mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-23 03:41:45 +00:00
Fix CSR test to accept certs shorter than the requested duration
This commit is contained in:
parent
883250145c
commit
11c2674ec2
@ -166,7 +166,10 @@ var _ = SIGDescribe("Certificates API [Privileged:ClusterAdmin]", func() {
|
||||
framework.ExpectNoError(err)
|
||||
framework.ExpectEqual(len(certs), 1, "expected a single cert, got %#v", certs)
|
||||
cert := certs[0]
|
||||
framework.ExpectEqual(cert.NotAfter.Sub(cert.NotBefore), time.Hour+5*time.Minute, "unexpected cert duration: %s", dynamiccertificates.GetHumanCertDetail(cert))
|
||||
// make sure the cert is not valid for longer than our requested time (plus allowance for backdating)
|
||||
if e, a := time.Hour+5*time.Minute, cert.NotAfter.Sub(cert.NotBefore); a > e {
|
||||
framework.Failf("expected cert valid for %s or less, got %s: %s", e, a, dynamiccertificates.GetHumanCertDetail(cert))
|
||||
}
|
||||
|
||||
newClient, err := certificatesclient.NewForConfig(rcfg)
|
||||
framework.ExpectNoError(err)
|
||||
|
Loading…
Reference in New Issue
Block a user