Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://fukushima.ltta.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=fukushima.ltta.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=fukushima.ltta.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=fukushima.ltta.jp
And you can
check your domain name
.
#
Certificate of
fukushima.ltta.jp
{ "serial": "0DD60789FBCA7011BFC951E7AE69C1CD", "OCSP_serial": "0DD60789FBCA7011BFC951E7AE69C1CD", "OCSP_cert_status": "good", "OCSP_this_update": "Nov 21 03:15:02 2024 GMT", "OCSP_next_update": "Nov 28 02:15:02 2024 GMT", "domainName": "fukushima.ltta.jp", "port": 443, "subjectAltName": "DNS:ltta.jp, DNS:fukui.ltta.jp, DNS:fukushima.ltta.jp, DNS:tochigi.ltta.jp, DNS:kyoto.ltta.jp", "is_valid": true, "CA": "Amazon", "updated_at": "2024/06/01 09:00:00", "expires_at": "2025/07/01 08:59:59", "today": "2024/11/21 16:09:45", "UTC": { "updated_at": "2024-06-01T00:00:00Z", "expires_at": "2025-06-30T23:59:59Z", "today": "2024-11-21T07:09:45Z" }, "remaining_days": 221 }
#
OCSP response of
fukushima.ltta.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: 55D9185FD21CCC01E158B4BEABD9554201D72E02 Produced At: Nov 21 03:30:47 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: 2A1C8FAC7666A96B042770BD6BA4211967C81348 Issuer Key Hash: 55D9185FD21CCC01E158B4BEABD9554201D72E02 Serial Number: 0DD60789FBCA7011BFC951E7AE69C1CD Cert Status: good This Update: Nov 21 03:15:02 2024 GMT Next Update: Nov 28 02:15:02 2024 GMT Signature Algorithm: sha256WithRSAEncryption Signature Value: 6e:64:2b:eb:35:f9:4a:f8:89:b5:c2:31:19:05:70:69:bd:54: 5a:d3:93:59:b5:26:5b:2d:a3:e4:a3:6e:02:28:23:c7:05:fd: f5:9e:bc:8f:13:44:63:b5:45:57:b3:0a:d9:99:7e:f5:b7:f4: 32:76:b0:36:c1:e2:8c:36:07:9e:ee:8e:b4:7a:16:9a:2c:60: 4f:15:78:2f:5a:51:bf:18:f2:b7:e3:e9:a6:79:f7:35:d4:3c: 5e:03:32:2f:b7:0e:1a:d8:67:2b:a5:76:83:f7:18:17:74:a2: ba:75:9d:9c:51:e9:ef:e0:17:cd:d8:7f:13:87:8b:3e:6e:34: aa:f0:df:30:b5:9c:ce:f5:ac:5f:c6:81:9d:1e:d3:ee:c3:83: c9:d3:6e:07:71:56:30:e1:ed:ad:ce:cc:28:12:cb:58:8a:4b: e5:9b:41:2f:1b:1c:0d:a8:c3:3c:f8:ff:3b:93:27:b4:e1:a9: 6a:46:aa:e8:61:3d:43:14:12:e5:93:1c:f8:ae:78:a7:c8:6f: 34:51:e7:a2:7d:b4:50:8a:ae:f5:b3:2f:3a:c3:24:41:86:92: e8:6c:f0:b0:e3:24:06:ac:b4:70:97:f6:27:56:4b:5c:10:f0: 94:65:5e:66:5b:1d:60:b6:fe:d1:d4:e1:6b:84:9f:14:de:80: 76:70:e0:b1 ====================================== --- Certificate chain 0 s:CN = ltta.jp i:C = US, O = Amazon, CN = Amazon RSA 2048 M03 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 1 00:00:00 2024 GMT; NotAfter: Jun 30 23:59:59 2025 GMT 1 s:C = US, O = Amazon, CN = Amazon RSA 2048 M03 i:C = US, O = Amazon, CN = Amazon Root CA 1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Aug 23 22:26:04 2022 GMT; NotAfter: Aug 23 22:26:04 2030 GMT 2 s:C = US, O = Amazon, CN = Amazon Root CA 1 i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: May 25 12:00:00 2015 GMT; NotAfter: Dec 31 01:00:00 2037 GMT 3 s:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 i:C = US, O = "Starfield Technologies, Inc.", OU = Starfield Class 2 Certification Authority a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Sep 2 00:00:00 2009 GMT; NotAfter: Jun 28 17:39:16 2034 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIF/DCCBOSgAwIBAgIQDdYHifvKcBG/yVHnrmnBzTANBgkqhkiG9w0BAQsFADA8 MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRwwGgYDVQQDExNBbWF6b24g UlNBIDIwNDggTTAzMB4XDTI0MDYwMTAwMDAwMFoXDTI1MDYzMDIzNTk1OVowEjEQ MA4GA1UEAxMHbHR0YS5qcDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB AMh84xdlx1lUNJmNQ85fkmli+BlU5/oorsYmfOxQEX3aE51EFS+38ssrinmpsB2u GkZ21TbnJt5MFor6S43IyjyWTZfPLLbo1zLXaZhBrOfrOmRD0fvmb0sfICVfljUN R6q1oOZir3q4ki8iiXqHVA+jtRLAYwhyq8C6fht8bzCggcKvXbDyE38B/CiDerkW UH/RcK7ecRNpq0peYAdWuRCH28h7wuIMhQZ5+Dbb+MVyYdqYuR1UzseS0np7XOfr kaHIlWWDa7liI6uIBFDtjk3dkWpSNvPLHSHKxYcIBg4TXIeDoIndWWQXIuM/UdgY DEomFNMjJM/AKJeSaI4pyT0CAwEAAaOCAyIwggMeMB8GA1UdIwQYMBaAFFXZGF/S HMwB4Vi0vqvZVUIB1y4CMB0GA1UdDgQWBBS+Dili08K+as+c8dChdEBaNL078TBU BgNVHREETTBLggdsdHRhLmpwgg1mdWt1aS5sdHRhLmpwghFmdWt1c2hpbWEubHR0 YS5qcIIPdG9jaGlnaS5sdHRhLmpwgg1reW90by5sdHRhLmpwMBMGA1UdIAQMMAow CAYGZ4EMAQIBMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYI KwYBBQUHAwIwOwYDVR0fBDQwMjAwoC6gLIYqaHR0cDovL2NybC5yMm0wMy5hbWF6 b250cnVzdC5jb20vcjJtMDMuY3JsMHUGCCsGAQUFBwEBBGkwZzAtBggrBgEFBQcw AYYhaHR0cDovL29jc3AucjJtMDMuYW1hem9udHJ1c3QuY29tMDYGCCsGAQUFBzAC hipodHRwOi8vY3J0LnIybTAzLmFtYXpvbnRydXN0LmNvbS9yMm0wMy5jZXIwDAYD VR0TAQH/BAIwADCCAX4GCisGAQQB1nkCBAIEggFuBIIBagFoAHYAzxFW7tUufK/z h1vZaS6b6RpxZ0qwF+ysAdJbd87MOwgAAAGP0m2qrQAABAMARzBFAiA3vzpj8yx7 fT4WwvWdRtzrL842Ou/0H36UrYiPf43EigIhAOOfDQSRxz1aD51zbKZIYuARLrTF fy/Mj3DCBGgGHdr+AHcAfVkeEuF4KnscYWd8Xv340IdcFKBOlZ65Ay/ZDowuebgA AAGP0m2qcgAABAMASDBGAiEArKMiYddiiaTyYBLm8IzVXjjgfk4KvLez6s4Ot5w/ kFoCIQDh30WljEBZlJHzcxaj9WSXTBp5A0vfRnDuB8VRo8KGMQB1AObSMWNAd4zB EEEG13G5zsHSQPaWhIb7uocyHf0eN45QAAABj9JtqpoAAAQDAEYwRAIgYYNk5s7/ OblJvlspY1chdIulqiN9l2Qz4L0rxcuDdsgCIFS68Ziuv6TqxD4BqVcCH4//HeaF sYBE4qptYPGAUv6LMA0GCSqGSIb3DQEBCwUAA4IBAQBVOG5Y71kY4p9OV5Acbmda fAqqdjONHgXJBNOyl3bMgnYWFTYB/beAxydmxEpjxfAOYOknbFnmQKmgjy34Dwvy JGxR0rzCpPMxXDbgC3E/ZZD8dC4aBG4E3PEoE5f0QSR/DEWwjHjdRHAuAU5BXM2N aK98Rbcod6XZGnCBxYqTRgFj/8yn+YMYfLZmVchsNemMaZwiyfPfSAQinWhx+p3X 7fkBnOcCYzoOqH6sePxELB8ycMwL+0I2ipWYTJBezToeJkqgDbrCJ1Jzx1LivNzG jsplPq+8AxDs26evIKVjkx43Xd/2au6sXbpmbfnosW5nd3w0ooGCm5EYd9M0HYa7 -----END CERTIFICATE----- subject=CN = ltta.jp issuer=C = US, O = Amazon, CN = Amazon RSA 2048 M03 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 6015 bytes and written 392 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
fukushima.ltta.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.