Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://acao.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=acao.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=acao.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=acao.jp
And you can
check your domain name
.
#
Certificate of
acao.jp
{ "serial": "0D2E8FAD32F1118B09B902DD7DAF5B2D", "OCSP_serial": null, "OCSP_cert_status": null, "OCSP_this_update": null, "OCSP_next_update": null, "domainName": "acao.jp", "port": 443, "subjectAltName": "DNS:acao.jp", "is_valid": true, "CA": "Google Trust Services", "updated_at": "2025/11/20 17:23:46", "expires_at": "2026/02/18 18:17:19", "today": "2026/01/01 08:11:42", "UTC": { "updated_at": "2025-11-20T08:23:46Z", "expires_at": "2026-02-18T09:17:19Z", "today": "2025-12-31T23:11:42Z" }, "remaining_days": 48 }
#
OCSP response of
acao.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:CN = acao.jp i:C = US, O = Google Trust Services, CN = WR3 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Nov 20 08:23:46 2025 GMT; NotAfter: Feb 18 09:17:19 2026 GMT 1 s:C = US, O = Google Trust Services, CN = WR3 i:C = US, O = Google Trust Services LLC, CN = GTS Root R1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT 2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R1 i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA a:PKEY: rsaEncryption, 4096 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIFGTCCBAGgAwIBAgIQDS6PrTLxEYsJuQLdfa9bLTANBgkqhkiG9w0BAQsFADA7 MQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMQww CgYDVQQDEwNXUjMwHhcNMjUxMTIwMDgyMzQ2WhcNMjYwMjE4MDkxNzE5WjASMRAw DgYDVQQDEwdhY2FvLmpwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA 4iUWElrnmH9mdYnq/YmZMhZyj5KlYAbdgbcH0IHritxvAHMFUwyKf0Bnhw9mav4L w5oGk3oDKAWUhBA/MlG2okvx5f8ia9BKmc4S1YwBooJy1Qgo9qAFl8045PGX2mCB vqMTvFflFObvlz0qWUDM3MU4X/tzdDIF0wKGx+xgybGFb4+Qp/o7UtvcFfxX78yd 7FJJn/5XJSmC2LFNgjYa8thppv48vaJ435ElyFyJ0EwYjWzY3JRb/8Kw/O4MjAHS eZp6lPC7uihALKLoB8Zm8sVo+GBNI89FahtioiCPpU7x09+i8E4TJg8mEgassar/ c7Fo703Byo3/Mye3LoLvjwIDAQABo4ICQDCCAjwwDgYDVR0PAQH/BAQDAgWgMBMG A1UdJQQMMAoGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFA6cNguM v5eJbz5lzDCSmaAhYZlxMB8GA1UdIwQYMBaAFMeB9f2OiNkAPE1jolAxJKDOI/4j MF4GCCsGAQUFBwEBBFIwUDAnBggrBgEFBQcwAYYbaHR0cDovL28ucGtpLmdvb2cv cy93cjMvRFM0MCUGCCsGAQUFBzAChhlodHRwOi8vaS5wa2kuZ29vZy93cjMuY3J0 MBIGA1UdEQQLMAmCB2FjYW8uanAwEwYDVR0gBAwwCjAIBgZngQwBAgEwNgYDVR0f BC8wLTAroCmgJ4YlaHR0cDovL2MucGtpLmdvb2cvd3IzL3FtczBPQVhndElnLmNy bDCCAQQGCisGAQQB1nkCBAIEgfUEgfIA8AB2AJaXZL9VWJet90OHaDcIQnfp8DrV 9qTzNm5GpD8PyqnGAAABmqCTvCoAAAQDAEcwRQIgf1qnkOXd7YvwlRebOQ4O8JJf pijpKPagT/LqClfz7GwCIQDp8BRXeRq7lc2xrOFwknCd4CMFts4zqB786wgdM4MJ iQB2ANFuqaVoB35mNaA/N6XdvAOlPEESFNSIGPXpMbMjy5UEAAABmqCTvNEAAAQD AEcwRQIhAM5amsp0JjyOnaqGBnAVe6zRhMN018rZpfI4+dSjk3jDAiBM1aIFxWzy Tshe8EBbPbtwM/JyYA1LTnend+Sv9goVXzANBgkqhkiG9w0BAQsFAAOCAQEAXrNc P1U1CluADIvKq9VJIb/lJvbpykGgjkCJUjCXI9IqE1h8KR/jux59osyJuyfUhkGM oZyeavJAsmKxAoESawYx+BQz6F3TuZY2/T49Dzw8UYRhnP3bUfzXTZjRnLNQs8Jw mHIq9v/B6uo+Edr5e7mfQE24+zcOYHM4xc/NCp0dqfxvHV/A5NXzuDm/1PbDfnCJ E5jx/rmyne+TE6PfeYDr/0iC1nNziWpLisECQcnX1LD1ESgq4B6qEj0ywbWZcEHV piOtsqcFDjIjvG1AVr3oSxodloONRQjb+26wyNT2XAja6t/ILldGKTJvb283mL2q Ntfzo7I8o3pkwFmWJA== -----END CERTIFICATE----- subject=CN = acao.jp issuer=C = US, O = Google Trust Services, CN = WR3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 4490 bytes and written 398 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
acao.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.