Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://kfs.kazusa.or.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=kfs.kazusa.or.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=kfs.kazusa.or.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=kfs.kazusa.or.jp
And you can
check your domain name
.
#
Certificate of
kfs.kazusa.or.jp
{ "serial": "05F197668E0A92A042A80F499EF15C28", "OCSP_serial": null, "OCSP_cert_status": null, "OCSP_this_update": null, "OCSP_next_update": null, "domainName": "kfs.kazusa.or.jp", "port": 443, "subjectAltName": "DNS:*.kazusa.or.jp", "is_valid": true, "CA": "DigiCert Inc", "updated_at": "2024/04/22 09:00:00", "expires_at": "2025/05/24 08:59:59", "today": "2024/11/21 16:09:48", "UTC": { "updated_at": "2024-04-22T00:00:00Z", "expires_at": "2025-05-23T23:59:59Z", "today": "2024-11-21T07:09:48Z" }, "remaining_days": 183 }
#
OCSP response of
kfs.kazusa.or.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:C = JP, ST = Chiba, L = Kisarazu, O = Kazusa DNA Research Institute, CN = *.kazusa.or.jp i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = GeoTrust TLS RSA CA G1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Apr 22 00:00:00 2024 GMT; NotAfter: May 23 23:59:59 2025 GMT 1 s:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = GeoTrust TLS RSA CA G1 i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Nov 2 12:23:37 2017 GMT; NotAfter: Nov 2 12:23:37 2027 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIGdDCCBVygAwIBAgIQBfGXZo4KkqBCqA9JnvFcKDANBgkqhkiG9w0BAQsFADBg MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 d3cuZGlnaWNlcnQuY29tMR8wHQYDVQQDExZHZW9UcnVzdCBUTFMgUlNBIENBIEcx MB4XDTI0MDQyMjAwMDAwMFoXDTI1MDUyMzIzNTk1OVowcTELMAkGA1UEBhMCSlAx DjAMBgNVBAgTBUNoaWJhMREwDwYDVQQHEwhLaXNhcmF6dTEmMCQGA1UEChMdS2F6 dXNhIEROQSBSZXNlYXJjaCBJbnN0aXR1dGUxFzAVBgNVBAMMDioua2F6dXNhLm9y LmpwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArgUoA+oKn7wLv8kZ xViR05tReXt+4w97ACiB3PVw9ifZB9n4S0lLZ1It+LT7npBZEOTT/+0gSuiZq2Z1 mDXDcpsdGULi2IbMbswemp8FHIOj9zqmxgXgvAmNx5c2t/TbiAYfWP2A10CbASHr Z6ebniXQaZb5PBFKXPS9Nve7ftdiIJFf18Ks1FrELZ7YXdFad5RF1ZlhvAnoEpyO ToUh8iLTAYHI7+BTB1iGWw9yxDYZu2tFw/TX30CVR33UO+uUt2lZztKUh8Ib3E09 fQoXJHCIY2hG0ivHWFBfFQf2tEcVQbKCSF4tjLML6SARQvRrnFKX04lMzGmp386i 3unxYwIDAQABo4IDFzCCAxMwHwYDVR0jBBgwFoAUlE/UXYvkpOKmgP792PkA76O+ AlcwHQYDVR0OBBYEFEU4ndaC+64z2YRqd/HYCvg44hutMBkGA1UdEQQSMBCCDiou a2F6dXNhLm9yLmpwMD4GA1UdIAQ3MDUwMwYGZ4EMAQICMCkwJwYIKwYBBQUHAgEW G2h0dHA6Ly93d3cuZGlnaWNlcnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCBaAwHQYD VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMD8GA1UdHwQ4MDYwNKAyoDCGLmh0 dHA6Ly9jZHAuZ2VvdHJ1c3QuY29tL0dlb1RydXN0VExTUlNBQ0FHMS5jcmwwdgYI KwYBBQUHAQEEajBoMCYGCCsGAQUFBzABhhpodHRwOi8vc3RhdHVzLmdlb3RydXN0 LmNvbTA+BggrBgEFBQcwAoYyaHR0cDovL2NhY2VydHMuZ2VvdHJ1c3QuY29tL0dl b1RydXN0VExTUlNBQ0FHMS5jcnQwDAYDVR0TAQH/BAIwADCCAX4GCisGAQQB1nkC BAIEggFuBIIBagFoAHYATnWjJ1yaEMM4W2zU3z9S6x3w4I4bjWnAsfpksWKaOd8A AAGPA0lsSwAABAMARzBFAiA2OpOYy9hbK5OLhLzt2ndlCs7dvPMZiG2WmLrvFAHj 0QIhAPDPgT4fFsF4xgOzt4yZiuZJ0RgqHyu/0dTYm1dRTj6lAHYAfVkeEuF4Knsc YWd8Xv340IdcFKBOlZ65Ay/ZDowuebgAAAGPA0lshwAABAMARzBFAiBtmX6JIj2H WDTR2miyfqJOoyLYOv6KCvDgiwe1FdJJzQIhAIL9wE2QaNqvRLJaGECEoIa2/xWX kWqILzL3CGQLi8mGAHYA5tIxY0B3jMEQQQbXcbnOwdJA9paEhvu6hzId/R43jlAA AAGPA0lsngAABAMARzBFAiBlD7PwArttn1FjvaixVun7lwR/h7JKvIMl4kEukK3d CgIhAKrRiezzP/GQBBqmjyB5dpsGrlBZnpeo+q871scGh1ZiMA0GCSqGSIb3DQEB CwUAA4IBAQApwWOAsdMBfg7ljjCFRFx1RUhswFHdffKwExf+7FycM1kt94tFaJMu cPDVb1XFhjCHV55wmjUs7kC0ygG18QiNtLBok85QtDBkdbT1TLLLuvGCAFJg7dzs 3cdOWJ+tFjvKmrMTEc6xcVj3c6eh0OW8vF6AOgv5T3mfnfG7Wq73S6Slo0KJKIqZ e4NSiwE/RB0v3zoNbkvjvcydkengcMJOGLh9eCqmSRJRqPSxfQJ9qx9TsQLz93yb dfWvn/W2PIBAui1OapOQixUo6NhcbKemLtPOBc6+aL1fCrftxYdH3rGfYfptWRgk Q08Wtx2kJpECCF71kqPnl46gUCgQ54n1 -----END CERTIFICATE----- subject=C = JP, ST = Chiba, L = Kisarazu, O = Kazusa DNA Research Institute, CN = *.kazusa.or.jp issuer=C = US, O = DigiCert Inc, OU = www.digicert.com, CN = GeoTrust TLS RSA CA G1 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 3362 bytes and written 407 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
kfs.kazusa.or.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.