Do not use expired IKMs

This commit is contained in:
Rodolphe Bréard 2024-03-16 10:29:06 +01:00
parent 66271877dc
commit 94b1809ffa

View file

@ -136,10 +136,11 @@ impl InputKeyMaterialList {
#[cfg(feature = "encryption")]
pub(crate) fn get_latest_ikm(&self) -> Result<&InputKeyMaterial> {
let now = SystemTime::now();
self.ikm_lst
.iter()
.rev()
.find(|&ikm| !ikm.is_revoked && ikm.created_at < SystemTime::now())
.find(|&ikm| !ikm.is_revoked && ikm.created_at < now && ikm.expire_at > now)
.ok_or(Error::IkmNoneAvailable)
}