CRL & OCSP report for 0-hosting.eu - immotherm.de

immotherm.de

This certificate was cached at
Certificate details for immotherm.de (At position 0 in certificate chain)
Serial number:
hex: 40c26e884f4077c7b615c02ded28e754
int: 86080139185404128723450848310748309332
Issued by: StartCom Class 1 DV Server CA
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Country: DE
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

View complete certificate details for 0-hosting.eu.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/sca-server1.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/sca-server1.crl
Size: 35998 bytes (DER data)
Response time: 258.792045ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 1014

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4.2-19368535) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [48798]
Content-Type: [application/pkix-crl]
Date: [Fri, 17 Feb 2017 16:45:48 GMT]
Last-Modified: [Fri, 17 Feb 2017 13:19:07 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4.2-19368535) (-)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL should be in DER format but is PEM encoded
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com (POST)
Size: 1816 bytes (DER data)
Response time: 218.839314ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 DV Server CA OCSP Responder
Issued by: StartCom Class 1 DV Server CA
Signing certificate validity: 2016-12-10 - 2017-03-30
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-88-138.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FO
AcSwv/jIZ5NEnOcz+q2TDK8CEEDCbohPQHfHthXALe0o51Q=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHFAoBAKCCBw0wggcJBgkrBgEFBQcwAQEEggb6MIIG9jCCAROhgYowgYcxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSkwJwYDVQQLDCBTdGFy
dENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE1MDMGA1UEAwwsU3RhcnRDb20g
Q2xhc3MgMSBEViBTZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIYDzIwMTcwMjE5MTAy
NjMwWjBzMHEwSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FO
AcSwv/jIZ5NEnOcz+q2TDK8CEEDCbohPQHfHthXALe0o51SAABgPMjAxNzAyMTkx
MDI2MzBaoBEYDzIwMTcwMjIzMTAzNjMwWjANBgkqhkiG9w0BAQsFAAOCAQEAPTpj
x9JoxKGPwYRkcD+9a7tWbUWcPM443tMZ8CWtmLAx4zXdetbYrrcdeB4wT0vtL0+K
lvGseMlabjjr/AVX6wN+kFOBGbP8OATLewdCRIUBOQEHP+XX4ToqxbxUDFMKIVHR
5iFqPsBUVQN4iqdVH52ql0R3JwcnmFXzYoisgMtqsT8QRe9UGjw4p2JaiMbsw9sX
yzrr3m3xaUaxdOGC/c35CO3zQjVOvA+AWNkzB4pEgJOt4aoOhaBAN9vj+dVn38rT
CgYeG1pY0Y8fCocasybMAw0S6Qz6SzwQFYmSKiVD6u+5opd7I8LpgHFHKsQ714WQ
RX1VBLrCKZSB7Bi6EqCCBMcwggTDMIIEvzCCA6egAwIBAgIQVKueA9VfZkHR3Afu
yXYb3TANBgkqhkiG9w0BAQsFADB4MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjEpMCcGA1UECxMgU3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHkxJjAkBgNVBAMTHVN0YXJ0Q29tIENsYXNzIDEgRFYgU2VydmVyIENBMB4X
DTE2MTIxMDAzNDQzMVoXDTE3MDMzMDAzNDQzMVowgYcxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSkwJwYDVQQLDCBTdGFydENvbSBDZXJ0aWZp
Y2F0aW9uIEF1dGhvcml0eTE1MDMGA1UEAwwsU3RhcnRDb20gQ2xhc3MgMSBEViBT
ZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDsWdnWSrg/VpeaRuJygc4sGjrPpnt7b0CzTwKWmK0kYkPu3YlzNyEI
HEqjaJK1VJP10WpZ/xW5/VYXoWOPXCSHKHG9e0+ci0zjCXUGWDg5VcHXFo17uksN
P32qlSwo71OnPkY8YF0AYI6h2XlKkPq9H7qtwTKidquHhCaoIj485WbvypGTGf+N
Q0sGqh3E433Ya7s47owOW/j3mwhSZ+d0hNR4mAfrepSn6PEo/o8/3YY5eFSF9lqz
XHx9exbzyMDp+gSWPrqltvbQhLOf4WGlMv5HpCeHkGj6FBmvIUkP6o79ljqMLjwZ
DWj5CPM1GEgkH1waPlBJH97atfBKWbWFAgMBAAGjggEzMIIBLzAOBgNVHQ8BAf8E
BAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNV
HRMBAf8EAjAAMB0GA1UdDgQWBBRv97wRaU9N66S5OrcF+lPg7d+nVDAfBgNVHSME
GDAWgBTXkU4BxLC/+Mhnk0Sc5zP6rZMMrzBvBggrBgEFBQcBAQRjMGEwJAYIKwYB
BQUHMAGGGGh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbTA5BggrBgEFBQcwAoYtaHR0
cDovL2FpYS5zdGFydHNzbC5jb20vY2VydHMvc2NhLnNlcnZlcjEuY3J0MDgGA1Ud
HwQxMC8wLaAroCmGJ2h0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3NjYS1zZXJ2ZXIx
LmNybDANBgkqhkiG9w0BAQsFAAOCAQEAIDClr/C1F+Sh/yYNQUVeKzE8wGIc0cby
rM7n7Rs0wBsZJjoIj+IG8Ksk134BurCswxRXqIPy/KgBrLkRSWhZU/+lVcsNAKLj
+bncbZ/n7x8E5oFGLOgKetyGrE3QVIvqWULt/aYQlFY45Wgri3RP/51F9v6WOC0W
raOR5vZJ/BDREslZDEq2IutiuLoWveGlAxwAh2wIDBK99IZLiNITFqze0R8xR1Nn
aF1uwENrXxANOjJ4TtO9321OHHRWAMx8sWvR1Jyna8+uefHrHcNvXpKMXjfcHfAT
vcIeFHl1q7yYyf/BW/QglRMwC9q1l2AHEkX5C70bmxh29EXu9bQyOw==
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIEvzCCA6egAwIBAgIQVKueA9VfZkHR3AfuyXYb3TANBgkqhkiG9w0BAQsFADB4
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjEpMCcGA1UECxMg
U3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxJjAkBgNVBAMTHVN0YXJ0
Q29tIENsYXNzIDEgRFYgU2VydmVyIENBMB4XDTE2MTIxMDAzNDQzMVoXDTE3MDMz
MDAzNDQzMVowgYcxCzAJBgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQu
MSkwJwYDVQQLDCBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE1MDMG
A1UEAwwsU3RhcnRDb20gQ2xhc3MgMSBEViBTZXJ2ZXIgQ0EgT0NTUCBSZXNwb25k
ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDsWdnWSrg/VpeaRuJy
gc4sGjrPpnt7b0CzTwKWmK0kYkPu3YlzNyEIHEqjaJK1VJP10WpZ/xW5/VYXoWOP
XCSHKHG9e0+ci0zjCXUGWDg5VcHXFo17uksNP32qlSwo71OnPkY8YF0AYI6h2XlK
kPq9H7qtwTKidquHhCaoIj485WbvypGTGf+NQ0sGqh3E433Ya7s47owOW/j3mwhS
Z+d0hNR4mAfrepSn6PEo/o8/3YY5eFSF9lqzXHx9exbzyMDp+gSWPrqltvbQhLOf
4WGlMv5HpCeHkGj6FBmvIUkP6o79ljqMLjwZDWj5CPM1GEgkH1waPlBJH97atfBK
WbWFAgMBAAGjggEzMIIBLzAOBgNVHQ8BAf8EBAMCA6gwEwYDVR0lBAwwCgYIKwYB
BQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBRv
97wRaU9N66S5OrcF+lPg7d+nVDAfBgNVHSMEGDAWgBTXkU4BxLC/+Mhnk0Sc5zP6
rZMMrzBvBggrBgEFBQcBAQRjMGEwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLnN0
YXJ0c3NsLmNvbTA5BggrBgEFBQcwAoYtaHR0cDovL2FpYS5zdGFydHNzbC5jb20v
Y2VydHMvc2NhLnNlcnZlcjEuY3J0MDgGA1UdHwQxMC8wLaAroCmGJ2h0dHA6Ly9j
cmwuc3RhcnRzc2wuY29tL3NjYS1zZXJ2ZXIxLmNybDANBgkqhkiG9w0BAQsFAAOC
AQEAIDClr/C1F+Sh/yYNQUVeKzE8wGIc0cbyrM7n7Rs0wBsZJjoIj+IG8Ksk134B
urCswxRXqIPy/KgBrLkRSWhZU/+lVcsNAKLj+bncbZ/n7x8E5oFGLOgKetyGrE3Q
VIvqWULt/aYQlFY45Wgri3RP/51F9v6WOC0WraOR5vZJ/BDREslZDEq2IutiuLoW
veGlAxwAh2wIDBK99IZLiNITFqze0R8xR1NnaF1uwENrXxANOjJ4TtO9321OHHRW
AMx8sWvR1Jyna8+uefHrHcNvXpKMXjfcHfATvcIeFHl1q7yYyf/BW/QglRMwC9q1
l2AHEkX5C70bmxh29EXu9bQyOw==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1816]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 20 Feb 2017 08:29:39 GMT]
Etag: ["14191C0C2CF9FA8F4A1C4144996B81A193A3D48A"]
Expires: [Mon, 20 Feb 2017 08:29:39 GMT]
Last-Modified: [Sun, 19 Feb 2017 10:26:30 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-88-138.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com (GET)
Size: 1816 bytes (DER data)
Response time: 245.569296ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 DV Server CA OCSP Responder
Issued by: StartCom Class 1 DV Server CA
Signing certificate validity: 2016-12-10 - 2017-03-30
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-88-138.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)

URL used for GET request

http:/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FOAcSwv%2FjIZ5NEnOcz%2Bq2TDK8CEEDCbohPQHfHthXALe0o51Q%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FO
AcSwv/jIZ5NEnOcz+q2TDK8CEEDCbohPQHfHthXALe0o51Q=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHFAoBAKCCBw0wggcJBgkrBgEFBQcwAQEEggb6MIIG9jCCAROhgYowgYcxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSkwJwYDVQQLDCBTdGFy
dENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE1MDMGA1UEAwwsU3RhcnRDb20g
Q2xhc3MgMSBEViBTZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIYDzIwMTcwMjE5MTAy
NjMwWjBzMHEwSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FO
AcSwv/jIZ5NEnOcz+q2TDK8CEEDCbohPQHfHthXALe0o51SAABgPMjAxNzAyMTkx
MDI2MzBaoBEYDzIwMTcwMjIzMTAzNjMwWjANBgkqhkiG9w0BAQsFAAOCAQEAPTpj
x9JoxKGPwYRkcD+9a7tWbUWcPM443tMZ8CWtmLAx4zXdetbYrrcdeB4wT0vtL0+K
lvGseMlabjjr/AVX6wN+kFOBGbP8OATLewdCRIUBOQEHP+XX4ToqxbxUDFMKIVHR
5iFqPsBUVQN4iqdVH52ql0R3JwcnmFXzYoisgMtqsT8QRe9UGjw4p2JaiMbsw9sX
yzrr3m3xaUaxdOGC/c35CO3zQjVOvA+AWNkzB4pEgJOt4aoOhaBAN9vj+dVn38rT
CgYeG1pY0Y8fCocasybMAw0S6Qz6SzwQFYmSKiVD6u+5opd7I8LpgHFHKsQ714WQ
RX1VBLrCKZSB7Bi6EqCCBMcwggTDMIIEvzCCA6egAwIBAgIQVKueA9VfZkHR3Afu
yXYb3TANBgkqhkiG9w0BAQsFADB4MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjEpMCcGA1UECxMgU3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHkxJjAkBgNVBAMTHVN0YXJ0Q29tIENsYXNzIDEgRFYgU2VydmVyIENBMB4X
DTE2MTIxMDAzNDQzMVoXDTE3MDMzMDAzNDQzMVowgYcxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSkwJwYDVQQLDCBTdGFydENvbSBDZXJ0aWZp
Y2F0aW9uIEF1dGhvcml0eTE1MDMGA1UEAwwsU3RhcnRDb20gQ2xhc3MgMSBEViBT
ZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDsWdnWSrg/VpeaRuJygc4sGjrPpnt7b0CzTwKWmK0kYkPu3YlzNyEI
HEqjaJK1VJP10WpZ/xW5/VYXoWOPXCSHKHG9e0+ci0zjCXUGWDg5VcHXFo17uksN
P32qlSwo71OnPkY8YF0AYI6h2XlKkPq9H7qtwTKidquHhCaoIj485WbvypGTGf+N
Q0sGqh3E433Ya7s47owOW/j3mwhSZ+d0hNR4mAfrepSn6PEo/o8/3YY5eFSF9lqz
XHx9exbzyMDp+gSWPrqltvbQhLOf4WGlMv5HpCeHkGj6FBmvIUkP6o79ljqMLjwZ
DWj5CPM1GEgkH1waPlBJH97atfBKWbWFAgMBAAGjggEzMIIBLzAOBgNVHQ8BAf8E
BAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNV
HRMBAf8EAjAAMB0GA1UdDgQWBBRv97wRaU9N66S5OrcF+lPg7d+nVDAfBgNVHSME
GDAWgBTXkU4BxLC/+Mhnk0Sc5zP6rZMMrzBvBggrBgEFBQcBAQRjMGEwJAYIKwYB
BQUHMAGGGGh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbTA5BggrBgEFBQcwAoYtaHR0
cDovL2FpYS5zdGFydHNzbC5jb20vY2VydHMvc2NhLnNlcnZlcjEuY3J0MDgGA1Ud
HwQxMC8wLaAroCmGJ2h0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3NjYS1zZXJ2ZXIx
LmNybDANBgkqhkiG9w0BAQsFAAOCAQEAIDClr/C1F+Sh/yYNQUVeKzE8wGIc0cby
rM7n7Rs0wBsZJjoIj+IG8Ksk134BurCswxRXqIPy/KgBrLkRSWhZU/+lVcsNAKLj
+bncbZ/n7x8E5oFGLOgKetyGrE3QVIvqWULt/aYQlFY45Wgri3RP/51F9v6WOC0W
raOR5vZJ/BDREslZDEq2IutiuLoWveGlAxwAh2wIDBK99IZLiNITFqze0R8xR1Nn
aF1uwENrXxANOjJ4TtO9321OHHRWAMx8sWvR1Jyna8+uefHrHcNvXpKMXjfcHfAT
vcIeFHl1q7yYyf/BW/QglRMwC9q1l2AHEkX5C70bmxh29EXu9bQyOw==
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIEvzCCA6egAwIBAgIQVKueA9VfZkHR3AfuyXYb3TANBgkqhkiG9w0BAQsFADB4
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjEpMCcGA1UECxMg
U3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxJjAkBgNVBAMTHVN0YXJ0
Q29tIENsYXNzIDEgRFYgU2VydmVyIENBMB4XDTE2MTIxMDAzNDQzMVoXDTE3MDMz
MDAzNDQzMVowgYcxCzAJBgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQu
MSkwJwYDVQQLDCBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTE1MDMG
A1UEAwwsU3RhcnRDb20gQ2xhc3MgMSBEViBTZXJ2ZXIgQ0EgT0NTUCBSZXNwb25k
ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDsWdnWSrg/VpeaRuJy
gc4sGjrPpnt7b0CzTwKWmK0kYkPu3YlzNyEIHEqjaJK1VJP10WpZ/xW5/VYXoWOP
XCSHKHG9e0+ci0zjCXUGWDg5VcHXFo17uksNP32qlSwo71OnPkY8YF0AYI6h2XlK
kPq9H7qtwTKidquHhCaoIj485WbvypGTGf+NQ0sGqh3E433Ya7s47owOW/j3mwhS
Z+d0hNR4mAfrepSn6PEo/o8/3YY5eFSF9lqzXHx9exbzyMDp+gSWPrqltvbQhLOf
4WGlMv5HpCeHkGj6FBmvIUkP6o79ljqMLjwZDWj5CPM1GEgkH1waPlBJH97atfBK
WbWFAgMBAAGjggEzMIIBLzAOBgNVHQ8BAf8EBAMCA6gwEwYDVR0lBAwwCgYIKwYB
BQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBRv
97wRaU9N66S5OrcF+lPg7d+nVDAfBgNVHSMEGDAWgBTXkU4BxLC/+Mhnk0Sc5zP6
rZMMrzBvBggrBgEFBQcBAQRjMGEwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLnN0
YXJ0c3NsLmNvbTA5BggrBgEFBQcwAoYtaHR0cDovL2FpYS5zdGFydHNzbC5jb20v
Y2VydHMvc2NhLnNlcnZlcjEuY3J0MDgGA1UdHwQxMC8wLaAroCmGJ2h0dHA6Ly9j
cmwuc3RhcnRzc2wuY29tL3NjYS1zZXJ2ZXIxLmNybDANBgkqhkiG9w0BAQsFAAOC
AQEAIDClr/C1F+Sh/yYNQUVeKzE8wGIc0cbyrM7n7Rs0wBsZJjoIj+IG8Ksk134B
urCswxRXqIPy/KgBrLkRSWhZU/+lVcsNAKLj+bncbZ/n7x8E5oFGLOgKetyGrE3Q
VIvqWULt/aYQlFY45Wgri3RP/51F9v6WOC0WraOR5vZJ/BDREslZDEq2IutiuLoW
veGlAxwAh2wIDBK99IZLiNITFqze0R8xR1NnaF1uwENrXxANOjJ4TtO9321OHHRW
AMx8sWvR1Jyna8+uefHrHcNvXpKMXjfcHfATvcIeFHl1q7yYyf/BW/QglRMwC9q1
l2AHEkX5C70bmxh29EXu9bQyOw==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1816]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 20 Feb 2017 08:29:39 GMT]
Etag: ["14191C0C2CF9FA8F4A1C4144996B81A193A3D48A"]
Expires: [Mon, 20 Feb 2017 08:29:39 GMT]
Last-Modified: [Sun, 19 Feb 2017 10:26:30 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-88-138.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

StartCom Class 1 DV Server CA (CA Certificate)

This certificate was cached at
Certificate details for StartCom Class 1 DV Server CA (At position 1 in certificate chain)
Serial number:
hex: 6a5dc3e53b4e4fd07b691ea5fcec646b
int: 141385024392521038045679749985328718955
Issued by: StartCom Certification Authority
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: StartCom Ltd.
Organization unit: StartCom Certification Authority
Country: IL
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/sfsca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/sfsca.crl
Size: 846 bytes (DER data)
Response time: 276.28324ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 4

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4.2-19368535) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [846]
Content-Type: [application/pkix-crl]
Date: [Fri, 17 Feb 2017 16:45:48 GMT]
Last-Modified: [Thu, 01 Dec 2016 02:39:50 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4.2-19368535) (-)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL file is DER encoded
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com (POST)
Size: 1769 bytes (DER data)
Response time: 258.148195ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-88-130.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG5QoBAKCCBt4wggbaBgkrBgEFBQcwAQEEggbLMIIGxzCB0aFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzAyMTgxMDEzMjRaMHMwcTBJMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIQ
al3D5TtOT9B7aR6l/Oxka4AAGA8yMDE3MDIxODEwMTMyNFqgERgPMjAxNzAyMjIx
MDIzMjRaMA0GCSqGSIb3DQEBBQUAA4IBAQBy9QJ4ldS8SFVWuxWR2l8X2jQILUlp
O/LEcx1g4/okJ4AzKG4r+2Mgo5XAZPhiQjpwzBzZmo6hU3MS5Dn2fKl31Gs2z84a
gL84Es61o/oCP3o6xKIzXvKCInrUGuQxGSE7PGXsm8p7xLtPkRTSs4jGMD0xaKk0
8BJSo9SEoYrYOvwqDNvp4mZ7cw6mU6i7Nez1Es6WWW7p3mp/0477/AQRLpoQxwVk
rwR8wSqdxDucNddV+uIK080CaBfkIZHu20VT8Cfj4bxcKGvSzdeC6UuKqPI2wkI+
/vJXuQKOCzS600p3mS9k1A+p0ljikrQTkOgsNRqwJYBePd/9OZVUj+9WoIIE2zCC
BNcwggTTMIICu6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUA
MH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQL
EyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBT
dGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFa
Fw0xNzA5MjAwMDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENv
bSBMdGQuMSAwHgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73
/KGBfj5JWHFXjL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYls
XO4fPd2zuNXq9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7f
rPplzXZkcG2l9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMIn
QQwS6HgUU63ePBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch
2fITwUxkXLshEuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOB
hDCBgTALBgNVHQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/
BAIwADAPBgkrBgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEm
n9cqHTAfBgNVHSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0B
AQUFAAOCAgEALbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56
nTWABnde9aW5W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEK
OvpHVriq2Znesu8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQB
wbK/L1KepHA83G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5
KvVUFxjQ6xXVvJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHu
wbM1WAPq2V0npFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lX
ITW2aB23z5+1YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6
ZgM+xBu7yP5L+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme
1iPneOUenpndLn4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0b
ococQpeHZ35UHuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMU
mSEqfLIBZONzHxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1769]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sat, 18 Feb 2017 10:24:12 GMT]
Etag: ["54E77C478DC51A418CE8A26E9ABC98AE890D134B"]
Expires: [Sat, 18 Feb 2017 10:24:12 GMT]
Last-Modified: [Sat, 18 Feb 2017 10:13:24 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-88-130.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com (GET)
Size: 1769 bytes (DER data)
Response time: 191.838247ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-88-130.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)

URL used for GET request

http:/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICEGpdw%2BU7Tk%2FQe2kepfzsZGs%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG5QoBAKCCBt4wggbaBgkrBgEFBQcwAQEEggbLMIIGxzCB0aFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzAyMTcxMDEyNDFaMHMwcTBJMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIQ
al3D5TtOT9B7aR6l/Oxka4AAGA8yMDE3MDIxNzEwMTI0MVqgERgPMjAxNzAyMjEx
MDIyNDFaMA0GCSqGSIb3DQEBBQUAA4IBAQB7cFGbwpjEVB23NO9TUr8S+tGB99XI
Q5RmLcMyJADxgzM194C65E2/0In6D7XoAOsq6X9+jl5DGYs6FImh+i0doz/lCKex
ac9ZGQq8MMNYwEtMwFTf/WMA5B8sjn7i4OPbtLOX/EFPb72XvmEwggqTyYglTniS
adrV/NQ+UAwaDNh/dSj5Nlvy+R2c+sl3O1JBapL3ecVeW8wuavP6es49KusQAira
UsJCHK5QPHx/7rzekgb1p22B3/5qnTDGqlPuB79ht97Bx1BE17ncCiOxoZJZUvSv
ReLyofmGGovZUJ7jGTLtkk2UV4VwuPE31jlwVDCkk1HERPv8KK0pcHkaoIIE2zCC
BNcwggTTMIICu6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUA
MH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQL
EyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBT
dGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFa
Fw0xNzA5MjAwMDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENv
bSBMdGQuMSAwHgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73
/KGBfj5JWHFXjL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYls
XO4fPd2zuNXq9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7f
rPplzXZkcG2l9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMIn
QQwS6HgUU63ePBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch
2fITwUxkXLshEuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOB
hDCBgTALBgNVHQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/
BAIwADAPBgkrBgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEm
n9cqHTAfBgNVHSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0B
AQUFAAOCAgEALbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56
nTWABnde9aW5W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEK
OvpHVriq2Znesu8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQB
wbK/L1KepHA83G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5
KvVUFxjQ6xXVvJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHu
wbM1WAPq2V0npFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lX
ITW2aB23z5+1YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6
ZgM+xBu7yP5L+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme
1iPneOUenpndLn4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0b
ococQpeHZ35UHuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMU
mSEqfLIBZONzHxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1769]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sat, 18 Feb 2017 10:24:12 GMT]
Etag: ["C1BAF7110964944069D05D1D7450040551D25CA4"]
Expires: [Sat, 18 Feb 2017 10:24:12 GMT]
Last-Modified: [Fri, 17 Feb 2017 10:12:41 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MEM_HIT from a23-219-88-130.deploy.akamaitechnologies.com (AkamaiGHost/8.2.2.1.2-19214781) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.