CRL & OCSP report for 0-jump.valueline.com.sierra.helenplum.org - sierra.helenplum.org (Helen M Plum Memorial Library)

sierra.helenplum.org

Certificate details for sierra.helenplum.org (At position 0 in certificate chain)
Serial number:
hex: 7a06a301da36ef670000000050dbc746
int: 162200275446438647877495545723763803974
Issued by: Entrust Certification Authority - L1K
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Helen M Plum Memorial Library
Organization unit: Public Library
State / Province: Illinois
Locality: Lombard
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Check certificate compliance for 0-jump.valueline.com.sierra.helenplum.org.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/level1k.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/level1k.crl
Size: 1929535 bytes (DER data)
Response time: 328.098491ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 41699

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_HIT from a72-246-65-150.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.2-19998404) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [1929535]
Content-Type: [application/x-pkcs7-crl]
Date: [Thu, 25 May 2017 10:42:22 GMT]
Expires: [Thu, 25 May 2017 10:42:22 GMT]
Last-Modified: [Thu, 25 May 2017 10:00:10 GMT]
Pragma: [no-cache]
X-Cache: [TCP_HIT from a72-246-65-150.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.2-19998404) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 2120 bytes (DER data)
Response time: 98.156792ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1K
Signing certificate validity: 2014-08-26 - 2017-08-26
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 59m20s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a72-247-10-160.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1.1-20063003) (-)

URL used for GET request

http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC%2BHkV9a%2FvDh7s6DzAQUgqJwdN28Uz%2FPe9T3zX%2BnYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC+HkV9a/vDh7s6DzAQUgqJw
dN28Uz/Pe9T3zX+nYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIIRAoBAKCCCD0wggg5BgkrBgEFBQcwAQEEgggqMIIIJjCCAVahgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDUyNDIyMTU0MVowczBxMEkwCQYFKw4DAhoFAAQUzG0iHPa0
VSwvh5FfWv7w4e7Og8wEFIKicHTdvFM/z3vU981/p2DGCky/AhB6BqMB2jbvZwAA
AABQ28dGgAAYDzIwMTcwNTI0MjIxNTQxWqARGA8yMDE3MDUzMTIyMTU0MVowDQYJ
KoZIhvcNAQEFBQADggEBAKJ4/rzOj/0Tx2GIBP45hTYWusFiiF8+iET6KAcrkGu9
Sw8AAMJlwt4jVK6Nd4YGP8NGhPJq7ATrocHFDR5SeLN6/Rt4m2WXn0kP4qOmpk1k
p1YyXfQQHzTd0SKm4GNPL3qSYn6A6cT9fGJVHIWCuyqtRHY7RYg6j2nsUBcflaLw
bj9gpyHMjwsi1GUNGNA2uSZAlwwT1/hPezfNuY0M19wA0P+1P0OIEBsVbuR+d/3E
95k5CJghg5NAxJadhP0fHs56B2rEazpLAUjKAVHuBEjwi0wVyZfCinaENmdMnoJY
lycA1bTAxWd2qop6xN9IuJElQh+YaKQt4MjLfHgUMY6gggW0MIIFsDCCBawwggSU
oAMCAQICDQD1nbmmAAAAAFDR/sEwDQYJKoZIhvcNAQELBQAwgboxCzAJBgNVBAYT
AlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVu
dHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0
LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1
c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUswHhcNMTQwODI2MTQ1MzA5
WhcNMTcwODI2MTUyMzA5WjCByjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1
c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVy
bXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9y
aXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1
dGhvcml0eSAtIEwxSzEOMAwGA1UEAxMFT0NTUDEwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOS
P5k+le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/Z
TD5thDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWT
syLxWYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j
17pRhqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEs
xyMXUZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjggGdMIIBmTALBgNV
HQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAz
BggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3Qu
bmV0MIHjBgNVHR8EgdswgdgwgdWggdKggc+kgcwwgckxCzAJBgNVBAYTAlVTMRYw
FAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVudHJ1c3Qu
bmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0LCBJbmMu
IC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1c3QgQ2Vy
dGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDTALBgNVBAMTBENSTDEwHwYDVR0j
BBgwFoAUgqJwdN28Uz/Pe9T3zX+nYMYKTL8wHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAKknvrNG7098
baAlYnkbIAiaJjR4W91g17sNu04+G0Eq8GkVh5V1DwpELGGlCgq/yUimCKMtU8Dq
Tzovm+49d19XKfyUokLsN0Rnn6Ni5Rlp09ReR0HI+0X05zm4HhhI9S1hEmcEwaoM
RAVhFfvpGLuc/DmLUfOyN87rsOB0fGIdpX9prmlK8pq3baawHfodssH+fxTlAwN4
vSedux3ADn8ao4XrZFUgGG9serhKj4uUyySpJAE5ZGa6AVocRJEJrGbqvY/Sb9cB
0PyHjRPAU28Aq2c7ZSzUW606AlPseVJhUR+A65rLCH4EiuS9ckSTJNqPCyGs7cNk
ZIigKIY+NVQ=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFrDCCBJSgAwIBAgINAPWduaYAAAAAUNH+wTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEy
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0xNDA4
MjYxNDUzMDlaFw0xNzA4MjYxNTIzMDlaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTIgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFLMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOCAZ0w
ggGZMAsGA1UdDwQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDCTAPBgkrBgEFBQcw
AQUEAgUAMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3Au
ZW50cnVzdC5uZXQwgeMGA1UdHwSB2zCB2DCB1aCB0qCBz6SBzDCByTELMAkGA1UE
BhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cu
ZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1
c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50
cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzENMAsGA1UEAxMEQ1JM
MTAfBgNVHSMEGDAWgBSConB03bxTP8971PfNf6dgxgpMvzAdBgNVHQ4EFgQU1QIE
ttegqC2zvRIlq1LU0eWWjcQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEA
qSe+s0bvT3xtoCVieRsgCJomNHhb3WDXuw27Tj4bQSrwaRWHlXUPCkQsYaUKCr/J
SKYIoy1TwOpPOi+b7j13X1cp/JSiQuw3RGefo2LlGWnT1F5HQcj7RfTnObgeGEj1
LWESZwTBqgxEBWEV++kYu5z8OYtR87I3zuuw4HR8Yh2lf2muaUrymrdtprAd+h2y
wf5/FOUDA3i9J527HcAOfxqjhetkVSAYb2x6uEqPi5TLJKkkATlkZroBWhxEkQms
Zuq9j9Jv1wHQ/IeNE8BTbwCrZztlLNRbrToCU+x5UmFRH4DrmssIfgSK5L1yRJMk
2o8LIaztw2RkiKAohj41VA==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=3560]
Content-Length: [2120]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Thu, 25 May 2017 10:44:13 GMT]
Etag: ["70047D2A930BEC8D1D755903A9C1A2F06C66BBB0"]
Expires: [Thu, 25 May 2017 11:43:33 GMT]
Last-Modified: [Wed, 24 May 2017 22:15:41 GMT]
X-Cache: [TCP_MISS from a72-247-10-160.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1.1-20063003) (-)]
  • OCSP requests is smaller than 255 bytes
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • OCSP response is valid for at least 8 hours (Microsoft)
  • OCSP response is available at least 8 hours before the current period expires or at ½ the validity if valid for more than 16 hours (Microsoft)
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 2120 bytes (DER data)
Response time: 102.403279ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1K
Signing certificate validity: 2014-08-26 - 2017-08-26
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 1h0m0s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a72-247-10-166.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1.1-20063003) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC+HkV9a/vDh7s6DzAQUgqJw
dN28Uz/Pe9T3zX+nYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIIRAoBAKCCCD0wggg5BgkrBgEFBQcwAQEEgggqMIIIJjCCAVahgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDUyNDIyMTU0MVowczBxMEkwCQYFKw4DAhoFAAQUzG0iHPa0
VSwvh5FfWv7w4e7Og8wEFIKicHTdvFM/z3vU981/p2DGCky/AhB6BqMB2jbvZwAA
AABQ28dGgAAYDzIwMTcwNTI0MjIxNTQxWqARGA8yMDE3MDUzMTIyMTU0MVowDQYJ
KoZIhvcNAQEFBQADggEBAKJ4/rzOj/0Tx2GIBP45hTYWusFiiF8+iET6KAcrkGu9
Sw8AAMJlwt4jVK6Nd4YGP8NGhPJq7ATrocHFDR5SeLN6/Rt4m2WXn0kP4qOmpk1k
p1YyXfQQHzTd0SKm4GNPL3qSYn6A6cT9fGJVHIWCuyqtRHY7RYg6j2nsUBcflaLw
bj9gpyHMjwsi1GUNGNA2uSZAlwwT1/hPezfNuY0M19wA0P+1P0OIEBsVbuR+d/3E
95k5CJghg5NAxJadhP0fHs56B2rEazpLAUjKAVHuBEjwi0wVyZfCinaENmdMnoJY
lycA1bTAxWd2qop6xN9IuJElQh+YaKQt4MjLfHgUMY6gggW0MIIFsDCCBawwggSU
oAMCAQICDQD1nbmmAAAAAFDR/sEwDQYJKoZIhvcNAQELBQAwgboxCzAJBgNVBAYT
AlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVu
dHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0
LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1
c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUswHhcNMTQwODI2MTQ1MzA5
WhcNMTcwODI2MTUyMzA5WjCByjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1
c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVy
bXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9y
aXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1
dGhvcml0eSAtIEwxSzEOMAwGA1UEAxMFT0NTUDEwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOS
P5k+le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/Z
TD5thDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWT
syLxWYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j
17pRhqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEs
xyMXUZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjggGdMIIBmTALBgNV
HQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAz
BggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3Qu
bmV0MIHjBgNVHR8EgdswgdgwgdWggdKggc+kgcwwgckxCzAJBgNVBAYTAlVTMRYw
FAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVudHJ1c3Qu
bmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0LCBJbmMu
IC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1c3QgQ2Vy
dGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDTALBgNVBAMTBENSTDEwHwYDVR0j
BBgwFoAUgqJwdN28Uz/Pe9T3zX+nYMYKTL8wHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAKknvrNG7098
baAlYnkbIAiaJjR4W91g17sNu04+G0Eq8GkVh5V1DwpELGGlCgq/yUimCKMtU8Dq
Tzovm+49d19XKfyUokLsN0Rnn6Ni5Rlp09ReR0HI+0X05zm4HhhI9S1hEmcEwaoM
RAVhFfvpGLuc/DmLUfOyN87rsOB0fGIdpX9prmlK8pq3baawHfodssH+fxTlAwN4
vSedux3ADn8ao4XrZFUgGG9serhKj4uUyySpJAE5ZGa6AVocRJEJrGbqvY/Sb9cB
0PyHjRPAU28Aq2c7ZSzUW606AlPseVJhUR+A65rLCH4EiuS9ckSTJNqPCyGs7cNk
ZIigKIY+NVQ=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFrDCCBJSgAwIBAgINAPWduaYAAAAAUNH+wTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEy
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0xNDA4
MjYxNDUzMDlaFw0xNzA4MjYxNTIzMDlaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTIgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFLMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOCAZ0w
ggGZMAsGA1UdDwQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDCTAPBgkrBgEFBQcw
AQUEAgUAMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3Au
ZW50cnVzdC5uZXQwgeMGA1UdHwSB2zCB2DCB1aCB0qCBz6SBzDCByTELMAkGA1UE
BhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cu
ZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1
c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50
cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzENMAsGA1UEAxMEQ1JM
MTAfBgNVHSMEGDAWgBSConB03bxTP8971PfNf6dgxgpMvzAdBgNVHQ4EFgQU1QIE
ttegqC2zvRIlq1LU0eWWjcQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEA
qSe+s0bvT3xtoCVieRsgCJomNHhb3WDXuw27Tj4bQSrwaRWHlXUPCkQsYaUKCr/J
SKYIoy1TwOpPOi+b7j13X1cp/JSiQuw3RGefo2LlGWnT1F5HQcj7RfTnObgeGEj1
LWESZwTBqgxEBWEV++kYu5z8OYtR87I3zuuw4HR8Yh2lf2muaUrymrdtprAd+h2y
wf5/FOUDA3i9J527HcAOfxqjhetkVSAYb2x6uEqPi5TLJKkkATlkZroBWhxEkQms
Zuq9j9Jv1wHQ/IeNE8BTbwCrZztlLNRbrToCU+x5UmFRH4DrmssIfgSK5L1yRJMk
2o8LIaztw2RkiKAohj41VA==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=3600]
Content-Length: [2120]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Thu, 25 May 2017 10:44:13 GMT]
Etag: ["70047D2A930BEC8D1D755903A9C1A2F06C66BBB0"]
Expires: [Thu, 25 May 2017 11:44:13 GMT]
Last-Modified: [Wed, 24 May 2017 22:15:41 GMT]
X-Cache: [TCP_MISS from a72-247-10-166.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1.1-20063003) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • OCSP response is valid for at least 8 hours (Microsoft)
  • OCSP response is available at least 8 hours before the current period expires or at ½ the validity if valid for more than 16 hours (Microsoft)
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Certification Authority - L1K (CA Certificate)

Certificate details for Entrust Certification Authority - L1K (At position 1 in certificate chain)
Serial number:
hex: 51d360ee
int: 1372807406
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2012 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/g2ca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/g2ca.crl
Size: 1224 bytes (DER data)
Response time: 65.407738ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 14

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a72-246-65-150.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.2-19998404) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [1224]
Content-Type: [application/x-pkcs7-crl]
Date: [Thu, 25 May 2017 10:42:22 GMT]
Expires: [Thu, 25 May 2017 10:42:22 GMT]
Last-Modified: [Thu, 05 Jan 2017 20:27:50 GMT]
Pragma: [no-cache]
X-Cache: [TCP_MEM_HIT from a72-246-65-150.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.2-19998404) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 1983 bytes (DER data)
Response time: 252.782638ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 49m30s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-217-200-69.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1-19946687) (-)

URL used for GET request

http://ocsp.entrust.net/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCBFHTYO4%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCBFHTYO4=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHuwoBAKCCB7QwggewBgkrBgEFBQcwAQEEggehMIIHnTCCAWWhgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDUyMTIyMjEx
MFowZzBlMD0wCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgRR02DugAAYDzIwMTcwNTIxMjIyMTEwWqARGA8yMDE3
MDUyODIyMjExMFowDQYJKoZIhvcNAQEFBQADggEBAKz7f0nHDErJTjh6swkJuwwK
lO5iFvVUI67Wh1Bxn4VYy4YPLrzPpi3Jhqb5bQ63HCozR45NNUVu+p4VrETAECGl
8IF5O/0C7F/BX/9u7I/y11hF0YIQr5JFHYY4gEhmbzFMQUxnCBgBw5gtYudIKIBN
dDL0lx1Juh1hQQ9F0nMAIGxkSPllCvCVkN0tCnEWwG8BkK8wDmuxPjzpgoMkiK2k
yfIfRppeEcxZxee4OWXEfZaIX4EdznQ/ennOcCp7snFl0KU/FnE0L6WcM0m0JGdt
Ow4ySWiOghAexyvmOn1nbheS23/Aw7BVZVwLYqpOsGZMkzb+PWpTaMNZFQv/zEag
ggUcMIIFGDCCBRQwggP8oAMCAQICDE3pUL0AAAAAUdNzSDANBgkqhkiG9w0BAQsF
ADCBvjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNV
BAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChj
KSAyMDA5IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEy
MDAGA1UEAxMpRW50cnVzdCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0g
RzIwHhcNMTUwNjA0MTkxNTM0WhcNMTcwNjA0MTk0NTM0WjCB5TELMAkGA1UEBhMC
VVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50
cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDA5IEVudHJ1c3Qs
IEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEyMDAGA1UEAxMpRW50cnVz
dCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzIxJTAjBgNVBAMTHEVu
dHJ1c3QgVmFsaWRhdGlvbiBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOSP5k+
le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/ZTD5t
hDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWTsyLx
WYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j17pR
hqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEsxyMX
UZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjgegwgeUwCwYDVR0PBAQD
AgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwMAYDVR0f
BCkwJzAloCOgIYYfaHR0cDovL2NybC5lbnRydXN0Lm5ldC9nMmNhLmNybDAzBggr
BgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0
MB8GA1UdIwQYMBaAFGpyJnrQHu995ztpUdRsjZ+QEmarMB0GA1UdDgQWBBTVAgS2
16CoLbO9EiWrUtTR5ZaNxDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQAz
oliCixo0FUe0m4c7Njr0eZfaS386B543vIix94TOfupmA84ZrfY1mAz0v8Zj1zzH
N+FUI6pERUJrZfKZ8tWMA62lsi1SUfNVn0TGtAZd0Fyvz8z7zRUol6dZ3GXLWjGu
ibGul/wzHQeijzIUbvaG3UBj2kb/YX9teQrjm5ZhUZiVKP2sFk4AD34iJCPc16C+
lHjDyEg1JPjpEiVqNc580V9wo7dQGc+Z5VL4HV2SO5b8Xb6ybGrqzcq6xgUGhaGR
MvoxCjp9FzqYdLCH6Tw8PBpVnF5G8N/A47sEVvkgZddTtLj6BEgc7LChBKp5Fxx6
Bc/UIpcSa4G3Ff0tYc/U
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=2970]
Content-Length: [1983]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 22 May 2017 07:46:36 GMT]
Etag: ["207C3F52CFE5878C2F4E451023D9B9CDE43AAF04"]
Expires: [Mon, 22 May 2017 08:36:06 GMT]
Last-Modified: [Sun, 21 May 2017 22:21:10 GMT]
X-Cache: [TCP_MEM_HIT from a23-217-200-69.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1-19946687) (-)]
  • OCSP requests is smaller than 255 bytes
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 1983 bytes (DER data)
Response time: 250.94452ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 32m4s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_REFRESH_MISS from a23-217-200-39.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1-19946687) (S)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCBFHTYO4=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHuwoBAKCCB7QwggewBgkrBgEFBQcwAQEEggehMIIHnTCCAWWhgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDUyMTIyMjEx
MFowZzBlMD0wCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgRR02DugAAYDzIwMTcwNTIxMjIyMTEwWqARGA8yMDE3
MDUyODIyMjExMFowDQYJKoZIhvcNAQEFBQADggEBAKz7f0nHDErJTjh6swkJuwwK
lO5iFvVUI67Wh1Bxn4VYy4YPLrzPpi3Jhqb5bQ63HCozR45NNUVu+p4VrETAECGl
8IF5O/0C7F/BX/9u7I/y11hF0YIQr5JFHYY4gEhmbzFMQUxnCBgBw5gtYudIKIBN
dDL0lx1Juh1hQQ9F0nMAIGxkSPllCvCVkN0tCnEWwG8BkK8wDmuxPjzpgoMkiK2k
yfIfRppeEcxZxee4OWXEfZaIX4EdznQ/ennOcCp7snFl0KU/FnE0L6WcM0m0JGdt
Ow4ySWiOghAexyvmOn1nbheS23/Aw7BVZVwLYqpOsGZMkzb+PWpTaMNZFQv/zEag
ggUcMIIFGDCCBRQwggP8oAMCAQICDE3pUL0AAAAAUdNzSDANBgkqhkiG9w0BAQsF
ADCBvjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNV
BAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChj
KSAyMDA5IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEy
MDAGA1UEAxMpRW50cnVzdCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0g
RzIwHhcNMTUwNjA0MTkxNTM0WhcNMTcwNjA0MTk0NTM0WjCB5TELMAkGA1UEBhMC
VVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50
cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDA5IEVudHJ1c3Qs
IEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEyMDAGA1UEAxMpRW50cnVz
dCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzIxJTAjBgNVBAMTHEVu
dHJ1c3QgVmFsaWRhdGlvbiBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOSP5k+
le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/ZTD5t
hDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWTsyLx
WYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j17pR
hqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEsxyMX
UZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjgegwgeUwCwYDVR0PBAQD
AgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwMAYDVR0f
BCkwJzAloCOgIYYfaHR0cDovL2NybC5lbnRydXN0Lm5ldC9nMmNhLmNybDAzBggr
BgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0
MB8GA1UdIwQYMBaAFGpyJnrQHu995ztpUdRsjZ+QEmarMB0GA1UdDgQWBBTVAgS2
16CoLbO9EiWrUtTR5ZaNxDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQAz
oliCixo0FUe0m4c7Njr0eZfaS386B543vIix94TOfupmA84ZrfY1mAz0v8Zj1zzH
N+FUI6pERUJrZfKZ8tWMA62lsi1SUfNVn0TGtAZd0Fyvz8z7zRUol6dZ3GXLWjGu
ibGul/wzHQeijzIUbvaG3UBj2kb/YX9teQrjm5ZhUZiVKP2sFk4AD34iJCPc16C+
lHjDyEg1JPjpEiVqNc580V9wo7dQGc+Z5VL4HV2SO5b8Xb6ybGrqzcq6xgUGhaGR
MvoxCjp9FzqYdLCH6Tw8PBpVnF5G8N/A47sEVvkgZddTtLj6BEgc7LChBKp5Fxx6
Bc/UIpcSa4G3Ff0tYc/U
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=1924]
Content-Length: [1983]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 22 May 2017 07:46:36 GMT]
Etag: ["207C3F52CFE5878C2F4E451023D9B9CDE43AAF04"]
Expires: [Mon, 22 May 2017 08:18:40 GMT]
Last-Modified: [Sun, 21 May 2017 22:21:10 GMT]
X-Cache: [TCP_REFRESH_MISS from a23-217-200-39.deploy.akamaitechnologies.com (AkamaiGHost/8.3.4.1-19946687) (S)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Root Certification Authority - G2 (CA Certificate)

Certificate details for Entrust Root Certification Authority - G2 (At position 2 in certificate chain)
Serial number:
hex: 4a538c28
int: 1246989352
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2009 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

This is a self signed certificate

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.