I have systems that sometimes lose time drastically due to low RTC battery voltage such that the system time lies outside these boundaries (/etc/openvpn/certificate):
Not Before: Jun 18 16:40:18 2012 GMT
Not After : Jun 16 16:40:18 2023 GMT
I would still like to have these systems connect to the VPN, so I don't get messages like:
Feb 6 13:50:58 hostname ovpn-client[2217]: VERIFY ERROR: depth=1, error=certificate is not yet valid: /C=ZA/ST=GA/L=Johannesburg/O=Embedded_IQ/CN=Embedded_IQ_CA/[email protected]
I can avoid this problem by simply correcting the datetime on these systems, but it's not always feasible... these are remote systems.