CRL & OCSP report for 0-jump.valueline.com.sierra.helenplum.org - sierra.helenplum.org (Helen M Plum Memorial Library)

sierra.helenplum.org

This certificate was cached at
Certificate details for sierra.helenplum.org (At position 0 in certificate chain)
Serial number:
hex: 7a06a301da36ef670000000050dbc746
int: 162200275446438647877495545723763803974
Issued by: Entrust Certification Authority - L1K
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Helen M Plum Memorial Library
Organization unit: Public Library
State / Province: Illinois
Locality: Lombard
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

View complete certificate details for 0-jump.valueline.com.sierra.helenplum.org.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/level1k.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/level1k.crl
Size: 1831982 bytes (DER data)
Response time: 20.483492ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 39933

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_HIT from a23-219-92-215.deploy.akamaitechnologies.com (AkamaiGHost/8.3.0-19527178) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [1831982]
Content-Type: [application/x-pkcs7-crl]
Date: [Tue, 28 Mar 2017 01:17:05 GMT]
Expires: [Tue, 28 Mar 2017 01:17:05 GMT]
Last-Modified: [Tue, 28 Mar 2017 01:00:13 GMT]
Pragma: [no-cache]
X-Cache: [TCP_HIT from a23-219-92-215.deploy.akamaitechnologies.com (AkamaiGHost/8.3.0-19527178) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 2120 bytes (DER data)
Response time: 75.346935ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1K
Signing certificate validity: 2014-08-26 - 2017-08-26
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 59m10s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-93-69.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC+HkV9a/vDh7s6DzAQUgqJw
dN28Uz/Pe9T3zX+nYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIIRAoBAKCCCD0wggg5BgkrBgEFBQcwAQEEgggqMIIIJjCCAVahgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDMyMTIwNTU1M1owczBxMEkwCQYFKw4DAhoFAAQUzG0iHPa0
VSwvh5FfWv7w4e7Og8wEFIKicHTdvFM/z3vU981/p2DGCky/AhB6BqMB2jbvZwAA
AABQ28dGgAAYDzIwMTcwMzIxMjA1NTUzWqARGA8yMDE3MDMyODIwNTU1M1owDQYJ
KoZIhvcNAQEFBQADggEBABHveOhftXqTPPtX1boAUbklZeCPy1GvYTRcVelZVC1o
yhSbUeX7sc0TvoI5EeG84NRJx6XnmQCgJMxW5ir2Wh0UuEyILialTIvE/7O8ZDWF
sIJEye3NDRF1Tt9uQZjmUNY6nhxhvZe4ZObyhpWHoTIWG/HH46WaWzJxE+yC1XJP
LFUhsKjDASiISECiZW26cF1jOanEwZ0stPlVFaqbhhNSmbeXWYTcy+gg24O/sb5y
sNPCgzwUDg6EmpIXJGN6AK2sVqLjVEBj2IHOdam7gAtjVFo0sxB/wTDhFDp8DybP
i5cLtWWUydJrgpPpWYBpuZngS5zrwqLyewbERM4U8ZCgggW0MIIFsDCCBawwggSU
oAMCAQICDQD1nbmmAAAAAFDR/sEwDQYJKoZIhvcNAQELBQAwgboxCzAJBgNVBAYT
AlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVu
dHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0
LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1
c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUswHhcNMTQwODI2MTQ1MzA5
WhcNMTcwODI2MTUyMzA5WjCByjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1
c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVy
bXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9y
aXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1
dGhvcml0eSAtIEwxSzEOMAwGA1UEAxMFT0NTUDEwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOS
P5k+le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/Z
TD5thDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWT
syLxWYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j
17pRhqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEs
xyMXUZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjggGdMIIBmTALBgNV
HQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAz
BggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3Qu
bmV0MIHjBgNVHR8EgdswgdgwgdWggdKggc+kgcwwgckxCzAJBgNVBAYTAlVTMRYw
FAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVudHJ1c3Qu
bmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0LCBJbmMu
IC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1c3QgQ2Vy
dGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDTALBgNVBAMTBENSTDEwHwYDVR0j
BBgwFoAUgqJwdN28Uz/Pe9T3zX+nYMYKTL8wHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAKknvrNG7098
baAlYnkbIAiaJjR4W91g17sNu04+G0Eq8GkVh5V1DwpELGGlCgq/yUimCKMtU8Dq
Tzovm+49d19XKfyUokLsN0Rnn6Ni5Rlp09ReR0HI+0X05zm4HhhI9S1hEmcEwaoM
RAVhFfvpGLuc/DmLUfOyN87rsOB0fGIdpX9prmlK8pq3baawHfodssH+fxTlAwN4
vSedux3ADn8ao4XrZFUgGG9serhKj4uUyySpJAE5ZGa6AVocRJEJrGbqvY/Sb9cB
0PyHjRPAU28Aq2c7ZSzUW606AlPseVJhUR+A65rLCH4EiuS9ckSTJNqPCyGs7cNk
ZIigKIY+NVQ=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFrDCCBJSgAwIBAgINAPWduaYAAAAAUNH+wTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEy
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0xNDA4
MjYxNDUzMDlaFw0xNzA4MjYxNTIzMDlaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTIgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFLMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOCAZ0w
ggGZMAsGA1UdDwQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDCTAPBgkrBgEFBQcw
AQUEAgUAMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3Au
ZW50cnVzdC5uZXQwgeMGA1UdHwSB2zCB2DCB1aCB0qCBz6SBzDCByTELMAkGA1UE
BhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cu
ZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1
c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50
cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzENMAsGA1UEAxMEQ1JM
MTAfBgNVHSMEGDAWgBSConB03bxTP8971PfNf6dgxgpMvzAdBgNVHQ4EFgQU1QIE
ttegqC2zvRIlq1LU0eWWjcQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEA
qSe+s0bvT3xtoCVieRsgCJomNHhb3WDXuw27Tj4bQSrwaRWHlXUPCkQsYaUKCr/J
SKYIoy1TwOpPOi+b7j13X1cp/JSiQuw3RGefo2LlGWnT1F5HQcj7RfTnObgeGEj1
LWESZwTBqgxEBWEV++kYu5z8OYtR87I3zuuw4HR8Yh2lf2muaUrymrdtprAd+h2y
wf5/FOUDA3i9J527HcAOfxqjhetkVSAYb2x6uEqPi5TLJKkkATlkZroBWhxEkQms
Zuq9j9Jv1wHQ/IeNE8BTbwCrZztlLNRbrToCU+x5UmFRH4DrmssIfgSK5L1yRJMk
2o8LIaztw2RkiKAohj41VA==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=3550]
Content-Length: [2120]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Tue, 21 Mar 2017 21:23:33 GMT]
Etag: ["C3AC253BF46B68BBDBB7B456566846290717FF69"]
Expires: [Tue, 21 Mar 2017 22:22:43 GMT]
Last-Modified: [Tue, 21 Mar 2017 20:55:53 GMT]
X-Cache: [TCP_MISS from a23-219-93-69.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 2120 bytes (DER data)
Response time: 95.719021ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1K
Signing certificate validity: 2014-08-26 - 2017-08-26
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 58m53s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-93-102.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)

URL used for GET request

http:/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC%2BHkV9a%2FvDh7s6DzAQUgqJwdN28Uz%2FPe9T3zX%2BnYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC+HkV9a/vDh7s6DzAQUgqJw
dN28Uz/Pe9T3zX+nYMYKTL8CEHoGowHaNu9nAAAAAFDbx0Y=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIIRAoBAKCCCD0wggg5BgkrBgEFBQcwAQEEgggqMIIIJjCCAVahgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDMyMTIwNTU1M1owczBxMEkwCQYFKw4DAhoFAAQUzG0iHPa0
VSwvh5FfWv7w4e7Og8wEFIKicHTdvFM/z3vU981/p2DGCky/AhB6BqMB2jbvZwAA
AABQ28dGgAAYDzIwMTcwMzIxMjA1NTUzWqARGA8yMDE3MDMyODIwNTU1M1owDQYJ
KoZIhvcNAQEFBQADggEBABHveOhftXqTPPtX1boAUbklZeCPy1GvYTRcVelZVC1o
yhSbUeX7sc0TvoI5EeG84NRJx6XnmQCgJMxW5ir2Wh0UuEyILialTIvE/7O8ZDWF
sIJEye3NDRF1Tt9uQZjmUNY6nhxhvZe4ZObyhpWHoTIWG/HH46WaWzJxE+yC1XJP
LFUhsKjDASiISECiZW26cF1jOanEwZ0stPlVFaqbhhNSmbeXWYTcy+gg24O/sb5y
sNPCgzwUDg6EmpIXJGN6AK2sVqLjVEBj2IHOdam7gAtjVFo0sxB/wTDhFDp8DybP
i5cLtWWUydJrgpPpWYBpuZngS5zrwqLyewbERM4U8ZCgggW0MIIFsDCCBawwggSU
oAMCAQICDQD1nbmmAAAAAFDR/sEwDQYJKoZIhvcNAQELBQAwgboxCzAJBgNVBAYT
AlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVu
dHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0
LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1
c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUswHhcNMTQwODI2MTQ1MzA5
WhcNMTcwODI2MTUyMzA5WjCByjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1
c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVy
bXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9y
aXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1
dGhvcml0eSAtIEwxSzEOMAwGA1UEAxMFT0NTUDEwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOS
P5k+le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/Z
TD5thDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWT
syLxWYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j
17pRhqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEs
xyMXUZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjggGdMIIBmTALBgNV
HQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAz
BggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3Qu
bmV0MIHjBgNVHR8EgdswgdgwgdWggdKggc+kgcwwgckxCzAJBgNVBAYTAlVTMRYw
FAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUgd3d3LmVudHJ1c3Qu
bmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxMiBFbnRydXN0LCBJbmMu
IC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMTJUVudHJ1c3QgQ2Vy
dGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMUsxDTALBgNVBAMTBENSTDEwHwYDVR0j
BBgwFoAUgqJwdN28Uz/Pe9T3zX+nYMYKTL8wHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAKknvrNG7098
baAlYnkbIAiaJjR4W91g17sNu04+G0Eq8GkVh5V1DwpELGGlCgq/yUimCKMtU8Dq
Tzovm+49d19XKfyUokLsN0Rnn6Ni5Rlp09ReR0HI+0X05zm4HhhI9S1hEmcEwaoM
RAVhFfvpGLuc/DmLUfOyN87rsOB0fGIdpX9prmlK8pq3baawHfodssH+fxTlAwN4
vSedux3ADn8ao4XrZFUgGG9serhKj4uUyySpJAE5ZGa6AVocRJEJrGbqvY/Sb9cB
0PyHjRPAU28Aq2c7ZSzUW606AlPseVJhUR+A65rLCH4EiuS9ckSTJNqPCyGs7cNk
ZIigKIY+NVQ=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFrDCCBJSgAwIBAgINAPWduaYAAAAAUNH+wTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEy
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0xNDA4
MjYxNDUzMDlaFw0xNzA4MjYxNTIzMDlaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTIgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFLMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOCAZ0w
ggGZMAsGA1UdDwQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDCTAPBgkrBgEFBQcw
AQUEAgUAMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3Au
ZW50cnVzdC5uZXQwgeMGA1UdHwSB2zCB2DCB1aCB0qCBz6SBzDCByTELMAkGA1UE
BhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cu
ZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDEyIEVudHJ1
c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50
cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzENMAsGA1UEAxMEQ1JM
MTAfBgNVHSMEGDAWgBSConB03bxTP8971PfNf6dgxgpMvzAdBgNVHQ4EFgQU1QIE
ttegqC2zvRIlq1LU0eWWjcQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEA
qSe+s0bvT3xtoCVieRsgCJomNHhb3WDXuw27Tj4bQSrwaRWHlXUPCkQsYaUKCr/J
SKYIoy1TwOpPOi+b7j13X1cp/JSiQuw3RGefo2LlGWnT1F5HQcj7RfTnObgeGEj1
LWESZwTBqgxEBWEV++kYu5z8OYtR87I3zuuw4HR8Yh2lf2muaUrymrdtprAd+h2y
wf5/FOUDA3i9J527HcAOfxqjhetkVSAYb2x6uEqPi5TLJKkkATlkZroBWhxEkQms
Zuq9j9Jv1wHQ/IeNE8BTbwCrZztlLNRbrToCU+x5UmFRH4DrmssIfgSK5L1yRJMk
2o8LIaztw2RkiKAohj41VA==
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=3533]
Content-Length: [2120]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Tue, 21 Mar 2017 21:23:33 GMT]
Etag: ["C3AC253BF46B68BBDBB7B456566846290717FF69"]
Expires: [Tue, 21 Mar 2017 22:22:26 GMT]
Last-Modified: [Tue, 21 Mar 2017 20:55:53 GMT]
X-Cache: [TCP_MISS from a23-219-93-102.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Certification Authority - L1K (CA Certificate)

This certificate was cached at
Certificate details for Entrust Certification Authority - L1K (At position 1 in certificate chain)
Serial number:
hex: 51d360ee
int: 1372807406
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2012 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/g2ca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/g2ca.crl
Size: 1224 bytes (DER data)
Response time: 6.216437ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 14

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-92-215.deploy.akamaitechnologies.com (AkamaiGHost/8.3.0-19527178) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [1224]
Content-Type: [application/x-pkcs7-crl]
Date: [Tue, 28 Mar 2017 01:17:05 GMT]
Expires: [Tue, 28 Mar 2017 01:17:05 GMT]
Last-Modified: [Thu, 05 Jan 2017 20:27:50 GMT]
Pragma: [no-cache]
X-Cache: [TCP_MEM_HIT from a23-219-92-215.deploy.akamaitechnologies.com (AkamaiGHost/8.3.0-19527178) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 1983 bytes (DER data)
Response time: 4.979243ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 58m40s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-93-102.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)

URL used for GET request

http:/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCBFHTYO4%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCBFHTYO4=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHuwoBAKCCB7QwggewBgkrBgEFBQcwAQEEggehMIIHnTCCAWWhgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDMyNDIyMTAx
OFowZzBlMD0wCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgRR02DugAAYDzIwMTcwMzI0MjIxMDE4WqARGA8yMDE3
MDMzMTIyMTAxOFowDQYJKoZIhvcNAQEFBQADggEBAAgceUzkqOWYEc+gN51aLlrX
5akX4SH41sNo27acWzlOQJk1ZRQVbdyK5MijDm286d8c7q59xlYdFU5pqrhspgbV
e4e+Q6OwcIscuXWXSNy8uoiTpTJj2xIVOWW/WXOgxjVvFLLH+XavNoqwIY5lEFzt
Lj0qwwHCulhtM6s0Y4M8nQWkpv1oba/z4QmPfiEr2z0Wd+f+O1T8C0oQ3avqahC6
07uiVeL6MEUcrl6W0y6xCNZUgKeIcQ8zGSkp7JYqbHbxWr6VX6h0x1CvWSplXPlN
INYIQqhBzeJyHRMXbHx7JBLbu/lLzeAGIUWgpFDBSxjtzPTmZmEeaCOOJr8Oko6g
ggUcMIIFGDCCBRQwggP8oAMCAQICDE3pUL0AAAAAUdNzSDANBgkqhkiG9w0BAQsF
ADCBvjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNV
BAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChj
KSAyMDA5IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEy
MDAGA1UEAxMpRW50cnVzdCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0g
RzIwHhcNMTUwNjA0MTkxNTM0WhcNMTcwNjA0MTk0NTM0WjCB5TELMAkGA1UEBhMC
VVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50
cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDA5IEVudHJ1c3Qs
IEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEyMDAGA1UEAxMpRW50cnVz
dCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzIxJTAjBgNVBAMTHEVu
dHJ1c3QgVmFsaWRhdGlvbiBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOSP5k+
le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/ZTD5t
hDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWTsyLx
WYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j17pR
hqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEsxyMX
UZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjgegwgeUwCwYDVR0PBAQD
AgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwMAYDVR0f
BCkwJzAloCOgIYYfaHR0cDovL2NybC5lbnRydXN0Lm5ldC9nMmNhLmNybDAzBggr
BgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0
MB8GA1UdIwQYMBaAFGpyJnrQHu995ztpUdRsjZ+QEmarMB0GA1UdDgQWBBTVAgS2
16CoLbO9EiWrUtTR5ZaNxDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQAz
oliCixo0FUe0m4c7Njr0eZfaS386B543vIix94TOfupmA84ZrfY1mAz0v8Zj1zzH
N+FUI6pERUJrZfKZ8tWMA62lsi1SUfNVn0TGtAZd0Fyvz8z7zRUol6dZ3GXLWjGu
ibGul/wzHQeijzIUbvaG3UBj2kb/YX9teQrjm5ZhUZiVKP2sFk4AD34iJCPc16C+
lHjDyEg1JPjpEiVqNc580V9wo7dQGc+Z5VL4HV2SO5b8Xb6ybGrqzcq6xgUGhaGR
MvoxCjp9FzqYdLCH6Tw8PBpVnF5G8N/A47sEVvkgZddTtLj6BEgc7LChBKp5Fxx6
Bc/UIpcSa4G3Ff0tYc/U
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=3520]
Content-Length: [1983]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Fri, 24 Mar 2017 22:21:53 GMT]
Etag: ["93BB0F193C5F21D2A52E9BFA162E19C355A032D3"]
Expires: [Fri, 24 Mar 2017 23:20:33 GMT]
Last-Modified: [Fri, 24 Mar 2017 22:10:18 GMT]
X-Cache: [TCP_MEM_HIT from a23-219-93-102.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 1983 bytes (DER data)
Response time: 13.571618ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 26m59s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_REFRESH_MISS from a23-219-93-86.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (S)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEUwQzBBMD8wPTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCBFHTYO4=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHuwoBAKCCB7QwggewBgkrBgEFBQcwAQEEggehMIIHnTCCAWWhgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDMyNDIxMDgx
MFowZzBlMD0wCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgRR02DugAAYDzIwMTcwMzI0MjEwODEwWqARGA8yMDE3
MDMzMTIxMDgxMFowDQYJKoZIhvcNAQEFBQADggEBAB7IT0tWU58wiPHAPNN730DX
sUIPIfZsgNQh1CFTulU1aaILWBeI3YWIhAxvBDAcyaN4AdaewaH4VbLK2ACM3W5P
y84xO8CzL1CJlQXUjzXorc4uyMDaHqid/9QWp3Nx4/DEvyV4WQUDCoE/NBzsN2ak
Lc6mZyTk+UE5gl1e5GzWc1VHP4RCLf8Bt4y0JN4zvQbadWFF1j0BQmAYbCsoC1+D
w4Zy3T+BV1HVIyfuynyPNnEfLKWdnZpMlyXI6c7MrtFlOmC80PW5rp3GSeRzeqXL
wRBVpW/oJ1tCX6HrGT1aFWuLEfzPJtARXlfnR7IjO990tCMURPg2KT8GvwEkXzqg
ggUcMIIFGDCCBRQwggP8oAMCAQICDE3pUL0AAAAAUdNzSDANBgkqhkiG9w0BAQsF
ADCBvjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNV
BAsTH1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChj
KSAyMDA5IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEy
MDAGA1UEAxMpRW50cnVzdCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0g
RzIwHhcNMTUwNjA0MTkxNTM0WhcNMTcwNjA0MTk0NTM0WjCB5TELMAkGA1UEBhMC
VVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50
cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDA5IEVudHJ1c3Qs
IEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEyMDAGA1UEAxMpRW50cnVz
dCBSb290IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzIxJTAjBgNVBAMTHEVu
dHJ1c3QgVmFsaWRhdGlvbiBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDJ2olV6euD1UypXkHiIkBtqWnQN+pBpNQle7cbn6HqteOSP5k+
le/tCKaVTNgOCy+Zdg1Rqk7AEAkYpRda22cp3OdBQN1106J6b2nZOMMuuQ/ZTD5t
hDaOaKw7W16paxxYXMga5Iveivn3VXnZce/riWXgAu9mQl82qFSnNsICBRWTsyLx
WYnJIh6YfLSBjNxEiSqdiX6OuHz1z5raE1dhlGTKqrnAFA9v7P0pTmGiU/9j17pR
hqIOgOAflyZFwZ6sGJh5v9tI5dXUhhwOZuPY46zHwblYSGAdA3jxWzIxzjEsxyMX
UZxng5nIZwS/we7y3nX/24L/DkTM5JheA6QzAgMBAAGjgegwgeUwCwYDVR0PBAQD
AgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwMAYDVR0f
BCkwJzAloCOgIYYfaHR0cDovL2NybC5lbnRydXN0Lm5ldC9nMmNhLmNybDAzBggr
BgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0
MB8GA1UdIwQYMBaAFGpyJnrQHu995ztpUdRsjZ+QEmarMB0GA1UdDgQWBBTVAgS2
16CoLbO9EiWrUtTR5ZaNxDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQAz
oliCixo0FUe0m4c7Njr0eZfaS386B543vIix94TOfupmA84ZrfY1mAz0v8Zj1zzH
N+FUI6pERUJrZfKZ8tWMA62lsi1SUfNVn0TGtAZd0Fyvz8z7zRUol6dZ3GXLWjGu
ibGul/wzHQeijzIUbvaG3UBj2kb/YX9teQrjm5ZhUZiVKP2sFk4AD34iJCPc16C+
lHjDyEg1JPjpEiVqNc580V9wo7dQGc+Z5VL4HV2SO5b8Xb6ybGrqzcq6xgUGhaGR
MvoxCjp9FzqYdLCH6Tw8PBpVnF5G8N/A47sEVvkgZddTtLj6BEgc7LChBKp5Fxx6
Bc/UIpcSa4G3Ff0tYc/U
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=1619]
Content-Length: [1983]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Fri, 24 Mar 2017 22:21:53 GMT]
Etag: ["D9610D0012B6B8166CA4F15D2E957F774B8FB124"]
Expires: [Fri, 24 Mar 2017 22:48:52 GMT]
Last-Modified: [Fri, 24 Mar 2017 21:08:10 GMT]
X-Cache: [TCP_REFRESH_MISS from a23-219-93-86.deploy.akamaitechnologies.com (AkamaiGHost/8.2.4-19356466) (S)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Root Certification Authority - G2 (CA Certificate)

This certificate was cached at
Certificate details for Entrust Root Certification Authority - G2 (At position 2 in certificate chain)
Serial number:
hex: 4a538c28
int: 1246989352
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2009 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

This is a self signed certificate

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.