Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://www.b-merit.jp
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=www.b-merit.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=www.b-merit.jp
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=www.b-merit.jp
And you can
check your domain name
.
#
Certificate of
www.b-merit.jp
{ "serial": "03D049B7B03F80EE1D792C5573A8F57B", "OCSP_serial": null, "OCSP_cert_status": null, "OCSP_this_update": null, "OCSP_next_update": null, "domainName": "www.b-merit.jp", "port": 443, "subjectAltName": "DNS:www.b-merit.jp", "is_valid": true, "CA": "Amazon", "updated_at": "2023/12/04 09:00:00", "expires_at": "2025/01/03 08:59:59", "today": "2024/04/28 15:38:10", "UTC": { "updated_at": "2023-12-04T00:00:00Z", "expires_at": "2025-01-02T23:59:59Z", "today": "2024-04-28T06:38:10Z" }, "remaining_days": 249 }
#
OCSP response of
www.b-merit.jp
from OCSP Stapling
CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:CN = www.b-merit.jp i:C = US, O = Amazon, CN = Amazon RSA 2048 M03 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Dec 4 00:00:00 2023 GMT; NotAfter: Jan 2 23:59:59 2025 GMT 1 s:C = US, O = Amazon, CN = Amazon RSA 2048 M03 i:C = US, O = Amazon, CN = Amazon Root CA 1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Aug 23 22:26:04 2022 GMT; NotAfter: Aug 23 22:26:04 2030 GMT 2 s:C = US, O = Amazon, CN = Amazon Root CA 1 i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: May 25 12:00:00 2015 GMT; NotAfter: Dec 31 01:00:00 2037 GMT 3 s:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 i:C = US, O = "Starfield Technologies, Inc.", OU = Starfield Class 2 Certification Authority a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Sep 2 00:00:00 2009 GMT; NotAfter: Jun 28 17:39:16 2034 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIFyTCCBLGgAwIBAgIQA9BJt7A/gO4deSxVc6j1ezANBgkqhkiG9w0BAQsFADA8 MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRwwGgYDVQQDExNBbWF6b24g UlNBIDIwNDggTTAzMB4XDTIzMTIwNDAwMDAwMFoXDTI1MDEwMjIzNTk1OVowGTEX MBUGA1UEAxMOd3d3LmItbWVyaXQuanAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw ggEKAoIBAQC/duaB5+PAWnuCBT5kIhFXTa28BLgmOCZ6HW5edMHvZZZE1czBhNdg qXty2CRwEBE7U3gWKEMxPAUYeHnNv4WiVyK7FTrb5mc8Cl0iqvthrArBK0ca2t1S eZZVQ2Dizb7DkEA2BCnudrwaVHQI/Nj1azRZaubBnfAiQN28fz8AqUZsGSdWg4Cn 7GMfqfXqnBFZGE79x/H8IUTusOVfijMTnaXxRbs+uD+VVWpKAHIELjj8m5zEWt0P 0Rj1LSHgLn90BXz7SNQfO2ts9NBOD3/VOjWEfaHCkpt+lvJM0DFZkPsThbq9f8zz PHJXXol/3E+344+eIzHmdJ7vt+aQ4qMzAgMBAAGjggLoMIIC5DAfBgNVHSMEGDAW gBRV2Rhf0hzMAeFYtL6r2VVCAdcuAjAdBgNVHQ4EFgQUfF+nKz1TiGIGn7baQ+ZY kG26/t0wGQYDVR0RBBIwEIIOd3d3LmItbWVyaXQuanAwEwYDVR0gBAwwCjAIBgZn gQwBAgEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF BQcDAjA7BgNVHR8ENDAyMDCgLqAshipodHRwOi8vY3JsLnIybTAzLmFtYXpvbnRy dXN0LmNvbS9yMm0wMy5jcmwwdQYIKwYBBQUHAQEEaTBnMC0GCCsGAQUFBzABhiFo dHRwOi8vb2NzcC5yMm0wMy5hbWF6b250cnVzdC5jb20wNgYIKwYBBQUHMAKGKmh0 dHA6Ly9jcnQucjJtMDMuYW1hem9udHJ1c3QuY29tL3IybTAzLmNlcjAMBgNVHRMB Af8EAjAAMIIBfwYKKwYBBAHWeQIEAgSCAW8EggFrAWkAdwDPEVbu1S58r/OHW9lp LpvpGnFnSrAX7KwB0lt3zsw7CAAAAYwyPmg5AAAEAwBIMEYCIQDcBHRw7itOj9fM X0qUEE2WqIlnWLtYbGrU3x4hDXWzzAIhANKK4B1wODKz0xFRrt3fnVyX6qUPrnXG /VZ9wpIBjOTKAHYAPxdLT9ciR1iUHWUchL4NEu2QN38fhWrrwb8ohez4ZG4AAAGM Mj5oWQAABAMARzBFAiAcRnNHcRBKJTuWCY/FneutFjtk7n6P4SMCbYi28RXVGAIh AICPLWAiCP9JudU4o7e3Y6eOMYBqOUluP7bAbFCWPiKVAHYAfVkeEuF4KnscYWd8 Xv340IdcFKBOlZ65Ay/ZDowuebgAAAGMMj5oRAAABAMARzBFAiAq5sPL4KDDoKD5 aMQkkIF0gzo9WzykKKv0e2e39/NKygIhAIwfC7nwB2fvglURdcNUDqGA/3D3VDNL 2FAxV+EpNA+IMA0GCSqGSIb3DQEBCwUAA4IBAQBdQNfo6wyCdGTPQ4s6dJxVf0JM xJclv7q4JWmrWRSVpp8gbfGO5/DPz1MvtZLUrTZqZyDLn0hZu6vDaGSf8adVWng4 LTeBH/002G71HvZX+JWRswH5nlsYLbr60/CZI1fmzYhKiemeWE9TMkUaOGIDZ1j4 Nu4fqQw1QR/yBgMwZR/MZ8f+l3/73IxO3IffUGv1FchOVYe75S6ftY1BL+kEpb++ Sdjo2S4vo8WN51VXy0r94aF3xRJ88cvar26Cd/3YLiqcApcpMKtHmaISSocDK7ld 3/odK3AepsLLj0yyIbp+IT4lbKUeN+KIH1aEAPrJsspRNqu/Vu6uG/bxj40j -----END CERTIFICATE----- subject=CN = www.b-merit.jp issuer=C = US, O = Amazon, CN = Amazon RSA 2048 M03 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA Server Temp Key: ECDH, prime256v1, 256 bits --- SSL handshake has read 5572 bytes and written 451 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 Session-ID: 91091B85B92B4FEA4561BDB19E05F6710B11C77F30F6C322C78691C1E5D049D0 Session-ID-ctx: Master-Key: 391A77E926DBCEACB9D82ACB0307D9ED63C09141B50FF05C3BA5D50D9CD07E63E77ACE43E68629FEEDE51E814983B2D6 PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 86400 (seconds) TLS session ticket: 0000 - 16 e9 18 11 c0 e6 87 77-5d 80 c6 b9 e2 3d aa ab .......w]....=.. 0010 - e8 34 32 82 f8 1f d7 82-29 99 14 88 1a 8c 36 76 .42.....).....6v 0020 - 67 43 d6 d7 42 5b e1 f8-72 d0 ac af e7 62 af 44 gC..B[..r....b.D 0030 - d2 03 e5 b9 38 54 77 40-40 d9 d8 32 99 75 9e 09 ....8Tw@@..2.u.. 0040 - 37 cc 43 f7 f3 df 85 35-3e e5 9e 7f 51 f5 f4 13 7.C....5>...Q... 0050 - 55 e8 28 88 13 6b 4f f7-d1 54 c2 9a c9 e8 36 2c U.(..kO..T....6, 0060 - 05 49 30 12 f1 17 60 c9-da .I0...`.. Start Time: 1714286291 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes ---
#
OCSP response of
www.b-merit.jp
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.