If we can't get precise time securely and do not have real-time clock, it does not mean, there are no options left.
For instance, device may be booted for the first time in secure controlled environment and synchronize time fro trusted source.
Then, every N seconds (like 60 to 3600), device will write current time to local file. Most devices have some kind of writable local storage.
Any next synchronization will not be able to return time before already experienced moment. Certificate expiration will actually work, with a bit higher tolerance of a few hours.
Comments
If we can't get precise time securely and do not have real-time clock, it does not mean, there are no options left.
For instance, device may be booted for the first time in secure controlled environment and synchronize time fro trusted source.
Then, every N seconds (like 60 to 3600), device will write current time to local file. Most devices have some kind of writable local storage.
Any next synchronization will not be able to return time before already experienced moment. Certificate expiration will actually work, with a bit higher tolerance of a few hours.