Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://hcdr.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=hcdr.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=hcdr.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=hcdr.jp
And you can
check your domain name
.
#
Certificate of
hcdr.jp
{ "serial": "03B0BC076C5D3E7C0EADA1321587DABF", "OCSP_serial": "03B0BC076C5D3E7C0EADA1321587DABF", "OCSP_cert_status": "good", "OCSP_this_update": "Nov 19 20:00:18 2024 GMT", "OCSP_next_update": "Nov 26 19:00:17 2024 GMT", "domainName": "hcdr.jp", "port": 443, "subjectAltName": "DNS:hcdr.jp, DNS:*.hcdr.jp", "is_valid": true, "CA": "Google Trust Services", "updated_at": "2024/11/05 02:08:30", "expires_at": "2025/02/03 02:08:29", "today": "2024/11/21 15:47:19", "UTC": { "updated_at": "2024-11-04T17:08:30Z", "expires_at": "2025-02-02T17:08:29Z", "today": "2024-11-21T06:47:19Z" }, "remaining_days": 73 }
#
OCSP response of
hcdr.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: 9077923567C4FFA8CCA9E67BD980797BCC93F938 Produced At: Nov 19 20:00:18 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: B9BED5F1A61E40B24196B0C29E7E1A9D8BFCB520 Issuer Key Hash: 9077923567C4FFA8CCA9E67BD980797BCC93F938 Serial Number: 03B0BC076C5D3E7C0EADA1321587DABF Cert Status: good This Update: Nov 19 20:00:18 2024 GMT Next Update: Nov 26 19:00:17 2024 GMT Signature Algorithm: ecdsa-with-SHA256 Signature Value: 30:45:02:20:5f:9d:21:d4:04:70:79:c0:07:18:54:98:4e:1a: 8f:8e:11:2f:a7:9e:81:a9:a3:c5:03:cd:ab:f5:e8:ac:50:0d: 02:21:00:e0:e3:8a:7d:eb:79:55:e6:2b:da:2a:5a:0d:0a:6d: 06:e7:ef:59:7c:6d:fa:a5:d0:99:57:03:e7:6d:2c:e6:af ====================================== --- Certificate chain 0 s:CN = hcdr.jp i:C = US, O = Google Trust Services, CN = WE1 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: ecdsa-with-SHA256 v:NotBefore: Nov 4 17:08:30 2024 GMT; NotAfter: Feb 2 17:08:29 2025 GMT 1 s:C = US, O = Google Trust Services, CN = WE1 i:C = US, O = Google Trust Services LLC, CN = GTS Root R4 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: ecdsa-with-SHA384 v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT 2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R4 i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA a:PKEY: id-ecPublicKey, 384 (bit); sigalg: RSA-SHA256 v:NotBefore: Nov 15 03:43:21 2023 GMT; NotAfter: Jan 28 00:00:42 2028 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIDmDCCAz+gAwIBAgIQA7C8B2xdPnwOraEyFYfavzAKBggqhkjOPQQDAjA7MQsw CQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMQwwCgYD VQQDEwNXRTEwHhcNMjQxMTA0MTcwODMwWhcNMjUwMjAyMTcwODI5WjASMRAwDgYD VQQDEwdoY2RyLmpwMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEG4MJIgFTj3Ss JY6Dq3CIkKi+DE6X/Svr3IR+/WXO/WwnaRR+OMBTagmZ3ErN2dSvlHBgrLFc3YNB DwDM44lS/6OCAkwwggJIMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKBggrBgEF BQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBTaZxXHEV6xQGNcoRu/1BcPlBqF GzAfBgNVHSMEGDAWgBSQd5I1Z8T/qMyp5nvZgHl7zJP5ODBeBggrBgEFBQcBAQRS MFAwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vLnBraS5nb29nL3Mvd2UxL0E3QTAlBggr BgEFBQcwAoYZaHR0cDovL2kucGtpLmdvb2cvd2UxLmNydDAdBgNVHREEFjAUggdo Y2RyLmpwggkqLmhjZHIuanAwEwYDVR0gBAwwCjAIBgZngQwBAgEwNgYDVR0fBC8w LTAroCmgJ4YlaHR0cDovL2MucGtpLmdvb2cvd2UxL21HblY0UldJem4wLmNybDCC AQUGCisGAQQB1nkCBAIEgfYEgfMA8QB3AM8RVu7VLnyv84db2Wkum+kacWdKsBfs rAHSW3fOzDsIAAABkvhdNH4AAAQDAEgwRgIhAKmhecT0aEgBh/hA/jb1IWkKYKxE qMbcRvG8P3FqmpeCAiEApxOyZVm/4cirY+MwnIedjhrZcczqV2n3tfmWTTxTkEAA dgDM+w9qhXEJZf6Vm1PO6bJ8IumFXA2XjbapflTA/kwNsAAAAZL4XTlLAAAEAwBH MEUCIQD2LbM0uwWEg4z+D7sGBcNd3Vo7Kx8aTvehoBChqWT7SAIgOFq3wnh6Xqpp QfBOrH4NzT9C8cM40yvahjg8k8xqneswCgYIKoZIzj0EAwIDRwAwRAIgFyup5lvU 3JLbXiyRzSWYA/g+0rsuGGxbF/4ltKlRY08CIB7bbKZlxe8IN18ADGNpALj7eAyB LKQ8cGCXHw4igUgU -----END CERTIFICATE----- subject=CN = hcdr.jp issuer=C = US, O = Google Trust Services, CN = WE1 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: ECDSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 3099 bytes and written 398 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 256 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
hcdr.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.