Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://kepura.com
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=kepura.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=kepura.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=kepura.com
And you can
check your domain name
.
#
Certificate of
kepura.com
{ "serial": "08CF781C46DD528CEF290BDA65B45F6D", "OCSP_serial": null, "OCSP_cert_status": null, "OCSP_this_update": null, "OCSP_next_update": null, "domainName": "kepura.com", "port": 443, "subjectAltName": "DNS:*.kepura.com, DNS:kepura.com", "is_valid": true, "CA": "Amazon", "updated_at": "2024/04/12 09:00:00", "expires_at": "2025/05/13 08:59:59", "today": "2024/11/21 15:38:33", "UTC": { "updated_at": "2024-04-12T00:00:00Z", "expires_at": "2025-05-12T23:59:59Z", "today": "2024-11-21T06:38:33Z" }, "remaining_days": 172 }
#
OCSP response of
kepura.com
from OCSP Stapling
CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:CN = *.kepura.com i:C = US, O = Amazon, CN = Amazon RSA 2048 M02 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Apr 12 00:00:00 2024 GMT; NotAfter: May 12 23:59:59 2025 GMT 1 s:C = US, O = Amazon, CN = Amazon RSA 2048 M02 i:C = US, O = Amazon, CN = Amazon Root CA 1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Aug 23 22:25:30 2022 GMT; NotAfter: Aug 23 22:25:30 2030 GMT 2 s:C = US, O = Amazon, CN = Amazon Root CA 1 i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: May 25 12:00:00 2015 GMT; NotAfter: Dec 31 01:00:00 2037 GMT 3 s:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 i:C = US, O = "Starfield Technologies, Inc.", OU = Starfield Class 2 Certification Authority a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Sep 2 00:00:00 2009 GMT; NotAfter: Jun 28 17:39:16 2034 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIF0TCCBLmgAwIBAgIQCM94HEbdUozvKQvaZbRfbTANBgkqhkiG9w0BAQsFADA8 MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRwwGgYDVQQDExNBbWF6b24g UlNBIDIwNDggTTAyMB4XDTI0MDQxMjAwMDAwMFoXDTI1MDUxMjIzNTk1OVowFzEV MBMGA1UEAwwMKi5rZXB1cmEuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEAteubLNLAVdu/viNru8BwohKGMGETAQLzVsxSuG2mw6wMbolwZhn+uZkW ueNy6xipatu/M1IuH/34AVLr/Tgqbpu3uE5CB4cvcbuQF61FKG5cDet/KG2BIb1N 0xUMgN6htCQjvo5dtCdFXPbcTm5kvkxvwgdoIbijEKVBvXM56uAXwbkiYna7O8RS j3nnfhAKPuMMGRzafwtndeK5In+ZOLcJ1/SGRHjtSPfpWnz0beOy/Mhuif1mZ9eS u4dB7XcroKtBKw2VIOtH3xVOxC/u2cG26s6BexTNIk+mfsFtXLUQRRFlR7/hm72L QJtkuSTL3qGg/UiDXNku95q4TBoneQIDAQABo4IC8jCCAu4wHwYDVR0jBBgwFoAU wDFSzVpQw4J8dHHOy+mc+XrrguIwHQYDVR0OBBYEFAWf3cobWMO1ocQCnU7ML4cs Zcv4MCMGA1UdEQQcMBqCDCoua2VwdXJhLmNvbYIKa2VwdXJhLmNvbTATBgNVHSAE DDAKMAgGBmeBDAECATAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUH AwEGCCsGAQUFBwMCMDsGA1UdHwQ0MDIwMKAuoCyGKmh0dHA6Ly9jcmwucjJtMDIu YW1hem9udHJ1c3QuY29tL3IybTAyLmNybDB1BggrBgEFBQcBAQRpMGcwLQYIKwYB BQUHMAGGIWh0dHA6Ly9vY3NwLnIybTAyLmFtYXpvbnRydXN0LmNvbTA2BggrBgEF BQcwAoYqaHR0cDovL2NydC5yMm0wMi5hbWF6b250cnVzdC5jb20vcjJtMDIuY2Vy MAwGA1UdEwEB/wQCMAAwggF/BgorBgEEAdZ5AgQCBIIBbwSCAWsBaQB2AM8RVu7V Lnyv84db2Wkum+kacWdKsBfsrAHSW3fOzDsIAAABjtBtGfQAAAQDAEcwRQIhALgF QsiNDgOhBCfEZKheeN5sTN1+6j4U1FD+P5FF8pndAiBa0iPpiijjdkimDdGTgPx8 bXQPu0gNGYNzgQUuoInqGQB3AFWB1MIWkDYBSuoLm1c8U/DA5Dh4cCUIFy+jqh0H E9MMAAABjtBtGhEAAAQDAEgwRgIhAJUgG1UU8oP5rUTv045k7otxWGpQL97EQpzF nXGMcOgtAiEAu1LtV8T42uibjPOkw97fJPmO2qnuNPN8N2scm5KDX7QAdgB9WR4S 4XgqexxhZ3xe/fjQh1wUoE6VnrkDL9kOjC55uAAAAY7QbRlwAAAEAwBHMEUCIFJT 4VcJmJxlISPkVnaBN0pQli79Nkos/o79SV1Uq/ApAiEApMqfWpoxXJUdTx5ERdbS VHB5IDW8Antz+pzYIjNw4wAwDQYJKoZIhvcNAQELBQADggEBABZUzFN6dTkXdrYt /Mvra0twG4Y5YM1wImElnHwnDYlJOHYEhd9tgSuAKuZgSFb9+uj4aRJPTx8vaHfa MBS77dFj9QCzU9Fhue8VUfAymG7ZMEGMi1PgHcAH8wHvqCOz5YjqU2Dl8Nwha2GO g5lGfQlxHFsOvlKpFDYh1RxTDOJ2Qwbni0qyLL0xdx2rY5SY9XdEbGc72Pw2giuK 5GsZoBaXkAOzmpUwh3XNNioRdc4kumfZPqS6qzpKtHPB6d128tC2y7f5ZyA/wUnC d1JNFw5DcWnW3kHIX9Hd58u2fmINqUO+n2Gw0xPGXf2tT0xPcKlWJOWYs+qZmtBx e6buYcs= -----END CERTIFICATE----- subject=CN = *.kepura.com issuer=C = US, O = Amazon, CN = Amazon RSA 2048 M02 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA Server Temp Key: ECDH, prime256v1, 256 bits --- SSL handshake has read 5613 bytes and written 447 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 Session-ID: 019C5EA5EE2D17F83B8EF6E11BA101793974060C5C2BF8765BA7A63C23363ADF Session-ID-ctx: Master-Key: C50A284C96811443C504C1A881BF766403788A6AAC2967A0A529B3B25D12D916B5128FA905E0D25761D7E5B3D401835A PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 86400 (seconds) TLS session ticket: 0000 - 01 f5 c6 3f ad 35 1b 2a-cd f7 2e 97 3b 20 af fc ...?.5.*....; .. 0010 - e4 8b a6 14 6d 69 ce ef-24 5b dc 49 2e 10 d3 6d ....mi..$[.I...m 0020 - 21 b6 cd 03 50 6d fa 5e-70 6e 7b bd ad a4 ae 58 !...Pm.^pn{....X 0030 - 42 4a 99 4d 5a 31 4c 0b-a8 2a 65 6f 37 85 b7 a3 BJ.MZ1L..*eo7... 0040 - 40 50 75 da bc 08 20 b1-6d b4 a1 f4 59 d1 56 29 @Pu... .m...Y.V) 0050 - 5c ea e5 4e aa ee 9c b1-7e 48 0f 88 4a d3 06 c4 \..N....~H..J... 0060 - 21 2f 40 b0 49 ce 93 b1-b8 b6 be e0 33 af 86 08 !/@.I.......3... 0070 - 64 f9 71 1b 8c 15 8e ed-87 9f 94 26 cc d7 a1 1e d.q........&.... 0080 - 27 ed 18 5c a0 f0 ae 6d-6f ad '..\...mo. Start Time: 1732171114 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes ---
#
OCSP response of
kepura.com
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.