diff --git a/jams-ca/src/main/java/net/jami/jams/ca/JamsCA.java b/jams-ca/src/main/java/net/jami/jams/ca/JamsCA.java index 24ff27dd7e84d4f49f864be3a1408b9ca7f72933..73b8bf576e6cbcc622ece8244e8868f88ed3a07a 100644 --- a/jams-ca/src/main/java/net/jami/jams/ca/JamsCA.java +++ b/jams-ca/src/main/java/net/jami/jams/ca/JamsCA.java @@ -78,12 +78,27 @@ public class JamsCA implements CertificateAuthority { CertificateAuthorityConfig config = gson.fromJson(settings, CertificateAuthorityConfig.class); CA = ca; - OCSP = ca; + OCSP = ocsp; serverDomain = config.getServerDomain(); signingAlgorithm = config.getSigningAlgorithm(); + crlLifetime = config.getCrlLifetime(); userLifetime = config.getUserLifetime(); deviceLifetime = config.getDeviceLifetime(); + + if (deviceLifetime > userLifetime) { + log.warn( + "Device lifetime is greater than user lifetime, this is not recommended, please change this in the config file."); + } + + X509Certificate cert = ca.getCertificate(); + long caLifetime = cert.getNotAfter().getTime() - cert.getNotBefore().getTime(); + + if (userLifetime > caLifetime) { + log.warn( + "User lifetime is greater than CA lifetime, this is not recommended, please change this in the config file."); + } + if (ca != null && ocsp != null) { crlWorker = new CRLWorker(CA.getPrivateKey(), CA.getCertificate()); try { diff --git a/jams-react-client/src/components/ServerParameters/ServerParameters.tsx b/jams-react-client/src/components/ServerParameters/ServerParameters.tsx index 1489ab7a1bed6aa14d15299a2c44c0e610b389b0..01cf480e8b004fca6d9cafc76d7a8d3b8c18b9a9 100644 --- a/jams-react-client/src/components/ServerParameters/ServerParameters.tsx +++ b/jams-react-client/src/components/ServerParameters/ServerParameters.tsx @@ -62,13 +62,11 @@ export default function ServerParameters(props) { { value: 7889238000, label: i18next.t("3_months", "3 months") }, { value: 15778476000, label: i18next.t("6_months", "6 months") }, { value: 31556952000, label: i18next.t("1_year", "1 year") }, - { value: 157784760000, label: i18next.t("5_years", "5 years") }, ]; const userAccountLifetimeTypes = [ { value: 31556952000, label: i18next.t("1_year", "1 year") }, { value: 157784760000, label: i18next.t("5_years", "5 years") }, - { value: 315569520000, label: i18next.t("10_years", "10 years") }, ]; const certificateRevocationTypesItems = tool.buildSelectMenuItems(