Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://thisisyr.com
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=thisisyr.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=thisisyr.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=thisisyr.com
And you can
check your domain name
.
#
Certificate of
thisisyr.com
{ "serial": "B9302A072F0489250ED42B499E2CE33D", "OCSP_serial": "B9302A072F0489250ED42B499E2CE33D", "OCSP_cert_status": "good", "OCSP_this_update": "Nov 21 00:16:07 2024 GMT", "OCSP_next_update": "Nov 27 23:16:06 2024 GMT", "domainName": "thisisyr.com", "port": 443, "subjectAltName": "DNS:thisisyr.com, DNS:*.thisisyr.com", "is_valid": true, "CA": "Google Trust Services", "updated_at": "2024/10/27 05:11:02", "expires_at": "2025/01/25 05:11:01", "today": "2024/11/21 15:59:30", "UTC": { "updated_at": "2024-10-26T20:11:02Z", "expires_at": "2025-01-24T20:11:01Z", "today": "2024-11-21T06:59:30Z" }, "remaining_days": 64 }
#
OCSP response of
thisisyr.com
from OCSP Stapling
CONNECTED(00000003) OCSP response: ====================================== OCSP Response Data: OCSP Response Status: successful (0x0) Response Type: Basic OCSP Response Version: 1 (0x0) Responder Id: 9077923567C4FFA8CCA9E67BD980797BCC93F938 Produced At: Nov 21 00:16:07 2024 GMT Responses: Certificate ID: Hash Algorithm: sha1 Issuer Name Hash: B9BED5F1A61E40B24196B0C29E7E1A9D8BFCB520 Issuer Key Hash: 9077923567C4FFA8CCA9E67BD980797BCC93F938 Serial Number: B9302A072F0489250ED42B499E2CE33D Cert Status: good This Update: Nov 21 00:16:07 2024 GMT Next Update: Nov 27 23:16:06 2024 GMT Signature Algorithm: ecdsa-with-SHA256 Signature Value: 30:44:02:20:1a:7f:15:16:78:ab:1b:92:63:8e:15:9d:14:de: 26:f1:7a:c6:b3:bc:e6:31:44:eb:ec:e4:c6:80:91:85:0e:a0: 02:20:30:a6:f1:c1:90:41:da:04:36:f5:2a:78:c7:29:8d:24: 8d:17:f3:ab:75:2f:7b:2a:62:1b:f7:07:cf:72:a1:dd ====================================== --- Certificate chain 0 s:CN = thisisyr.com i:C = US, O = Google Trust Services, CN = WE1 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: ecdsa-with-SHA256 v:NotBefore: Oct 26 20:11:02 2024 GMT; NotAfter: Jan 24 20:11:01 2025 GMT 1 s:C = US, O = Google Trust Services, CN = WE1 i:C = US, O = Google Trust Services LLC, CN = GTS Root R4 a:PKEY: id-ecPublicKey, 256 (bit); sigalg: ecdsa-with-SHA384 v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT 2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R4 i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA a:PKEY: id-ecPublicKey, 384 (bit); sigalg: RSA-SHA256 v:NotBefore: Nov 15 03:43:21 2023 GMT; NotAfter: Jan 28 00:00:42 2028 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIDqDCCA06gAwIBAgIRALkwKgcvBIklDtQrSZ4s4z0wCgYIKoZIzj0EAwIwOzEL MAkGA1UEBhMCVVMxHjAcBgNVBAoTFUdvb2dsZSBUcnVzdCBTZXJ2aWNlczEMMAoG A1UEAxMDV0UxMB4XDTI0MTAyNjIwMTEwMloXDTI1MDEyNDIwMTEwMVowFzEVMBMG A1UEAxMMdGhpc2lzeXIuY29tMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEwLcs q+UrCw7RksudmZf++TCN1Ll5hUMmZ20QbgdHi7D2FNHjzvFDJqm1usvPQxAjECPy MzA32J4rsV+y7nqQZ6OCAlUwggJRMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAK BggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBTCR3BilGVffCQ5NELY WuIxZW3lPTAfBgNVHSMEGDAWgBSQd5I1Z8T/qMyp5nvZgHl7zJP5ODBeBggrBgEF BQcBAQRSMFAwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vLnBraS5nb29nL3Mvd2UxL3VU QTAlBggrBgEFBQcwAoYZaHR0cDovL2kucGtpLmdvb2cvd2UxLmNydDAnBgNVHREE IDAeggx0aGlzaXN5ci5jb22CDioudGhpc2lzeXIuY29tMBMGA1UdIAQMMAowCAYG Z4EMAQIBMDYGA1UdHwQvMC0wK6ApoCeGJWh0dHA6Ly9jLnBraS5nb29nL3dlMS9j OWVnWTlpa1BzVS5jcmwwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdgDm0jFjQHeM wRBBBtdxuc7B0kD2loSG+7qHMh39HjeOUAAAAZLKqxZoAAAEAwBHMEUCIQD+KpcL 42VCUf8e3dhbmL7h99dWcTPxBcwNaSdy55u6ngIgUWDv0RjeLSm5FY63fO4ZW014 ODpohjc4ZYYj/YmG/gIAdgDPEVbu1S58r/OHW9lpLpvpGnFnSrAX7KwB0lt3zsw7 CAAAAZLKqxaDAAAEAwBHMEUCIAK5mq74fDHkfnayDyTQmyQLiTkATNMa0LswN7P0 BHcaAiEA3PzZDZe85mxG2XYUbQLdxxt83r4T/Mbq4A48NZ7qaFQwCgYIKoZIzj0E AwIDSAAwRQIgEweVSOvxPuC7S4iE7in7YKo9flGsrPuwGIU0/hk9XEECIQDeEGOx HchUcclvSwCKZwEzLGOIGtWS8O4rOpRk0TMJbQ== -----END CERTIFICATE----- subject=CN = thisisyr.com issuer=C = US, O = Google Trust Services, CN = WE1 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: ECDSA Server Temp Key: X25519, 253 bits --- SSL handshake has read 3116 bytes and written 403 bytes Verification: OK --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 256 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
#
OCSP response of
thisisyr.com
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.