Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://ltta.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=ltta.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=ltta.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=ltta.jp
And you can
check your domain name
.
#
Certificate of
ltta.jp
{ "serial": "0DD60789FBCA7011BFC951E7AE69C1CD", "OCSP_serial": "0DD60789FBCA7011BFC951E7AE69C1CD", "OCSP_cert_status": "good", "OCSP_this_update": "Nov 21 03:15:02 2024 GMT", "OCSP_next_update": "Nov 28 02:15:02 2024 GMT", "domainName": "ltta.jp", "port": 443, "subjectAltName": "DNS:ltta.jp, DNS:fukui.ltta.jp, DNS:fukushima.ltta.jp, DNS:tochigi.ltta.jp, DNS:kyoto.ltta.jp", "is_valid": true, "CA": "Amazon", "updated_at": "2024/06/01 09:00:00", "expires_at": "2025/07/01 08:59:59", "today": "2024/11/21 15:31:27", "UTC": { "updated_at": "2024-06-01T00:00:00Z", "expires_at": "2025-06-30T23:59:59Z", "today": "2024-11-21T06:31:27Z" }, "remaining_days": 221 }
#
OCSP response of
ltta.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: 55D9185FD21CCC01E158B4BEABD9554201D72E02 Produced At: Nov 20 03:30:51 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: 2A1C8FAC7666A96B042770BD6BA4211967C81348 Issuer Key Hash: 55D9185FD21CCC01E158B4BEABD9554201D72E02 Serial Number: 0DD60789FBCA7011BFC951E7AE69C1CD Cert Status: good This Update: Nov 20 03:15:02 2024 GMT Next Update: Nov 27 02:15:02 2024 GMT Signature Algorithm: sha256WithRSAEncryption Signature Value: b0:a2:3f:e8:8a:6f:49:34:5d:9b:1e:8a:9c:d4:21:7d:77:25: b7:78:7f:1a:36:57:55:cb:cb:ca:2f:7d:08:86:52:f1:b3:b4: ef:84:b5:f9:ba:29:3b:d2:69:00:86:df:57:73:83:a1:6a:6b: 2c:eb:02:8d:f5:06:df:0d:3e:0f:49:b7:97:dd:ea:59:db:07: c3:8b:01:b9:be:5d:1b:40:bd:77:a2:ad:49:63:86:20:64:81: 2f:32:b3:14:2e:41:d9:f4:dc:68:a9:66:52:52:ed:82:4e:fb: 4b:cc:06:62:ae:c8:db:78:47:76:f1:f8:85:ac:9b:c5:41:51: 28:60:75:d8:22:f6:6b:52:72:64:2b:d9:c0:ce:9f:72:a7:1c: a4:f8:7b:7f:a5:0f:d5:a3:88:fb:0f:06:dc:fa:3d:b0:86:8c: 2a:fc:4b:ee:bc:2d:7c:92:2e:22:ba:69:27:ed:37:dd:e2:8b: 1b:20:9f:b3:66:08:7d:cc:ee:82:a5:c0:2a:34:4d:18:e7:6a: 92:9c:37:05:63:3f:83:af:32:e4:ec:97:fc:41:18:16:04:f9: 1e:a8:54:89:7a:f4:06:1e:b6:c5:d7:28:be:62:f8:3a:e7:ff: b0:92:05:e3:fe:b8:8d:2b:9e:6e:f4:fd:85:0a:00:7c:5d:b0: c7:bb:fa:61 ====================================== --- Certificate chain 0 s:CN = ltta.jp i:C = US, O = Amazon, CN = Amazon RSA 2048 M03 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Jun 1 00:00:00 2024 GMT; NotAfter: Jun 30 23:59:59 2025 GMT 1 s:C = US, O = Amazon, CN = Amazon RSA 2048 M03 i:C = US, O = Amazon, CN = Amazon Root CA 1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Aug 23 22:26:04 2022 GMT; NotAfter: Aug 23 22:26:04 2030 GMT 2 s:C = US, O = Amazon, CN = Amazon Root CA 1 i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: May 25 12:00:00 2015 GMT; NotAfter: Dec 31 01:00:00 2037 GMT 3 s:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 i:C = US, O = "Starfield Technologies, Inc.", OU = Starfield Class 2 Certification Authority a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Sep 2 00:00:00 2009 GMT; NotAfter: Jun 28 17:39:16 2034 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIF/DCCBOSgAwIBAgIQDdYHifvKcBG/yVHnrmnBzTANBgkqhkiG9w0BAQsFADA8 MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRwwGgYDVQQDExNBbWF6b24g UlNBIDIwNDggTTAzMB4XDTI0MDYwMTAwMDAwMFoXDTI1MDYzMDIzNTk1OVowEjEQ MA4GA1UEAxMHbHR0YS5qcDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB AMh84xdlx1lUNJmNQ85fkmli+BlU5/oorsYmfOxQEX3aE51EFS+38ssrinmpsB2u GkZ21TbnJt5MFor6S43IyjyWTZfPLLbo1zLXaZhBrOfrOmRD0fvmb0sfICVfljUN R6q1oOZir3q4ki8iiXqHVA+jtRLAYwhyq8C6fht8bzCggcKvXbDyE38B/CiDerkW UH/RcK7ecRNpq0peYAdWuRCH28h7wuIMhQZ5+Dbb+MVyYdqYuR1UzseS0np7XOfr kaHIlWWDa7liI6uIBFDtjk3dkWpSNvPLHSHKxYcIBg4TXIeDoIndWWQXIuM/UdgY DEomFNMjJM/AKJeSaI4pyT0CAwEAAaOCAyIwggMeMB8GA1UdIwQYMBaAFFXZGF/S HMwB4Vi0vqvZVUIB1y4CMB0GA1UdDgQWBBS+Dili08K+as+c8dChdEBaNL078TBU BgNVHREETTBLggdsdHRhLmpwgg1mdWt1aS5sdHRhLmpwghFmdWt1c2hpbWEubHR0 YS5qcIIPdG9jaGlnaS5sdHRhLmpwgg1reW90by5sdHRhLmpwMBMGA1UdIAQMMAow CAYGZ4EMAQIBMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYI KwYBBQUHAwIwOwYDVR0fBDQwMjAwoC6gLIYqaHR0cDovL2NybC5yMm0wMy5hbWF6 b250cnVzdC5jb20vcjJtMDMuY3JsMHUGCCsGAQUFBwEBBGkwZzAtBggrBgEFBQcw AYYhaHR0cDovL29jc3AucjJtMDMuYW1hem9udHJ1c3QuY29tMDYGCCsGAQUFBzAC hipodHRwOi8vY3J0LnIybTAzLmFtYXpvbnRydXN0LmNvbS9yMm0wMy5jZXIwDAYD VR0TAQH/BAIwADCCAX4GCisGAQQB1nkCBAIEggFuBIIBagFoAHYAzxFW7tUufK/z h1vZaS6b6RpxZ0qwF+ysAdJbd87MOwgAAAGP0m2qrQAABAMARzBFAiA3vzpj8yx7 fT4WwvWdRtzrL842Ou/0H36UrYiPf43EigIhAOOfDQSRxz1aD51zbKZIYuARLrTF fy/Mj3DCBGgGHdr+AHcAfVkeEuF4KnscYWd8Xv340IdcFKBOlZ65Ay/ZDowuebgA AAGP0m2qcgAABAMASDBGAiEArKMiYddiiaTyYBLm8IzVXjjgfk4KvLez6s4Ot5w/ kFoCIQDh30WljEBZlJHzcxaj9WSXTBp5A0vfRnDuB8VRo8KGMQB1AObSMWNAd4zB EEEG13G5zsHSQPaWhIb7uocyHf0eN45QAAABj9JtqpoAAAQDAEYwRAIgYYNk5s7/ OblJvlspY1chdIulqiN9l2Qz4L0rxcuDdsgCIFS68Ziuv6TqxD4BqVcCH4//HeaF sYBE4qptYPGAUv6LMA0GCSqGSIb3DQEBCwUAA4IBAQBVOG5Y71kY4p9OV5Acbmda fAqqdjONHgXJBNOyl3bMgnYWFTYB/beAxydmxEpjxfAOYOknbFnmQKmgjy34Dwvy JGxR0rzCpPMxXDbgC3E/ZZD8dC4aBG4E3PEoE5f0QSR/DEWwjHjdRHAuAU5BXM2N aK98Rbcod6XZGnCBxYqTRgFj/8yn+YMYfLZmVchsNemMaZwiyfPfSAQinWhx+p3X 7fkBnOcCYzoOqH6sePxELB8ycMwL+0I2ipWYTJBezToeJkqgDbrCJ1Jzx1LivNzG jsplPq+8AxDs26evIKVjkx43Xd/2au6sXbpmbfnosW5nd3w0ooGCm5EYd9M0HYa7 -----END CERTIFICATE----- subject=CN = ltta.jp issuer=C = US, O = Amazon, CN = Amazon RSA 2048 M03 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 6015 bytes and written 382 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
ltta.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.