically $ C. generateKeyPair drg
264
264
pure RCCtrlPairing {caKey, caCert, ctrlFingerprint = ca, idPubKey = idkey, dhPrivKey, prevDhPrivKey = Nothing }
265
265
updateCtrlPairing :: RCCtrlPairing -> ExceptT RCErrorType IO RCCtrlPairing
0 commit comments