print out why we couldn't parse the expiry time
authorAlan T. DeKok <aland@freeradius.org>
Tue, 11 Jul 2017 12:36:06 +0000 (08:36 -0400)
committerAlan T. DeKok <aland@freeradius.org>
Mon, 17 Jul 2017 12:36:52 +0000 (08:36 -0400)
src/main/tls.c

index 20e0151..e14f435 100644 (file)
@@ -1617,7 +1617,7 @@ static SSL_SESSION *cbtls_get_session(SSL *ssl, const unsigned char *data, int l
                        time_t expires;
 
                        if (ocsp_asn1time_to_epoch(&expires, vp->vp_strvalue) < 0) {
-                               RDEBUG2("Failed getting certificate expiration, removing cache entry for session %s", buffer);
+                               RDEBUG2("Failed getting certificate expiration, removing cache entry for session %s - %s", buffer, fr_strerror());
                                SSL_SESSION_free(sess);
                                sess = NULL;
                                goto error;