Welcome to OCSP Checker.
Author: coeurl (
@debiru_R
)
This is test page for
OCSP Stapling Test
.
Test URL:
https://www.kepura.com
Each APIs:
https://ssl.lavoscore.org/api/sslcert-expires/?q=www.kepura.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp-stapling/?q=www.kepura.com
https://ssl.lavoscore.org/api/sslcert-expires/ocsp/?q=www.kepura.com
And you can
check your domain name
.
#
Certificate of
www.kepura.com
{ "serial": "025F3F5D1C3CAC7FDCF709845153FC15", "OCSP_serial": null, "OCSP_cert_status": null, "OCSP_this_update": null, "OCSP_next_update": null, "domainName": "www.kepura.com", "port": 443, "subjectAltName": "DNS:*.kepura.com, DNS:kepura.com", "is_valid": true, "CA": "Amazon", "updated_at": "2025/03/14 09:00:00", "expires_at": "2026/04/14 08:59:59", "today": "2025/11/03 14:14:07", "UTC": { "updated_at": "2025-03-14T00:00:00Z", "expires_at": "2026-04-13T23:59:59Z", "today": "2025-11-03T05:14:07Z" }, "remaining_days": 161 }
#
OCSP response of
www.kepura.com
from OCSP Stapling
CONNECTED(00000003) OCSP response: no response sent --- Certificate chain 0 s:CN = *.kepura.com i:C = US, O = Amazon, CN = Amazon RSA 2048 M03 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Mar 14 00:00:00 2025 GMT; NotAfter: Apr 13 23:59:59 2026 GMT 1 s:C = US, O = Amazon, CN = Amazon RSA 2048 M03 i:C = US, O = Amazon, CN = Amazon Root CA 1 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Aug 23 22:26:04 2022 GMT; NotAfter: Aug 23 22:26:04 2030 GMT 2 s:C = US, O = Amazon, CN = Amazon Root CA 1 i:C = US, ST = Arizona, L = Scottsdale, O = "Starfield Technologies, Inc.", CN = Starfield Services Root Certificate Authority - G2 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: May 25 12:00:00 2015 GMT; NotAfter: Dec 31 01:00:00 2037 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIFzzCCBLegAwIBAgIQAl8/XRw8rH/c9wmEUVP8FTANBgkqhkiG9w0BAQsFADA8 MQswCQYDVQQGEwJVUzEPMA0GA1UEChMGQW1hem9uMRwwGgYDVQQDExNBbWF6b24g UlNBIDIwNDggTTAzMB4XDTI1MDMxNDAwMDAwMFoXDTI2MDQxMzIzNTk1OVowFzEV MBMGA1UEAwwMKi5rZXB1cmEuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEAsBXDV+HgZLmpQxJY5a8FTvMXWdXRG7t1nwoK4c3kogT9FiZs+SAMfls4 gmVBW0EKKNBMK8AzFXAweufpGM0z8itdgzqqvwTQGMc8ayolSX9aLlt6Nrcror4U fpPHouR3+2PqXQn/I709CHcshqaiyaxoOT398VBoc7fvJEwq+mCyBP6zkqit1Dds nJv/lbxYIOcHxE8nVOsMlKZlPLWMr+abYXkUQzNoYbxfs6tcT2sxFSvbBfPJFk7E iIptFbdI9VopAE/nyShesBLvQR6qXwy8ulvG0HgFSB9LFdd6jR1AYZAzR8K0vzh9 AgAOHMqoVOa9zPjB7g/+QKsKa+HKhQIDAQABo4IC8DCCAuwwHwYDVR0jBBgwFoAU VdkYX9IczAHhWLS+q9lVQgHXLgIwHQYDVR0OBBYEFGZj9eUyoqD391V4zDrDv+wX TM6JMCMGA1UdEQQcMBqCDCoua2VwdXJhLmNvbYIKa2VwdXJhLmNvbTATBgNVHSAE DDAKMAgGBmeBDAECATAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUH AwEGCCsGAQUFBwMCMDsGA1UdHwQ0MDIwMKAuoCyGKmh0dHA6Ly9jcmwucjJtMDMu YW1hem9udHJ1c3QuY29tL3IybTAzLmNybDB1BggrBgEFBQcBAQRpMGcwLQYIKwYB BQUHMAGGIWh0dHA6Ly9vY3NwLnIybTAzLmFtYXpvbnRydXN0LmNvbTA2BggrBgEF BQcwAoYqaHR0cDovL2NydC5yMm0wMy5hbWF6b250cnVzdC5jb20vcjJtMDMuY2Vy MAwGA1UdEwEB/wQCMAAwggF9BgorBgEEAdZ5AgQCBIIBbQSCAWkBZwB2AA5XlLzz rqk+MxssmQez95Dfm8I9cTIl3SGpJaxhxU4hAAABlZIomBwAAAQDAEcwRQIhAPEn 1u5TT73GqvkC7fkEIA4igONhSfj7+XZYK9KrgUqsAiB/QeRpohN+w7CLqZY7+hlu wx3qHSDYCX1h8bu07VLcbwB2AGQRxGykEuyniRyiAi4AvKtPKAfUHjUnq+r+1QPJ fc3wAAABlZIol8kAAAQDAEcwRQIhAK+LeerDcyU2Nl/3BzvDwK3XTJ6j81p2qutX YaBmL/+nAiA23+mTl6Jz4Noh7uMx0Junjfzn2wy0fEgB4iOxIcLCiwB1AEmcm2ne HXzs/DbezYdkprhbrwqHgBnRVVL76esp3fjDAAABlZIol9IAAAQDAEYwRAIgJZfO tBKPPrap8Pw/TcnUJu6e1pRleZrr8L0ICWY4fqwCIBMJEiz/6usPHmrO9wjr9bc4 +4c50U2Joho4eP/8zXbIMA0GCSqGSIb3DQEBCwUAA4IBAQCjqZvsqaE+aFqco+Ws UWy/M3pgUsujIp0/T+gmvQ9P/talrhQZRuYGwVjw/PUODhsmJ9o3lvizouVHxfu0 u9ZqVUlERY9Pj/6tPi4sQ1JSS6zYZxhynjDtDcY1V4oV2NLVPUaGEwY2Zlttue5C b/Qop/vq6tjKYMfEs+tnnhPd9bM6s0U7igWw3PN9U2xQzATVxRbLYKblQJMi/01b Zpe7+LLD82ivUpDsgYmfRqIlxqzQSSO08mWNiV1VVKF02/wNNWB1iX4YlAIupDIf w0W81bB5F3ea4eRnszCocWyKLhPJD9JFZIxkUM/l7Km7pufAvifWqUHp7RQTXVeD RRM4 -----END CERTIFICATE----- subject=CN = *.kepura.com issuer=C = US, O = Amazon, CN = Amazon RSA 2048 M03 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA Server Temp Key: ECDH, prime256v1, 256 bits --- SSL handshake has read 4463 bytes and written 451 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 Session-ID: F0EEAA2A06E73126B5F9C67C6C59A1AA8965D23261FD26D55FBD95EC82EA5AC1 Session-ID-ctx: Master-Key: 09FA444FB310FFC47DDB3EFE1D5B6CAC40EFB98378DE468DFA35704B58377331E8E07CD1381A0DA3861331EFC1DC685B PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 58852 (seconds) TLS session ticket: 0000 - 01 08 c4 1c 41 9c 25 fe-eb ac e9 40 24 fb 05 34 ....A.%....@$..4 0010 - 8f 21 6e ac 5d 80 c6 71-a9 75 cc 1f 5b ad 82 fc .!n.]..q.u..[... 0020 - 4e 5c 4d 71 d4 99 6a 1d-3c 15 42 6d 03 36 8e 07 N\Mq..j.<.Bm.6.. 0030 - aa 3a da c8 2a 2b 95 d9-55 12 1c bd df 30 6f de .:..*+..U....0o. 0040 - 06 cf b4 ba 23 84 ac 98-25 3c 60 74 9a 7e 7d 79 ....#...%<`t.~}y 0050 - dd 5b b1 f5 46 fa 1f bb-48 f7 06 db 41 6d fc dd .[..F...H...Am.. 0060 - 4c 75 63 14 c3 c3 c1 4f-a5 1f e8 75 23 94 38 e8 Luc....O...u#.8. 0070 - be a2 25 ef 67 25 2a 36-c8 e1 4c a1 25 c8 e1 6b ..%.g%*6..L.%..k 0080 - 66 62 f1 19 b3 58 64 2e-72 be fb...Xd.r. Start Time: 1762146848 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes ---
#
OCSP response of
www.kepura.com
from OCSP responder (Let's Encrypt)
OCSP response from OCSP responder allows only Let's Encrypt's Certificate.