Earlier quoted context omitted.
So instead of trying to conform to the x.509 spec MS should have just developed their own certificate validation scheme, because that would totally be less of a "footgun" than conforming to the spec. Am I getting this right? Why aren't we blaming the people behind RFC5280, after all it was them who came up with this awful idea that certificates should expire. >giant footgun oh dear god how are you generating your cer…
FWIW, there are basically no common implementations that fully conform to the x.509 spec. That thing is a bundle of unimplemented features.
However, I'd argue that disregarding the Validity section would be an unusually big departure from the spec, not comparable to the typical silliness surrounding x.509.