CRL & OCSP report for www.techfreaks.de

www.techfreaks.de

Certificate details for www.techfreaks.de (At position 0 in certificate chain)
Serial number:
hex: 60ff81ca06ae9
int: 1706408166845161
Issued by: StartCom Class 1 Primary Intermediate Server CA
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Country: DE
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Check certificate compliance for www.techfreaks.de.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/crt1-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/crt1-crl.crl
Size: 41500 bytes (DER data)
Response time: 49.899964ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 1583

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (A)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [56249]
Content-Type: [application/pkix-crl]
Date: [Wed, 26 Apr 2017 04:04:04 GMT]
Last-Modified: [Tue, 25 Apr 2017 04:46:29 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (A)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL should be in DER format but is PEM encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com/sub/class1/server/ca (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/sub/class1/server/ca (POST)
Size: 1897 bytes (DER data)
Response time: 111.726391ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 Primary Intermediate Server CA OCSP Responder
Issued by: StartCom Class 1 Primary Intermediate Server CA
Signing certificate validity: 2017-03-03 - 2017-06-21
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I0
0Jiwq5/0G2sI98xkLu8OLEUCBwYP+Bygauk=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHZQoBAKCCB14wggdaBgkrBgEFBQcwAQEEggdLMIIHRzCCAR6hgZ4wgZsxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENv
bSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJl
c3BvbmRlchgPMjAxNzA0MjYwMzEyNDdaMGowaDBAMAkGBSsOAwIaBQAEFGVoh09A
dQ8BajR1Yl4fXJPlom1YBBTrQjTQmLCrn/Qbawj3zGQu7w4sRQIHBg/4HKBq6YAA
GA8yMDE3MDQyNjAzMTI0N1qgERgPMjAxNzA0MzAwMzIyNDdaMA0GCSqGSIb3DQEB
CwUAA4IBAQCAj+nD4R1fMYUlBcFgIART/XXkx22IJJNfZZ000a60Lrv+2/kFcXTf
kryjCt5XASvKRiwqz8miximY2+bFoWSmwd95IPPMMJz27iX0A1Mw65PJYfRjG0bP
+LffXaFvIcg8Ns8kvxhJiUhbKEGUieRf2QVUqJOa+TMiZSF0iMcWENXNIbrdo8jQ
Ekazbi97yeERGJsJw2DTu1xkgjsiNi/3eW99QbkMGpa3IBkdXj6mhyImK2qCH8+o
Ehq/Un+NK+id4h/g9F/pa3BDkyOu2KyS+ky57bSM9Bm8aQm1/EXpvNYeZ+IJ6ybD
/HZ2vkP3G1nU+WduVzlj9p6wCISJvQE8oIIFDTCCBQkwggUFMIID7aADAgECAhAT
e0DkrXeLZGi+o3DVS+oWMA0GCSqGSIb3DQEBCwUAMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwg
Q2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQ
cmltYXJ5IEludGVybWVkaWF0ZSBTZXJ2ZXIgQ0EwHhcNMTcwMzAzMDE0MjEzWhcN
MTcwNjIxMDE0MjEzWjCBmzELMAkGA1UEBhMCSUwxFjAUBgNVBAoMDVN0YXJ0Q29t
IEx0ZC4xKzApBgNVBAsMIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25p
bmcxRzBFBgNVBAMMPlN0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgU2VydmVyIENBIE9DU1AgUmVzcG9uZGVyMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEA5lLhiU5ptb0Ox2Zzhk48H1Vx2S7Rkr+hjuqf8HYKOECVpTxp
R+C/8/ZRs9VFljetpzQGcD1q4SsJkf6NjXpxmQQF1+k0JKqeuS+ma2k4nN5l77Fw
SqG73iSKNyU6yswfXSwpmprgqC+lZpsv453S3LPuqzWL+EK0yCDV0oiT4d6TDRfv
DIInsfhs9wdiBcutjJ0FNk/HsJFUmSQQjB3aVrf5CqIufbeKzLfGzhR7cQA01UEI
xMs+qegVG+ZFoqM56sb0vLSj1WU8voGXaNGYmM5TwAMfuztabIUEJd+5qNluI2PG
bNmooAswgWipKfr+LOcfpq7DfNCmNOZfM70qvQIDAQABo4IBUDCCAUwwDgYDVR0P
AQH/BAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAw
DAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQULmLbez7bmY1mtrhLM3ogR7k0yE4wHwYD
VR0jBBgwFoAU60I00Jiwq5/0G2sI98xkLu8OLEUwgY4GCCsGAQUFBwEBBIGBMH8w
OQYIKwYBBQUHMAGGLWh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9zdWIvY2xhc3Mx
L3NlcnZlci9jYTBCBggrBgEFBQcwAoY2aHR0cDovL2FpYS5zdGFydHNzbC5jb20v
Y2VydHMvc3ViLmNsYXNzMS5zZXJ2ZXIuY2EuY3J0MDUGA1UdHwQuMCwwKqAooCaG
JGh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL2NydDEtY3JsLmNybDANBgkqhkiG9w0B
AQsFAAOCAQEAYvqr8TqHfyoXIpxB4nR/pnVuMdvjq/4h3HpuMkMRvk+I44PrpF8y
IN+91Rv7VIiXJ/j11haYeUVvs4JuxRBZ0cK1J8wBrY/MrywqNyjOvDZ1d/0ldIFj
4r76ASUHnlfhGA0pev1gfMBXzrQ/raWJYmeh21lAVs0zSzb7oKv0MenXMmq2pfua
fzXq4UFveWbgVr4azRGBo5D9/o3rq7s2pw6pzeK93tI9Ne21PQzwjs85C03dzfRK
TeEA4gJGMYgzJgTlgNFZBi12wMI0P5jXoBqaNp3MqPRlKgj6eW0pieVt8Pb7miJl
I11Df2WRY2NuoIYM8nOWCqe/97eg+6/Vlg==
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgIQE3tA5K13i2RovqNw1UvqFjANBgkqhkiG9w0BAQsFADCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsT
IlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0
YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgU2VydmVyIENBMB4X
DTE3MDMwMzAxNDIxM1oXDTE3MDYyMTAxNDIxM1owgZsxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1cmUgRGlnaXRhbCBD
ZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENvbSBDbGFzcyAxIFBy
aW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJlc3BvbmRlcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOZS4YlOabW9Dsdmc4ZOPB9Vcdku
0ZK/oY7qn/B2CjhAlaU8aUfgv/P2UbPVRZY3rac0BnA9auErCZH+jY16cZkEBdfp
NCSqnrkvpmtpOJzeZe+xcEqhu94kijclOsrMH10sKZqa4KgvpWabL+Od0tyz7qs1
i/hCtMgg1dKIk+Hekw0X7wyCJ7H4bPcHYgXLrYydBTZPx7CRVJkkEIwd2la3+Qqi
Ln23isy3xs4Ue3EANNVBCMTLPqnoFRvmRaKjOerG9Ly0o9VlPL6Bl2jRmJjOU8AD
H7s7WmyFBCXfuajZbiNjxmzZqKALMIFoqSn6/iznH6auw3zQpjTmXzO9Kr0CAwEA
AaOCAVAwggFMMA4GA1UdDwEB/wQEAwIDqDATBgNVHSUEDDAKBggrBgEFBQcDCTAP
BgkrBgEFBQcwAQUEAgUAMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFC5i23s+25mN
Zra4SzN6IEe5NMhOMB8GA1UdIwQYMBaAFOtCNNCYsKuf9BtrCPfMZC7vDixFMIGO
BggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRwOi8vb2NzcC5zdGFydHNz
bC5jb20vc3ViL2NsYXNzMS9zZXJ2ZXIvY2EwQgYIKwYBBQUHMAKGNmh0dHA6Ly9h
aWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuc2VydmVyLmNhLmNydDA1
BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9jcnQxLWNy
bC5jcmwwDQYJKoZIhvcNAQELBQADggEBAGL6q/E6h38qFyKcQeJ0f6Z1bjHb46v+
Idx6bjJDEb5PiOOD66RfMiDfvdUb+1SIlyf49dYWmHlFb7OCbsUQWdHCtSfMAa2P
zK8sKjcozrw2dXf9JXSBY+K++gElB55X4RgNKXr9YHzAV860P62liWJnodtZQFbN
M0s2+6Cr9DHp1zJqtqX7mn816uFBb3lm4Fa+Gs0RgaOQ/f6N66u7NqcOqc3ivd7S
PTXttT0M8I7POQtN3c30Sk3hAOICRjGIMyYE5YDRWQYtdsDCND+Y16AamjadzKj0
ZSoI+nltKYnlbfD2+5oiZSNdQ39lkWNjbqCGDPJzlgqnv/e3oPuv1ZY=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1897]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Wed, 26 Apr 2017 04:04:04 GMT]
Etag: ["350D496F0C8C13ECCF46082449C9D6FF512A0D07"]
Expires: [Wed, 26 Apr 2017 04:04:04 GMT]
Last-Modified: [Wed, 26 Apr 2017 03:12:47 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com/sub/class1/server/ca (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/sub/class1/server/ca (GET)
Size: 1897 bytes (DER data)
Response time: 431.847626ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 Primary Intermediate Server CA OCSP Responder
Issued by: StartCom Class 1 Primary Intermediate Server CA
Signing certificate validity: 2017-03-03 - 2017-06-21
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

URL used for GET request

http:/sub/class1/server/ca/MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I00Jiwq5%2F0G2sI98xkLu8OLEUCBwYP%2BBygauk%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I0
0Jiwq5/0G2sI98xkLu8OLEUCBwYP+Bygauk=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHZQoBAKCCB14wggdaBgkrBgEFBQcwAQEEggdLMIIHRzCCAR6hgZ4wgZsxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENv
bSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJl
c3BvbmRlchgPMjAxNzA0MjYwMzEyNDdaMGowaDBAMAkGBSsOAwIaBQAEFGVoh09A
dQ8BajR1Yl4fXJPlom1YBBTrQjTQmLCrn/Qbawj3zGQu7w4sRQIHBg/4HKBq6YAA
GA8yMDE3MDQyNjAzMTI0N1qgERgPMjAxNzA0MzAwMzIyNDdaMA0GCSqGSIb3DQEB
CwUAA4IBAQCAj+nD4R1fMYUlBcFgIART/XXkx22IJJNfZZ000a60Lrv+2/kFcXTf
kryjCt5XASvKRiwqz8miximY2+bFoWSmwd95IPPMMJz27iX0A1Mw65PJYfRjG0bP
+LffXaFvIcg8Ns8kvxhJiUhbKEGUieRf2QVUqJOa+TMiZSF0iMcWENXNIbrdo8jQ
Ekazbi97yeERGJsJw2DTu1xkgjsiNi/3eW99QbkMGpa3IBkdXj6mhyImK2qCH8+o
Ehq/Un+NK+id4h/g9F/pa3BDkyOu2KyS+ky57bSM9Bm8aQm1/EXpvNYeZ+IJ6ybD
/HZ2vkP3G1nU+WduVzlj9p6wCISJvQE8oIIFDTCCBQkwggUFMIID7aADAgECAhAT
e0DkrXeLZGi+o3DVS+oWMA0GCSqGSIb3DQEBCwUAMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwg
Q2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQ
cmltYXJ5IEludGVybWVkaWF0ZSBTZXJ2ZXIgQ0EwHhcNMTcwMzAzMDE0MjEzWhcN
MTcwNjIxMDE0MjEzWjCBmzELMAkGA1UEBhMCSUwxFjAUBgNVBAoMDVN0YXJ0Q29t
IEx0ZC4xKzApBgNVBAsMIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25p
bmcxRzBFBgNVBAMMPlN0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgU2VydmVyIENBIE9DU1AgUmVzcG9uZGVyMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEA5lLhiU5ptb0Ox2Zzhk48H1Vx2S7Rkr+hjuqf8HYKOECVpTxp
R+C/8/ZRs9VFljetpzQGcD1q4SsJkf6NjXpxmQQF1+k0JKqeuS+ma2k4nN5l77Fw
SqG73iSKNyU6yswfXSwpmprgqC+lZpsv453S3LPuqzWL+EK0yCDV0oiT4d6TDRfv
DIInsfhs9wdiBcutjJ0FNk/HsJFUmSQQjB3aVrf5CqIufbeKzLfGzhR7cQA01UEI
xMs+qegVG+ZFoqM56sb0vLSj1WU8voGXaNGYmM5TwAMfuztabIUEJd+5qNluI2PG
bNmooAswgWipKfr+LOcfpq7DfNCmNOZfM70qvQIDAQABo4IBUDCCAUwwDgYDVR0P
AQH/BAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAw
DAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQULmLbez7bmY1mtrhLM3ogR7k0yE4wHwYD
VR0jBBgwFoAU60I00Jiwq5/0G2sI98xkLu8OLEUwgY4GCCsGAQUFBwEBBIGBMH8w
OQYIKwYBBQUHMAGGLWh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9zdWIvY2xhc3Mx
L3NlcnZlci9jYTBCBggrBgEFBQcwAoY2aHR0cDovL2FpYS5zdGFydHNzbC5jb20v
Y2VydHMvc3ViLmNsYXNzMS5zZXJ2ZXIuY2EuY3J0MDUGA1UdHwQuMCwwKqAooCaG
JGh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL2NydDEtY3JsLmNybDANBgkqhkiG9w0B
AQsFAAOCAQEAYvqr8TqHfyoXIpxB4nR/pnVuMdvjq/4h3HpuMkMRvk+I44PrpF8y
IN+91Rv7VIiXJ/j11haYeUVvs4JuxRBZ0cK1J8wBrY/MrywqNyjOvDZ1d/0ldIFj
4r76ASUHnlfhGA0pev1gfMBXzrQ/raWJYmeh21lAVs0zSzb7oKv0MenXMmq2pfua
fzXq4UFveWbgVr4azRGBo5D9/o3rq7s2pw6pzeK93tI9Ne21PQzwjs85C03dzfRK
TeEA4gJGMYgzJgTlgNFZBi12wMI0P5jXoBqaNp3MqPRlKgj6eW0pieVt8Pb7miJl
I11Df2WRY2NuoIYM8nOWCqe/97eg+6/Vlg==
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgIQE3tA5K13i2RovqNw1UvqFjANBgkqhkiG9w0BAQsFADCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsT
IlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0
YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgU2VydmVyIENBMB4X
DTE3MDMwMzAxNDIxM1oXDTE3MDYyMTAxNDIxM1owgZsxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1cmUgRGlnaXRhbCBD
ZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENvbSBDbGFzcyAxIFBy
aW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJlc3BvbmRlcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOZS4YlOabW9Dsdmc4ZOPB9Vcdku
0ZK/oY7qn/B2CjhAlaU8aUfgv/P2UbPVRZY3rac0BnA9auErCZH+jY16cZkEBdfp
NCSqnrkvpmtpOJzeZe+xcEqhu94kijclOsrMH10sKZqa4KgvpWabL+Od0tyz7qs1
i/hCtMgg1dKIk+Hekw0X7wyCJ7H4bPcHYgXLrYydBTZPx7CRVJkkEIwd2la3+Qqi
Ln23isy3xs4Ue3EANNVBCMTLPqnoFRvmRaKjOerG9Ly0o9VlPL6Bl2jRmJjOU8AD
H7s7WmyFBCXfuajZbiNjxmzZqKALMIFoqSn6/iznH6auw3zQpjTmXzO9Kr0CAwEA
AaOCAVAwggFMMA4GA1UdDwEB/wQEAwIDqDATBgNVHSUEDDAKBggrBgEFBQcDCTAP
BgkrBgEFBQcwAQUEAgUAMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFC5i23s+25mN
Zra4SzN6IEe5NMhOMB8GA1UdIwQYMBaAFOtCNNCYsKuf9BtrCPfMZC7vDixFMIGO
BggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRwOi8vb2NzcC5zdGFydHNz
bC5jb20vc3ViL2NsYXNzMS9zZXJ2ZXIvY2EwQgYIKwYBBQUHMAKGNmh0dHA6Ly9h
aWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuc2VydmVyLmNhLmNydDA1
BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9jcnQxLWNy
bC5jcmwwDQYJKoZIhvcNAQELBQADggEBAGL6q/E6h38qFyKcQeJ0f6Z1bjHb46v+
Idx6bjJDEb5PiOOD66RfMiDfvdUb+1SIlyf49dYWmHlFb7OCbsUQWdHCtSfMAa2P
zK8sKjcozrw2dXf9JXSBY+K++gElB55X4RgNKXr9YHzAV860P62liWJnodtZQFbN
M0s2+6Cr9DHp1zJqtqX7mn816uFBb3lm4Fa+Gs0RgaOQ/f6N66u7NqcOqc3ivd7S
PTXttT0M8I7POQtN3c30Sk3hAOICRjGIMyYE5YDRWQYtdsDCND+Y16AamjadzKj0
ZSoI+nltKYnlbfD2+5oiZSNdQ39lkWNjbqCGDPJzlgqnv/e3oPuv1ZY=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1897]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Wed, 26 Apr 2017 04:04:05 GMT]
Etag: ["350D496F0C8C13ECCF46082449C9D6FF512A0D07"]
Expires: [Wed, 26 Apr 2017 04:04:05 GMT]
Last-Modified: [Wed, 26 Apr 2017 03:12:47 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

StartCom Class 1 Primary Intermediate Server CA (CA Certificate)

Certificate details for StartCom Class 1 Primary Intermediate Server CA (At position 1 in certificate chain)
Serial number:
hex: 17153d9eab3fbf
int: 6497278863556543
Issued by: StartCom Certification Authority
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: StartCom Ltd.
Organization unit: Secure Digital Certificate Signing
Country: IL
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/sfsca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/sfsca.crl
Size: 952 bytes (DER data)
Response time: 35.753537ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 7

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [952]
Content-Type: [application/pkix-crl]
Date: [Wed, 26 Apr 2017 04:04:04 GMT]
Last-Modified: [Wed, 12 Apr 2017 08:39:01 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_MEM_HIT from a23-219-88-155.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com/ca (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/ca (GET)
Size: 1760 bytes (DER data)
Response time: 38.354825ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

URL used for GET request

http:/ca/MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG3AoBAKCCBtUwggbRBgkrBgEFBQcwAQEEggbCMIIGvjCByKFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzA0MjUxMDEyMzNaMGowaDBAMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIH
FxU9nqs/v4AAGA8yMDE3MDQyNTEwMTIzM1qgERgPMjAxNzA0MjkxMDIyMzNaMA0G
CSqGSIb3DQEBBQUAA4IBAQB9LcCgpXcdwMnR1/METwZlFNSgBy0b5H33o5fjXVLX
QmKO9v394L2FF4v6MSlXk82nakqBauVYajvYlZaSjXk2SlMk1VP4LgHsZCeznP6d
AOvyFBOVdF/PplyWoFhbNVTbI8Im2kkAEC2jl+KR7HFmEgdDyFRvrUnh61jWxPFx
7WZktWNiITDX68lfd/+xdg4E0Q/D3wMX7vzZ41ga9PYnnVK/r7nWpjqfnicL+RS+
Ova/0mLGsR+YISUIwaQl6ae9kVY0pHA7fVq9gR+81wYgyNvJFq/Y+c7uMewsobfv
chOEpLRGVRpCo52ikfDOsNn29k1qG4Ma53SrdQuUFlI+oIIE2zCCBNcwggTTMIIC
u6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUg
RGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFaFw0xNzA5MjAw
MDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAw
HgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73/KGBfj5JWHFX
jL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYlsXO4fPd2zuNXq
9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7frPplzXZkcG2l
9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMInQQwS6HgUU63e
PBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch2fITwUxkXLsh
EuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOBhDCBgTALBgNV
HQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/BAIwADAPBgkr
BgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEmn9cqHTAfBgNV
HSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0BAQUFAAOCAgEA
LbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56nTWABnde9aW5
W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEKOvpHVriq2Zne
su8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQBwbK/L1KepHA8
3G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5KvVUFxjQ6xXV
vJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHuwbM1WAPq2V0n
pFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lXITW2aB23z5+1
YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6ZgM+xBu7yP5L
+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme1iPneOUenpnd
Ln4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0bococQpeHZ35U
HuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMUmSEqfLIBZONz
HxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1760]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Wed, 26 Apr 2017 04:04:04 GMT]
Etag: ["42BDD75F1CA3CE1274213BF0C75CBF2299EDCCF0"]
Expires: [Wed, 26 Apr 2017 04:04:04 GMT]
Last-Modified: [Tue, 25 Apr 2017 10:12:33 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MEM_HIT from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com/ca (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/ca (POST)
Size: 1760 bytes (DER data)
Response time: 266.141837ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG3AoBAKCCBtUwggbRBgkrBgEFBQcwAQEEggbCMIIGvjCByKFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzA0MjUxMDEyMzNaMGowaDBAMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIH
FxU9nqs/v4AAGA8yMDE3MDQyNTEwMTIzM1qgERgPMjAxNzA0MjkxMDIyMzNaMA0G
CSqGSIb3DQEBBQUAA4IBAQB9LcCgpXcdwMnR1/METwZlFNSgBy0b5H33o5fjXVLX
QmKO9v394L2FF4v6MSlXk82nakqBauVYajvYlZaSjXk2SlMk1VP4LgHsZCeznP6d
AOvyFBOVdF/PplyWoFhbNVTbI8Im2kkAEC2jl+KR7HFmEgdDyFRvrUnh61jWxPFx
7WZktWNiITDX68lfd/+xdg4E0Q/D3wMX7vzZ41ga9PYnnVK/r7nWpjqfnicL+RS+
Ova/0mLGsR+YISUIwaQl6ae9kVY0pHA7fVq9gR+81wYgyNvJFq/Y+c7uMewsobfv
chOEpLRGVRpCo52ikfDOsNn29k1qG4Ma53SrdQuUFlI+oIIE2zCCBNcwggTTMIIC
u6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUg
RGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFaFw0xNzA5MjAw
MDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAw
HgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73/KGBfj5JWHFX
jL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYlsXO4fPd2zuNXq
9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7frPplzXZkcG2l
9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMInQQwS6HgUU63e
PBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch2fITwUxkXLsh
EuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOBhDCBgTALBgNV
HQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/BAIwADAPBgkr
BgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEmn9cqHTAfBgNV
HSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0BAQUFAAOCAgEA
LbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56nTWABnde9aW5
W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEKOvpHVriq2Zne
su8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQBwbK/L1KepHA8
3G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5KvVUFxjQ6xXV
vJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHuwbM1WAPq2V0n
pFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lXITW2aB23z5+1
YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6ZgM+xBu7yP5L
+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme1iPneOUenpnd
Ln4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0bococQpeHZ35U
HuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMUmSEqfLIBZONz
HxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1760]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Wed, 26 Apr 2017 04:04:05 GMT]
Etag: ["42BDD75F1CA3CE1274213BF0C75CBF2299EDCCF0"]
Expires: [Wed, 26 Apr 2017 04:04:05 GMT]
Last-Modified: [Tue, 25 Apr 2017 10:12:33 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-50-225-6.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

StartCom Certification Authority (CA Certificate)

Certificate details for StartCom Certification Authority (At position 2 in certificate chain)
Serial number:
hex: 1
int: 1
Issued by: StartCom Certification Authority
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: StartCom Ltd.
Organization unit: Secure Digital Certificate Signing
Country: IL
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

This is a self signed certificate

Certificate Revocation List (CRL)

This CRL was cached at
http://cert.startcom.org/sfsca-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://cert.startcom.org/sfsca-crl.crl
Size: 952 bytes (DER data)
Response time: 519.695603ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 7

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.9.14

Raw CRL response headers

Accept-Ranges: [bytes]
Connection: [keep-alive]
Content-Length: [952]
Content-Type: [application/pkix-crl]
Date: [Wed, 26 Apr 2017 04:04:05 GMT]
Etag: ["58ede862-3b8"]
Last-Modified: [Wed, 12 Apr 2017 08:42:10 GMT]
Server: [nginx/1.9.14]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)
This CRL was cached at
http://crl.startcom.org/sfsca-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startcom.org/sfsca-crl.crl
Size: 0 bytes (DER data)
Response time: 0s

Raw CRL response headers

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.