CRL & OCSP report for www.infomotor.hr

www.infomotor.hr

Certificate details for www.infomotor.hr (At position 0 in certificate chain)
Serial number:
hex: 70ae0
int: 461536
Issued by: StartCom Class 1 Primary Intermediate Server CA
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Country: HR
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Check certificate compliance for www.infomotor.hr.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/crt1-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/crt1-crl.crl
Size: 41500 bytes (DER data)
Response time: 7.561952ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 1583

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-92-30.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [56249]
Content-Type: [application/pkix-crl]
Date: [Sun, 30 Apr 2017 12:47:47 GMT]
Last-Modified: [Sat, 29 Apr 2017 16:46:28 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_MEM_HIT from a23-219-92-30.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL should be in DER format but is PEM encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com/sub/class1/server/ca (POST)Unknown

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/sub/class1/server/ca (POST)
Size: 1893 bytes (DER data)
Response time: 317.983776ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 Primary Intermediate Server CA OCSP Responder
Issued by: StartCom Class 1 Primary Intermediate Server CA
Signing certificate validity: 2017-03-03 - 2017-06-21
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Unknown

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEQwQjBAMD4wPDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I0
0Jiwq5/0G2sI98xkLu8OLEUCAwcK4A==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHYQoBAKCCB1owggdWBgkrBgEFBQcwAQEEggdHMIIHQzCCARqhgZ4wgZsxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENv
bSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJl
c3BvbmRlchgPMjAxNzA0MzAxMjQ4MTJaMGYwZDA8MAkGBSsOAwIaBQAEFGVoh09A
dQ8BajR1Yl4fXJPlom1YBBTrQjTQmLCrn/Qbawj3zGQu7w4sRQIDBwrgggAYDzIw
MTcwNDMwMTI0ODEyWqARGA8yMDE3MDUwNDEyNTgxMlowDQYJKoZIhvcNAQELBQAD
ggEBAG53auMQDWldPSgtilHI3UQZMWN4xVpY2EZnlZDxxxv87LXDbT4DPeeZVGdP
xICPCpheliBQ+h/BUJHXFk6jwfwEIbwMstk7TbEoTT8YnIK9YFB545HW4Kd2hoO9
pWCBwYfXUB56bQ/A6uybktXlaiiQUz2BqEqj00kfG4BZq5RCjtqBFCLQLYnyRRqx
7Xn9fvhkMusWCcMXqJCctso/LYcfW3oSIdUrDX0C36J/pYmIcLTRwOmuMHhHxiBR
YPff1XQT5suhMDZuLhZSYTkws0tRT8jYNb/XNy44E+q9gD62kRyC6lX9ZCQV92vE
TsKWym0MubYpzfMDt6eO2n1l6KWgggUNMIIFCTCCBQUwggPtoAMCAQICEBN7QOSt
d4tkaL6jcNVL6hYwDQYJKoZIhvcNAQELBQAwgYwxCzAJBgNVBAYTAklMMRYwFAYD
VQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0
aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQTAeFw0xNzAzMDMwMTQyMTNaFw0xNzA2
MjEwMTQyMTNaMIGbMQswCQYDVQQGEwJJTDEWMBQGA1UECgwNU3RhcnRDb20gTHRk
LjErMCkGA1UECwwiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzFH
MEUGA1UEAww+U3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBT
ZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDmUuGJTmm1vQ7HZnOGTjwfVXHZLtGSv6GO6p/wdgo4QJWlPGlH4L/z
9lGz1UWWN62nNAZwPWrhKwmR/o2NenGZBAXX6TQkqp65L6ZraTic3mXvsXBKobve
JIo3JTrKzB9dLCmamuCoL6Vmmy/jndLcs+6rNYv4QrTIINXSiJPh3pMNF+8Mgiex
+Gz3B2IFy62MnQU2T8ewkVSZJBCMHdpWt/kKoi59t4rMt8bOFHtxADTVQQjEyz6p
6BUb5kWioznqxvS8tKPVZTy+gZdo0ZiYzlPAAx+7O1pshQQl37mo2W4jY8Zs2aig
CzCBaKkp+v4s5x+mrsN80KY05l8zvSq9AgMBAAGjggFQMIIBTDAOBgNVHQ8BAf8E
BAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNV
HRMBAf8EAjAAMB0GA1UdDgQWBBQuYtt7PtuZjWa2uEszeiBHuTTITjAfBgNVHSME
GDAWgBTrQjTQmLCrn/Qbawj3zGQu7w4sRTCBjgYIKwYBBQUHAQEEgYEwfzA5Bggr
BgEFBQcwAYYtaHR0cDovL29jc3Auc3RhcnRzc2wuY29tL3N1Yi9jbGFzczEvc2Vy
dmVyL2NhMEIGCCsGAQUFBzAChjZodHRwOi8vYWlhLnN0YXJ0c3NsLmNvbS9jZXJ0
cy9zdWIuY2xhc3MxLnNlcnZlci5jYS5jcnQwNQYDVR0fBC4wLDAqoCigJoYkaHR0
cDovL2NybC5zdGFydHNzbC5jb20vY3J0MS1jcmwuY3JsMA0GCSqGSIb3DQEBCwUA
A4IBAQBi+qvxOod/KhcinEHidH+mdW4x2+Or/iHcem4yQxG+T4jjg+ukXzIg373V
G/tUiJcn+PXWFph5RW+zgm7FEFnRwrUnzAGtj8yvLCo3KM68NnV3/SV0gWPivvoB
JQeeV+EYDSl6/WB8wFfOtD+tpYliZ6HbWUBWzTNLNvugq/Qx6dcyaral+5p/Nerh
QW95ZuBWvhrNEYGjkP3+jeuruzanDqnN4r3e0j017bU9DPCOzzkLTd3N9EpN4QDi
AkYxiDMmBOWA0VkGLXbAwjQ/mNegGpo2ncyo9GUqCPp5bSmJ5W3w9vuaImUjXUN/
ZZFjY26ghgzyc5YKp7/3t6D7r9WW
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgIQE3tA5K13i2RovqNw1UvqFjANBgkqhkiG9w0BAQsFADCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsT
IlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0
YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgU2VydmVyIENBMB4X
DTE3MDMwMzAxNDIxM1oXDTE3MDYyMTAxNDIxM1owgZsxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1cmUgRGlnaXRhbCBD
ZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENvbSBDbGFzcyAxIFBy
aW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJlc3BvbmRlcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOZS4YlOabW9Dsdmc4ZOPB9Vcdku
0ZK/oY7qn/B2CjhAlaU8aUfgv/P2UbPVRZY3rac0BnA9auErCZH+jY16cZkEBdfp
NCSqnrkvpmtpOJzeZe+xcEqhu94kijclOsrMH10sKZqa4KgvpWabL+Od0tyz7qs1
i/hCtMgg1dKIk+Hekw0X7wyCJ7H4bPcHYgXLrYydBTZPx7CRVJkkEIwd2la3+Qqi
Ln23isy3xs4Ue3EANNVBCMTLPqnoFRvmRaKjOerG9Ly0o9VlPL6Bl2jRmJjOU8AD
H7s7WmyFBCXfuajZbiNjxmzZqKALMIFoqSn6/iznH6auw3zQpjTmXzO9Kr0CAwEA
AaOCAVAwggFMMA4GA1UdDwEB/wQEAwIDqDATBgNVHSUEDDAKBggrBgEFBQcDCTAP
BgkrBgEFBQcwAQUEAgUAMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFC5i23s+25mN
Zra4SzN6IEe5NMhOMB8GA1UdIwQYMBaAFOtCNNCYsKuf9BtrCPfMZC7vDixFMIGO
BggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRwOi8vb2NzcC5zdGFydHNz
bC5jb20vc3ViL2NsYXNzMS9zZXJ2ZXIvY2EwQgYIKwYBBQUHMAKGNmh0dHA6Ly9h
aWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuc2VydmVyLmNhLmNydDA1
BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9jcnQxLWNy
bC5jcmwwDQYJKoZIhvcNAQELBQADggEBAGL6q/E6h38qFyKcQeJ0f6Z1bjHb46v+
Idx6bjJDEb5PiOOD66RfMiDfvdUb+1SIlyf49dYWmHlFb7OCbsUQWdHCtSfMAa2P
zK8sKjcozrw2dXf9JXSBY+K++gElB55X4RgNKXr9YHzAV860P62liWJnodtZQFbN
M0s2+6Cr9DHp1zJqtqX7mn816uFBb3lm4Fa+Gs0RgaOQ/f6N66u7NqcOqc3ivd7S
PTXttT0M8I7POQtN3c30Sk3hAOICRjGIMyYE5YDRWQYtdsDCND+Y16AamjadzKj0
ZSoI+nltKYnlbfD2+5oiZSNdQ39lkWNjbqCGDPJzlgqnv/e3oPuv1ZY=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1893]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sun, 30 Apr 2017 12:47:48 GMT]
Etag: ["81B5901A83A6719642CCD139C49F89DE953DA849"]
Expires: [Sun, 30 Apr 2017 12:47:48 GMT]
Last-Modified: [Sun, 30 Apr 2017 12:48:12 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • OCSP response is valid for at least 8 hours (Microsoft)
  • OCSP response is available at least 8 hours before the current period expires or at ½ the validity if valid for more than 16 hours (Microsoft)
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is not yet valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com/sub/class1/server/ca (GET)Unknown

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/sub/class1/server/ca (GET)
Size: 1893 bytes (DER data)
Response time: 343.411147ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: StartCom Class 1 Primary Intermediate Server CA OCSP Responder
Issued by: StartCom Class 1 Primary Intermediate Server CA
Signing certificate validity: 2017-03-03 - 2017-06-21
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Unknown

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

URL used for GET request

http:/sub/class1/server/ca/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I00Jiwq5%2F0G2sI98xkLu8OLEUCAwcK4A%3D%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEQwQjBAMD4wPDAJBgUrDgMCGgUABBRlaIdPQHUPAWo0dWJeH1yT5aJtWAQU60I0
0Jiwq5/0G2sI98xkLu8OLEUCAwcK4A==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHYQoBAKCCB1owggdWBgkrBgEFBQcwAQEEggdHMIIHQzCCARqhgZ4wgZsxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENv
bSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJl
c3BvbmRlchgPMjAxNzA0MzAxMjQ4MTJaMGYwZDA8MAkGBSsOAwIaBQAEFGVoh09A
dQ8BajR1Yl4fXJPlom1YBBTrQjTQmLCrn/Qbawj3zGQu7w4sRQIDBwrgggAYDzIw
MTcwNDMwMTI0ODEyWqARGA8yMDE3MDUwNDEyNTgxMlowDQYJKoZIhvcNAQELBQAD
ggEBAG53auMQDWldPSgtilHI3UQZMWN4xVpY2EZnlZDxxxv87LXDbT4DPeeZVGdP
xICPCpheliBQ+h/BUJHXFk6jwfwEIbwMstk7TbEoTT8YnIK9YFB545HW4Kd2hoO9
pWCBwYfXUB56bQ/A6uybktXlaiiQUz2BqEqj00kfG4BZq5RCjtqBFCLQLYnyRRqx
7Xn9fvhkMusWCcMXqJCctso/LYcfW3oSIdUrDX0C36J/pYmIcLTRwOmuMHhHxiBR
YPff1XQT5suhMDZuLhZSYTkws0tRT8jYNb/XNy44E+q9gD62kRyC6lX9ZCQV92vE
TsKWym0MubYpzfMDt6eO2n1l6KWgggUNMIIFCTCCBQUwggPtoAMCAQICEBN7QOSt
d4tkaL6jcNVL6hYwDQYJKoZIhvcNAQELBQAwgYwxCzAJBgNVBAYTAklMMRYwFAYD
VQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0
aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQTAeFw0xNzAzMDMwMTQyMTNaFw0xNzA2
MjEwMTQyMTNaMIGbMQswCQYDVQQGEwJJTDEWMBQGA1UECgwNU3RhcnRDb20gTHRk
LjErMCkGA1UECwwiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzFH
MEUGA1UEAww+U3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBT
ZXJ2ZXIgQ0EgT0NTUCBSZXNwb25kZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDmUuGJTmm1vQ7HZnOGTjwfVXHZLtGSv6GO6p/wdgo4QJWlPGlH4L/z
9lGz1UWWN62nNAZwPWrhKwmR/o2NenGZBAXX6TQkqp65L6ZraTic3mXvsXBKobve
JIo3JTrKzB9dLCmamuCoL6Vmmy/jndLcs+6rNYv4QrTIINXSiJPh3pMNF+8Mgiex
+Gz3B2IFy62MnQU2T8ewkVSZJBCMHdpWt/kKoi59t4rMt8bOFHtxADTVQQjEyz6p
6BUb5kWioznqxvS8tKPVZTy+gZdo0ZiYzlPAAx+7O1pshQQl37mo2W4jY8Zs2aig
CzCBaKkp+v4s5x+mrsN80KY05l8zvSq9AgMBAAGjggFQMIIBTDAOBgNVHQ8BAf8E
BAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAMBgNV
HRMBAf8EAjAAMB0GA1UdDgQWBBQuYtt7PtuZjWa2uEszeiBHuTTITjAfBgNVHSME
GDAWgBTrQjTQmLCrn/Qbawj3zGQu7w4sRTCBjgYIKwYBBQUHAQEEgYEwfzA5Bggr
BgEFBQcwAYYtaHR0cDovL29jc3Auc3RhcnRzc2wuY29tL3N1Yi9jbGFzczEvc2Vy
dmVyL2NhMEIGCCsGAQUFBzAChjZodHRwOi8vYWlhLnN0YXJ0c3NsLmNvbS9jZXJ0
cy9zdWIuY2xhc3MxLnNlcnZlci5jYS5jcnQwNQYDVR0fBC4wLDAqoCigJoYkaHR0
cDovL2NybC5zdGFydHNzbC5jb20vY3J0MS1jcmwuY3JsMA0GCSqGSIb3DQEBCwUA
A4IBAQBi+qvxOod/KhcinEHidH+mdW4x2+Or/iHcem4yQxG+T4jjg+ukXzIg373V
G/tUiJcn+PXWFph5RW+zgm7FEFnRwrUnzAGtj8yvLCo3KM68NnV3/SV0gWPivvoB
JQeeV+EYDSl6/WB8wFfOtD+tpYliZ6HbWUBWzTNLNvugq/Qx6dcyaral+5p/Nerh
QW95ZuBWvhrNEYGjkP3+jeuruzanDqnN4r3e0j017bU9DPCOzzkLTd3N9EpN4QDi
AkYxiDMmBOWA0VkGLXbAwjQ/mNegGpo2ncyo9GUqCPp5bSmJ5W3w9vuaImUjXUN/
ZZFjY26ghgzyc5YKp7/3t6D7r9WW
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgIQE3tA5K13i2RovqNw1UvqFjANBgkqhkiG9w0BAQsFADCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsT
IlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0
YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgU2VydmVyIENBMB4X
DTE3MDMwMzAxNDIxM1oXDTE3MDYyMTAxNDIxM1owgZsxCzAJBgNVBAYTAklMMRYw
FAYDVQQKDA1TdGFydENvbSBMdGQuMSswKQYDVQQLDCJTZWN1cmUgRGlnaXRhbCBD
ZXJ0aWZpY2F0ZSBTaWduaW5nMUcwRQYDVQQDDD5TdGFydENvbSBDbGFzcyAxIFBy
aW1hcnkgSW50ZXJtZWRpYXRlIFNlcnZlciBDQSBPQ1NQIFJlc3BvbmRlcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOZS4YlOabW9Dsdmc4ZOPB9Vcdku
0ZK/oY7qn/B2CjhAlaU8aUfgv/P2UbPVRZY3rac0BnA9auErCZH+jY16cZkEBdfp
NCSqnrkvpmtpOJzeZe+xcEqhu94kijclOsrMH10sKZqa4KgvpWabL+Od0tyz7qs1
i/hCtMgg1dKIk+Hekw0X7wyCJ7H4bPcHYgXLrYydBTZPx7CRVJkkEIwd2la3+Qqi
Ln23isy3xs4Ue3EANNVBCMTLPqnoFRvmRaKjOerG9Ly0o9VlPL6Bl2jRmJjOU8AD
H7s7WmyFBCXfuajZbiNjxmzZqKALMIFoqSn6/iznH6auw3zQpjTmXzO9Kr0CAwEA
AaOCAVAwggFMMA4GA1UdDwEB/wQEAwIDqDATBgNVHSUEDDAKBggrBgEFBQcDCTAP
BgkrBgEFBQcwAQUEAgUAMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFC5i23s+25mN
Zra4SzN6IEe5NMhOMB8GA1UdIwQYMBaAFOtCNNCYsKuf9BtrCPfMZC7vDixFMIGO
BggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzABhi1odHRwOi8vb2NzcC5zdGFydHNz
bC5jb20vc3ViL2NsYXNzMS9zZXJ2ZXIvY2EwQgYIKwYBBQUHMAKGNmh0dHA6Ly9h
aWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuc2VydmVyLmNhLmNydDA1
BgNVHR8ELjAsMCqgKKAmhiRodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9jcnQxLWNy
bC5jcmwwDQYJKoZIhvcNAQELBQADggEBAGL6q/E6h38qFyKcQeJ0f6Z1bjHb46v+
Idx6bjJDEb5PiOOD66RfMiDfvdUb+1SIlyf49dYWmHlFb7OCbsUQWdHCtSfMAa2P
zK8sKjcozrw2dXf9JXSBY+K++gElB55X4RgNKXr9YHzAV860P62liWJnodtZQFbN
M0s2+6Cr9DHp1zJqtqX7mn816uFBb3lm4Fa+Gs0RgaOQ/f6N66u7NqcOqc3ivd7S
PTXttT0M8I7POQtN3c30Sk3hAOICRjGIMyYE5YDRWQYtdsDCND+Y16AamjadzKj0
ZSoI+nltKYnlbfD2+5oiZSNdQ39lkWNjbqCGDPJzlgqnv/e3oPuv1ZY=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1893]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sun, 30 Apr 2017 12:47:48 GMT]
Etag: ["81B5901A83A6719642CCD139C49F89DE953DA849"]
Expires: [Sun, 30 Apr 2017 12:47:48 GMT]
Last-Modified: [Sun, 30 Apr 2017 12:48:12 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP requests is smaller than 255 bytes
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • OCSP response is valid for at least 8 hours (Microsoft)
  • OCSP response is available at least 8 hours before the current period expires or at ½ the validity if valid for more than 16 hours (Microsoft)
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is not yet valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

StartCom Class 1 Primary Intermediate Server CA (CA Certificate)

Certificate details for StartCom Class 1 Primary Intermediate Server CA (At position 1 in certificate chain)
Serial number:
hex: 17153d9eab3fbf
int: 6497278863556543
Issued by: StartCom Certification Authority
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: StartCom Ltd.
Organization unit: Secure Digital Certificate Signing
Country: IL
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.startssl.com/sfsca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startssl.com/sfsca.crl
Size: 952 bytes (DER data)
Response time: 4.243649ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 7

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.0.12
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-92-30.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Content-Length: [952]
Content-Type: [application/pkix-crl]
Date: [Sun, 30 Apr 2017 12:47:47 GMT]
Last-Modified: [Wed, 12 Apr 2017 08:39:01 GMT]
Server: [nginx/1.0.12]
X-Cache: [TCP_MEM_HIT from a23-219-92-30.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.startssl.com/ca (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/ca (GET)
Size: 1760 bytes (DER data)
Response time: 225.750886ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

URL used for GET request

http:/ca/MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG3AoBAKCCBtUwggbRBgkrBgEFBQcwAQEEggbCMIIGvjCByKFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzA0MjkxMDEyMjdaMGowaDBAMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIH
FxU9nqs/v4AAGA8yMDE3MDQyOTEwMTIyN1qgERgPMjAxNzA1MDMxMDIyMjdaMA0G
CSqGSIb3DQEBBQUAA4IBAQAE7UOmfQFqgZShayww7KfJf4ImqgwBqWONd4p3qe+v
T7WiRVo7QpJwHM2xRhngroOirdWbm8846+gkYc5YylwHE1M7r5iWs6awk8GZmqDn
yYfWu4pbQ1QclaC30J/jtyjGRv/JcQlEx/0ozJRzjvhpp7x63OUly+L7h2R7mbEk
YV5veV7xLeRvfrI6DfcGXZlVMMyO7eClGWZXWDBAvstHmudrIzg40QSOMGktKYIk
MFPtlW8vrgjECe2EmoRzexX1PDjoMfQpNTSMHq6gTzDVHpuM71+2kmsq8oY0zFA3
eU6V90Gpsxff2RtYdYNCcmwBtxnhcip60h+n7s00jyuDoIIE2zCCBNcwggTTMIIC
u6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUg
RGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFaFw0xNzA5MjAw
MDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAw
HgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73/KGBfj5JWHFX
jL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYlsXO4fPd2zuNXq
9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7frPplzXZkcG2l
9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMInQQwS6HgUU63e
PBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch2fITwUxkXLsh
EuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOBhDCBgTALBgNV
HQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/BAIwADAPBgkr
BgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEmn9cqHTAfBgNV
HSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0BAQUFAAOCAgEA
LbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56nTWABnde9aW5
W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEKOvpHVriq2Zne
su8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQBwbK/L1KepHA8
3G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5KvVUFxjQ6xXV
vJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHuwbM1WAPq2V0n
pFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lXITW2aB23z5+1
YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6ZgM+xBu7yP5L
+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme1iPneOUenpnd
Ln4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0bococQpeHZ35U
HuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMUmSEqfLIBZONz
HxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1760]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sun, 30 Apr 2017 12:47:48 GMT]
Etag: ["86C59021B24795CABB2558283A7D5418D0BAF8F0"]
Expires: [Sun, 30 Apr 2017 12:47:48 GMT]
Last-Modified: [Sat, 29 Apr 2017 10:12:27 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MEM_HIT from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP requests is smaller than 255 bytes
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.startssl.com/ca (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.startssl.com/ca (POST)
Size: 1760 bytes (DER data)
Response time: 435.062031ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: StartCom OCSP Responder
Issued by: StartCom Certification Authority
Signing certificate validity: 2016-09-20 - 2017-09-20
Signing certificate algorithm: SHA1-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Server Software: nginx/1.7.2
Content Delivery Network (CDN): Akamai
Cache Information: TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
MEgwRjBEMEIwQDAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvv
GqRAW6UXaYcwyjRoQ9BBrvICBxcVPZ6rP78=
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIG3AoBAKCCBtUwggbRBgkrBgEFBQcwAQEEggbCMIIGvjCByKFJMEcxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAwHgYDVQQDExdTdGFydENv
bSBPQ1NQIFJlc3BvbmRlchgPMjAxNzA0MzAxMDEyMjVaMGowaDBAMAkGBSsOAwIa
BQAEFEFzptPY32rNGR6Ja+flYjkwcGk1BBROC+8apEBbpRdphzDKNGhD0EGu8gIH
FxU9nqs/v4AAGA8yMDE3MDQzMDEwMTIyNVqgERgPMjAxNzA1MDQxMDIyMjVaMA0G
CSqGSIb3DQEBBQUAA4IBAQCBpjtNaLTulFCoVwdRPl6Mwc7rxOmSjq6RRSEPzdcu
RTkw5QoV2ghy5D3KGZ6h0mBiG8b4L6psiSG3kcpZ6BNA6nLxD0ISQiVAheuyrAXQ
t3hZogJjXPkI5Frg1BWzOjN0c7NfvFJw4C7qLNa/t/G2Ji+ss11BLt/8plAvBPDt
/6enq6Whn2wZKVGeNFjTIUwbrghzDsj25ybVOntcaXFTv6JrAeKldbq+Ct8yvbZE
HQ2SvNdp/oo245MupPt+IwH6vHDI0Hh2HmXibzg6jqPo2rdRngzam1tUSTRYMl3O
uRDHNVodpd5cfhWqEUywtS60IRnaZFVe3DZQ5evhakBmoIIE2zCCBNcwggTTMIIC
u6ADAgECAhB0G1CHgU03TwwiPka2dpOyMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUg
RGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMSkwJwYDVQQDEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xNjA5MjAwMDAxMDFaFw0xNzA5MjAw
MDAxMDFaMEcxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSAw
HgYDVQQDExdTdGFydENvbSBPQ1NQIFJlc3BvbmRlcjCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAL67V5Yt7+ta/FzjtC7S1XWouzbVRn73/KGBfj5JWHFX
jL1oKcHHeyuiQ46IawZ3TKMIZafle69rt2/J+q+K1AcF+yWfnYlsXO4fPd2zuNXq
9mLqlxwsYYLGwYo51ZY09YMenMo2hqcnE2jN4GNhW8HA7M5b1D7frPplzXZkcG2l
9imHwapl+RItDefLqTYvoGXZE8JhefiFx1SkYwZ9Da9hMjWavMInQQwS6HgUU63e
PBAj6oS9IBvEeGzFGeXeRKPOAtlwhsA1787V5OeamA5Ms2/8IEch2fITwUxkXLsh
EuQpb9HqR0vPpWnCd5/SCWIRtNQV5XCTU6VyFcru1f8CAwEAAaOBhDCBgTALBgNV
HQ8EBAMCA6gwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDAYDVR0TAQH/BAIwADAPBgkr
BgEFBQcwAQUEAgUAMB0GA1UdDgQWBBRfdFkMIvy5C8QhXMZu/hEmn9cqHTAfBgNV
HSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jANBgkqhkiG9w0BAQUFAAOCAgEA
LbOpeDVprhn5SMPJuyRZGpe0vRR5FhCPmjJyCiGwi1ddVI++Eg56nTWABnde9aW5
W64x0MWuoEhg1+FOh5D2fIEztbKQKGQ8hDiQGTSz9Gy9KrZAzaEKOvpHVriq2Zne
su8W2w2cPahu09mY6ivtwJF5jVdLA3iG1X4xtiXUzdBqG+cQiWQBwbK/L1KepHA8
3G1S8xvOSWkBJQwZ/plkrTXNUARa3nOhGvsQKw6OcAo3+FdfrTn5KvVUFxjQ6xXV
vJcSK46LbD5NAD3hp8N3OJVLfvIpHnVVBcIBbhNR4kBe+GNSnGHuwbM1WAPq2V0n
pFD1WWYWHdYwVu4z9yAa2vhoYd7S/6eUhVH8FgCafBcQVoTuH2lXITW2aB23z5+1
YOedwbnb2B2j7T8iIgYG8zNJFoOa0Ue4mXRR7KH0kyanxVSPjtn6ZgM+xBu7yP5L
+W2rWCjPPRwbLxdWaCuPvJ3EsUONbcI0OtY8FbKr01Qurk7i3Qme1iPneOUenpnd
Ln4cNb6gKZ8b1rRB+AlJCm7DnEDyarEEd62wzRFMb+djTU5SPZ0bococQpeHZ35U
HuvFisJndbw17UkiLu8Dhivq6BaskcehToq0bhyewa8Pr1s+zcMUmSEqfLIBZONz
HxtCF0DFldDA5OJB8Y4iOMGSMxKxsKhAaBWolVceORM=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE0zCCArugAwIBAgIQdBtQh4FNN08MIj5GtnaTsjANBgkqhkiG9w0BAQUFADB9
MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMi
U2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzEpMCcGA1UEAxMgU3Rh
cnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTYwOTIwMDAwMTAxWhcN
MTcwOTIwMDAwMTAxWjBHMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20g
THRkLjEgMB4GA1UEAxMXU3RhcnRDb20gT0NTUCBSZXNwb25kZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+u1eWLe/rWvxc47Qu0tV1qLs21UZ+9/yh
gX4+SVhxV4y9aCnBx3srokOOiGsGd0yjCGWn5Xuva7dvyfqvitQHBfsln52JbFzu
Hz3ds7jV6vZi6pccLGGCxsGKOdWWNPWDHpzKNoanJxNozeBjYVvBwOzOW9Q+36z6
Zc12ZHBtpfYph8GqZfkSLQ3ny6k2L6Bl2RPCYXn4hcdUpGMGfQ2vYTI1mrzCJ0EM
Euh4FFOt3jwQI+qEvSAbxHhsxRnl3kSjzgLZcIbANe/O1eTnmpgOTLNv/CBHIdny
E8FMZFy7IRLkKW/R6kdLz6Vpwnef0gliEbTUFeVwk1OlchXK7tX/AgMBAAGjgYQw
gYEwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoGCCsGAQUFBwMJMAwGA1UdEwEB/wQC
MAAwDwYJKwYBBQUHMAEFBAIFADAdBgNVHQ4EFgQUX3RZDCL8uQvEIVzGbv4RJp/X
Kh0wHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwDQYJKoZIhvcNAQEF
BQADggIBAC2zqXg1aa4Z+UjDybskWRqXtL0UeRYQj5oycgohsItXXVSPvhIOep01
gAZ3XvWluVuuMdDFrqBIYNfhToeQ9nyBM7WykChkPIQ4kBk0s/RsvSq2QM2hCjr6
R1a4qtmZ3rLvFtsNnD2obtPZmOor7cCReY1XSwN4htV+MbYl1M3QahvnEIlkAcGy
vy9SnqRwPNxtUvMbzklpASUMGf6ZZK01zVAEWt5zoRr7ECsOjnAKN/hXX605+Sr1
VBcY0OsV1byXEiuOi2w+TQA94afDdziVS37yKR51VQXCAW4TUeJAXvhjUpxh7sGz
NVgD6tldJ6RQ9VlmFh3WMFbuM/cgGtr4aGHe0v+nlIVR/BYAmnwXEFaE7h9pVyE1
tmgdt8+ftWDnncG529gdo+0/IiIGBvMzSRaDmtFHuJl0Ueyh9JMmp8VUj47Z+mYD
PsQbu8j+S/ltq1gozz0cGy8XVmgrj7ydxLFDjW3CNDrWPBWyq9NULq5O4t0JntYj
53jlHp6Z3S5+HDW+oCmfG9a0QfgJSQpuw5xA8mqxBHetsM0RTG/nY01OUj2dG6HK
HEKXh2d+VB7rxYrCZ3W8Ne1JIi7vA4Yr6ugWrJHHoU6KtG4cnsGvD69bPs3DFJkh
KnyyAWTjcx8bQhdAxZXQwOTiQfGOIjjBkjMSsbCoQGgVqJVXHjkT
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [max-age=0, no-cache, no-store]
Content-Length: [1760]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Sun, 30 Apr 2017 12:47:48 GMT]
Etag: ["B868890B171522978B2ABC7116D5EA112D95DBC4"]
Expires: [Sun, 30 Apr 2017 12:47:48 GMT]
Last-Modified: [Sun, 30 Apr 2017 10:12:25 GMT]
Pragma: [no-cache]
Server: [nginx/1.7.2]
X-Cache: [TCP_MISS from a23-219-92-55.deploy.akamaitechnologies.com (AkamaiGHost/8.3.2-19674918) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

StartCom Certification Authority (CA Certificate)

Certificate details for StartCom Certification Authority (At position 2 in certificate chain)
Serial number:
hex: 1
int: 1
Issued by: StartCom Certification Authority
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: StartCom Ltd.
Organization unit: Secure Digital Certificate Signing
Country: IL
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

This is a self signed certificate

Certificate Revocation List (CRL)

This CRL was cached at
http://cert.startcom.org/sfsca-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://cert.startcom.org/sfsca-crl.crl
Size: 952 bytes (DER data)
Response time: 691.381664ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 7

Relevant server response headers

Date:
Last Modified:

Server and network information

Server Software: nginx/1.9.14

Raw CRL response headers

Accept-Ranges: [bytes]
Connection: [keep-alive]
Content-Length: [952]
Content-Type: [application/pkix-crl]
Date: [Sun, 30 Apr 2017 12:47:48 GMT]
Etag: ["58ede862-3b8"]
Last-Modified: [Wed, 12 Apr 2017 08:42:10 GMT]
Server: [nginx/1.9.14]
  • Content-Type in response is set to 'application/pkix-crl (RFC 5280, section 4.2.1.13)'
  • This CRL file is DER encoded
  • Issuer field is byte-for-byte equivalent with issuers subject
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • Expires cache header not set (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is the same as the NextUpdate field (RFC 5019 section 6.2)
This CRL was cached at
http://crl.startcom.org/sfsca-crl.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.startcom.org/sfsca-crl.crl
Size: 0 bytes (DER data)
Response time: 0s

Raw CRL response headers

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.