From cdb65dd119c8d1116b418efcc7c8b96e2c2fd154 Mon Sep 17 00:00:00 2001 From: Rob Crittenden Date: Jul 16 2015 18:04:56 +0000 Subject: Include timezone in metadata validUntil value and use UTC time The python datetime module doesn't append the timezone in its isoformat() output, so add a Z indicating that the time is UTC time. Also generate the output using utcnow() rather than now() so the times line up. https://fedorahosted.org/ipsilon/ticket/137 Signed-off-by: Rob Crittenden --- diff --git a/ipsilon/tools/saml2metadata.py b/ipsilon/tools/saml2metadata.py index 98e7c67..d360ccd 100755 --- a/ipsilon/tools/saml2metadata.py +++ b/ipsilon/tools/saml2metadata.py @@ -97,11 +97,11 @@ class Metadata(object): elif isinstance(exp, datetime.datetime): d = exp elif isinstance(exp, datetime.timedelta): - d = datetime.datetime.now() + exp + d = datetime.datetime.utcnow() + exp else: raise TypeError('Invalid expiration date type') - self.root.set('validUntil', d.isoformat()) + self.root.set('validUntil', d.isoformat() + 'Z') def add_cert(self, certdata, use): desc = mdElement(self.role, 'KeyDescriptor')