CRL & OCSP report for www.entrust.net (Entrust, Inc.)

www.entrust.net

This certificate was cached at
Certificate details for www.entrust.net (At position 0 in certificate chain)
Serial number:
hex: 17662f80000000054cca1d0
int: 452605623243722817962549712
Issued by: Entrust Certification Authority - L1M
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Company registration number: 115868500
Organization: Entrust, Inc.
State / Province: Ontario
Locality: Kanata
Country: CA
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

View complete certificate details for www.entrust.net.

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/level1m.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/level1m.crl
Size: 115237 bytes (DER data)
Response time: 392.84541ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 2459

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_HIT from a204-2-193-133.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.1-18764048) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [115237]
Content-Type: [application/x-pkcs7-crl]
Date: [Fri, 20 Jan 2017 19:20:49 GMT]
Expires: [Fri, 20 Jan 2017 19:20:49 GMT]
Last-Modified: [Fri, 20 Jan 2017 19:00:02 GMT]
Pragma: [no-cache]
X-Cache: [TCP_HIT from a204-2-193-133.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.1-18764048) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than seven days old, CRLs must be updated and reissued at least every seven days (Mozilla Maintenance Policy section 3)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 1937 bytes (DER data)
Response time: 17.012456ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1M
Signing certificate validity: 2014-12-09 - 2017-12-09
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 24m9s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_REFRESH_MISS from a184-26-44-14.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (S)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQnuEQcScL/kljKed+RzpzFYOq9kwQUw/fQ
tSowra8NkSFwOVTdvIlwxzoCDAF2YvgAAAAAVMyh0A==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHjQoBAKCCB4YwggeCBgkrBgEFBQcwAQEEggdzMIIHbzCCAVKhgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxNCBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMU0xDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDEyMjE3MjExM1owbzBtMEUwCQYFKw4DAhoFAAQUJ7hEHEnC
/5JYynnfkc6cxWDqvZMEFMP30LUqMK2vDZEhcDlU3byJcMc6AgwBdmL4AAAAAFTM
odCAABgPMjAxNzAxMjIxNzIxMTNaoBEYDzIwMTcwMTI5MTcyMTEzWjANBgkqhkiG
9w0BAQsFAAOCAQEAtziY2tzQPL9umpiiTP1EeHCGbcKgHTvRrymT4L4jDL2EKFPg
GricYQOFOg48gv2gS41j4GrBV+bm7El7TVpYM4Q3ZYh79pFr3SHpkXdi5UpQ3MMI
g2KfgqctZULc10R/UKElpn9a7Rtv2mB+LAAQzyk4x0RcP3nQNllvWlqwV0oiJ0LL
KJloQ0fHvglsFTdTXRjnPG1cPyOCbppCo76NcWiKK/SiiHResdbRjNJ/mYWlDNWX
R3MwBtCQAS45yjDp0dGz3v9NOYNc0FJPN+zFCGv/W4B3SlIKIe9JFDAyxiWFG+mu
mJmikK61RrQAPkZ1qh3avQoGSkvnxHAZi5votqCCBQEwggT9MIIE+TCCA+GgAwIB
AgINANqFcngAAAAAVD/kTTANBgkqhkiG9w0BAQsFADCBujELMAkGA1UEBhMCVVMx
FjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVz
dC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDE0IEVudHJ1c3QsIElu
Yy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxTTAeFw0xNDEyMDkyMDI2NTBaFw0x
NzEyMDkyMDU2NTBaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwg
SW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5
MDcGA1UECxMwKGMpIDIwMTQgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVk
IHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmljYXRpb24gQXV0aG9y
aXR5IC0gTDFNMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V
7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2E
No5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZ
ickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGG
og6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdR
nGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6zCB6DALBgNVHQ8EBAMC
B4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAzBggrBgEF
BQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0MDMG
A1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwuZW50cnVzdC5uZXQvbGV2ZWwxbS5j
cmwwHwYDVR0jBBgwFoAUw/fQtSowra8NkSFwOVTdvIlwxzowHQYDVR0OBBYEFNUC
BLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEB
AFSh86jHNHEN0D6w0wSFXODf3YYGsPLnb+g6htal0rFOORVLE3XcnA0MrZGgtkZS
/f+vANGm0cN048ry+nT85m3ZqcfQHsnDsXfBU5/seLTNWqwjWOqdcwxXG173rk4/
7PMqWxgKw+rSsftwNpNgxw+fLZdV3WA8j9d3EIY7nFlpogsUM1x8FCizkbD7LUfC
RTEDIXYamntZCKfhKGDhIhlxqD2bPJ+GPHIbX61uuTtoLM82HJ2U2SP0RchhRh2U
a0WlUlMT0nJt+GUYfAVSRL6cbBVXeqIqi9bPVzh7AUD5AI0nA9SUjyjja5ZeKsI6
xPGLK3oHUirdnp0YIzPq42Y=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE+TCCA+GgAwIBAgINANqFcngAAAAAVD/kTTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDE0
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxTTAeFw0xNDEy
MDkyMDI2NTBaFw0xNzEyMDkyMDU2NTBaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTQgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFNMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6zCB
6DALBgNVHQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEF
BAIFADAzBggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVu
dHJ1c3QubmV0MDMGA1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwuZW50cnVzdC5u
ZXQvbGV2ZWwxbS5jcmwwHwYDVR0jBBgwFoAUw/fQtSowra8NkSFwOVTdvIlwxzow
HQYDVR0OBBYEFNUCBLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZI
hvcNAQELBQADggEBAFSh86jHNHEN0D6w0wSFXODf3YYGsPLnb+g6htal0rFOORVL
E3XcnA0MrZGgtkZS/f+vANGm0cN048ry+nT85m3ZqcfQHsnDsXfBU5/seLTNWqwj
WOqdcwxXG173rk4/7PMqWxgKw+rSsftwNpNgxw+fLZdV3WA8j9d3EIY7nFlpogsU
M1x8FCizkbD7LUfCRTEDIXYamntZCKfhKGDhIhlxqD2bPJ+GPHIbX61uuTtoLM82
HJ2U2SP0RchhRh2Ua0WlUlMT0nJt+GUYfAVSRL6cbBVXeqIqi9bPVzh7AUD5AI0n
A9SUjyjja5ZeKsI6xPGLK3oHUirdnp0YIzPq42Y=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=1449]
Content-Length: [1937]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 23 Jan 2017 00:52:07 GMT]
Etag: ["44EEB9E701CFB7326DD693C1895560F3E96C78C6"]
Expires: [Mon, 23 Jan 2017 01:16:16 GMT]
Last-Modified: [Sun, 22 Jan 2017 17:21:13 GMT]
X-Cache: [TCP_REFRESH_MISS from a184-26-44-14.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (S)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 1937 bytes (DER data)
Response time: 5.384315ms
Signature algorithm: SHA256WithRSA
Signature type: CA Deligated
Signed by: OCSP1
Issued by: Entrust Certification Authority - L1M
Signing certificate validity: 2014-12-09 - 2017-12-09
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 36m53s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a184-26-44-14.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (-)

URL used for GET request

http:/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCDAF2YvgAAAAAVMyh0A%3D%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQnuEQcScL/kljKed+RzpzFYOq9kwQUw/fQ
tSowra8NkSFwOVTdvIlwxzoCDAF2YvgAAAAAVMyh0A==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHjQoBAKCCB4YwggeCBgkrBgEFBQcwAQEEggdzMIIHbzCCAVKhgc0wgcoxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAxNCBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxLjAsBgNVBAMT
JUVudHJ1c3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBMMU0xDjAMBgNVBAMT
BU9DU1AxGA8yMDE3MDEyMjE5MTYxM1owbzBtMEUwCQYFKw4DAhoFAAQUJ7hEHEnC
/5JYynnfkc6cxWDqvZMEFMP30LUqMK2vDZEhcDlU3byJcMc6AgwBdmL4AAAAAFTM
odCAABgPMjAxNzAxMjIxOTE2MTNaoBEYDzIwMTcwMTI5MTkxNjEzWjANBgkqhkiG
9w0BAQsFAAOCAQEAyK7VesIGi8KZabijtMzSTwBHPJgi7gbTiJI86XYxCR4ZELbG
D4bL95/7gaTvYV/x14NYfv882jOSIB0mHfwFLqdPtIK2JHKq8IAA3tEFN+CJJxrX
32bDdiUjJRtmyKqHPJaQj7kriUaAymsBzsnp2dBn0jrLWnPwyC2LIo60SyOSmYib
87FxT6h+oH9p8ZskwCIh1Dz5EbRAM4+pmlb6yv3cGaBRChE3QNsh3j0LCddxB2Jo
rmp99jZ7qAye57oUvwZc77cb8uFs1LdTOqjLsWyBBvdzOJSAtjdyl5rip4afLdfx
GcY08C47Hm0MQ3B9j45bA/An2kKVmyNKLNwhi6CCBQEwggT9MIIE+TCCA+GgAwIB
AgINANqFcngAAAAAVD/kTTANBgkqhkiG9w0BAQsFADCBujELMAkGA1UEBhMCVVMx
FjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1NlZSB3d3cuZW50cnVz
dC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDE0IEVudHJ1c3QsIElu
Yy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UEAxMlRW50cnVzdCBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxTTAeFw0xNDEyMDkyMDI2NTBaFw0x
NzEyMDkyMDU2NTBaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwg
SW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5
MDcGA1UECxMwKGMpIDIwMTQgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVk
IHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmljYXRpb24gQXV0aG9y
aXR5IC0gTDFNMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V
7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2E
No5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZ
ickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGG
og6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdR
nGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6zCB6DALBgNVHQ8EBAMC
B4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAzBggrBgEF
BQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVudHJ1c3QubmV0MDMG
A1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwuZW50cnVzdC5uZXQvbGV2ZWwxbS5j
cmwwHwYDVR0jBBgwFoAUw/fQtSowra8NkSFwOVTdvIlwxzowHQYDVR0OBBYEFNUC
BLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEB
AFSh86jHNHEN0D6w0wSFXODf3YYGsPLnb+g6htal0rFOORVLE3XcnA0MrZGgtkZS
/f+vANGm0cN048ry+nT85m3ZqcfQHsnDsXfBU5/seLTNWqwjWOqdcwxXG173rk4/
7PMqWxgKw+rSsftwNpNgxw+fLZdV3WA8j9d3EIY7nFlpogsUM1x8FCizkbD7LUfC
RTEDIXYamntZCKfhKGDhIhlxqD2bPJ+GPHIbX61uuTtoLM82HJ2U2SP0RchhRh2U
a0WlUlMT0nJt+GUYfAVSRL6cbBVXeqIqi9bPVzh7AUD5AI0nA9SUjyjja5ZeKsI6
xPGLK3oHUirdnp0YIzPq42Y=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIE+TCCA+GgAwIBAgINANqFcngAAAAAVD/kTTANBgkqhkiG9w0BAQsFADCBujEL
MAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsTH1Nl
ZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAyMDE0
IEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwGA1UE
AxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxTTAeFw0xNDEy
MDkyMDI2NTBaFw0xNzEyMDkyMDU2NTBaMIHKMQswCQYDVQQGEwJVUzEWMBQGA1UE
ChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9s
ZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMTQgRW50cnVzdCwgSW5jLiAtIGZv
ciBhdXRob3JpemVkIHVzZSBvbmx5MS4wLAYDVQQDEyVFbnRydXN0IENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5IC0gTDFNMQ4wDAYDVQQDEwVPQ1NQMTCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7
txufoeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpv
adk4wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzao
VKc2wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s
/SlOYaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0D
ePFbMjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6zCB
6DALBgNVHQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEF
BAIFADAzBggrBgEFBQcBAQQnMCUwIwYIKwYBBQUHMAGGF2h0dHA6Ly9vY3NwLmVu
dHJ1c3QubmV0MDMGA1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwuZW50cnVzdC5u
ZXQvbGV2ZWwxbS5jcmwwHwYDVR0jBBgwFoAUw/fQtSowra8NkSFwOVTdvIlwxzow
HQYDVR0OBBYEFNUCBLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZI
hvcNAQELBQADggEBAFSh86jHNHEN0D6w0wSFXODf3YYGsPLnb+g6htal0rFOORVL
E3XcnA0MrZGgtkZS/f+vANGm0cN048ry+nT85m3ZqcfQHsnDsXfBU5/seLTNWqwj
WOqdcwxXG173rk4/7PMqWxgKw+rSsftwNpNgxw+fLZdV3WA8j9d3EIY7nFlpogsU
M1x8FCizkbD7LUfCRTEDIXYamntZCKfhKGDhIhlxqD2bPJ+GPHIbX61uuTtoLM82
HJ2U2SP0RchhRh2Ua0WlUlMT0nJt+GUYfAVSRL6cbBVXeqIqi9bPVzh7AUD5AI0n
A9SUjyjja5ZeKsI6xPGLK3oHUirdnp0YIzPq42Y=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=2213]
Content-Length: [1937]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Mon, 23 Jan 2017 00:52:07 GMT]
Etag: ["BEEB84F726B4C4F03CC2549E41ACEFD6D82F852A"]
Expires: [Mon, 23 Jan 2017 01:29:00 GMT]
Last-Modified: [Sun, 22 Jan 2017 19:16:13 GMT]
X-Cache: [TCP_MEM_HIT from a184-26-44-14.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • ThisUpdate is less than four days old, OCSP information must be updated at least every four days (Mozilla & Baseline Requirements)
  • The NextUpdate field is not more than ten days beyond the value of the ThisUpdate field (Mozilla & Baseline Requirements)
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Certification Authority - L1M (CA Certificate)

This certificate was cached at
Certificate details for Entrust Certification Authority - L1M (At position 1 in certificate chain)
Serial number:
hex: 61a1e7d20000000051d366a6
int: 30215777750102225331854468774
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2014 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

Certificate Revocation List (CRL)

This CRL was cached at
http://crl.entrust.net/g2ca.crl

CRL information

Source: CRL Distribution Points in Certificate
Location: http://crl.entrust.net/g2ca.crl
Size: 1224 bytes (DER data)
Response time: 119.07263ms
This update:
Next update:
Revoked: No
Revoked certificates in CRL: 14

Relevant server response headers

Date:
Last Modified:
Expires:

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a23-219-88-101.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.1-18764048) (-)

Raw CRL response headers

Accept-Ranges: [bytes]
Cache-Control: [no-cache]
Content-Length: [1224]
Content-Type: [application/x-pkcs7-crl]
Date: [Mon, 23 Jan 2017 04:58:53 GMT]
Expires: [Mon, 23 Jan 2017 04:58:53 GMT]
Last-Modified: [Thu, 05 Jan 2017 20:27:50 GMT]
Pragma: [no-cache]
X-Cache: [TCP_MEM_HIT from a23-219-88-101.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.1-18764048) (-)]
X-Frame-Options: [DENY]
  • Content-Type in response is set 'application/x-pkcs7-crl' and should be replaced with 'application/pkix-crl' (RFC 5280, section 4.2.1.13)
  • This CRL file is DER encoded
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is not the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Online Certificate Status Protocol (OCSP)

This OCSP response was cached at
http://ocsp.entrust.net (POST)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (POST)
Size: 1991 bytes (DER data)
Response time: 104.55325ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 4m58s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a165-254-48-146.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (A)

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCDGGh59IAAAAAUdNmpg==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHwwoBAKCCB7wwgge4BgkrBgEFBQcwAQEEggepMIIHpTCCAW2hgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDExOTIyMTE1
MVowbzBtMEUwCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgxhoefSAAAAAFHTZqaAABgPMjAxNzAxMTkyMjExNTFa
oBEYDzIwMTcwMTI2MjIxMTUxWjANBgkqhkiG9w0BAQUFAAOCAQEAPbMlxzGNKADJ
Lab9q46ESrb0ktKXNoSxXk6uK3jISNVVYrAuH3kkr3+NQLMEa5V5hspIjAIGFRib
v/JvKFGNhBEIsorO/vJB4DjcwRVXXXtds2ZP8WRVR96yThPYcedAFhDBFcfNnfKp
wqRy5JfSzWI9rW55BmO5p/WZUMo2KYl2ggPaWWq2fNk+K36KpGGCkKRLtr06WNPR
EDSJdMAhBx5Dx2Lnr7nnv2c6h8NHNYdOE1pMlFoGimzERZxxJ0zXTAYC/dLSKfvM
6sLNNL5KCGtTgvhnMYswtrQWy0Y7De+wdF6j20iszPB/Pv1xYnrknZBIrKHnF6k1
Uo7mHE9qLKCCBRwwggUYMIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqG
SIb3DQEBCwUAMIG+MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5j
LjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcG
A1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVz
ZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHkgLSBHMjAeFw0xNTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMG
A1UEAxMcRW50cnVzdCBWYWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txuf
oeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4
wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2
wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlO
YaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFb
MjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TAL
BgNVHQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIF
ADAwBgNVHR8EKTAnMCWgI6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2Eu
Y3JsMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50
cnVzdC5uZXQwHwYDVR0jBBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0O
BBYEFNUCBLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQEL
BQADggEBADOiWIKLGjQVR7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWY
DPS/xmPXPMc34VQjqkRFQmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiX
p1ncZctaMa6Jsa6X/DMdB6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAP
fiIkI9zXoL6UeMPISDUk+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurN
yrrGBQaFoZEy+jEKOn0XOph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzs
sKEEqnkXHHoFz9QilxJrgbcV/S1hz9Q=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=298]
Content-Length: [1991]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Fri, 20 Jan 2017 19:20:49 GMT]
Etag: ["BE7CF19706C56F1DFA8BC2A410A4039752468E1A"]
Expires: [Fri, 20 Jan 2017 19:25:47 GMT]
Last-Modified: [Thu, 19 Jan 2017 22:11:51 GMT]
X-Cache: [TCP_MEM_HIT from a165-254-48-146.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (A)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)
This OCSP response was cached at
http://ocsp.entrust.net (GET)Good

OCSP response information

Source: Authority Information Access in Certificate
Location: http://ocsp.entrust.net (GET)
Size: 1991 bytes (DER data)
Response time: 104.665716ms
Signature algorithm: SHA1WithRSA
Signature type: CA Deligated
Signed by: Entrust Validation Authority
Issued by: Entrust Root Certification Authority - G2
Signing certificate validity: 2015-06-04 - 2017-06-04
Signing certificate algorithm: SHA256-RSA
Reported statuses: 1
This update:
Next update:
Produced at:
Status: Good

Relevant server response headers

Date:
Last Modified:
Expires:
Cache Control Max-age: 39m14s

Server and network information

Content Delivery Network (CDN): Akamai
Cache Information: TCP_MEM_HIT from a165-254-48-146.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (-)

URL used for GET request

http:/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCDGGh59IAAAAAUdNmpg%3D%3D

Raw OCSP request (PEM encoded)

-----BEGIN OCSP REQUEST-----
ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanIm
etAe733nO2lR1GyNn5ASZqsCDGGh59IAAAAAUdNmpg==
-----END OCSP REQUEST-----

Raw OCSP response (PEM encoded)

-----BEGIN OCSP RESPONSE-----
MIIHwwoBAKCCB7wwgge4BgkrBgEFBQcwAQEEggepMIIHpTCCAW2hgegwgeUxCzAJ
BgNVBAYTAlVTMRYwFAYDVQQKEw1FbnRydXN0LCBJbmMuMSgwJgYDVQQLEx9TZWUg
d3d3LmVudHJ1c3QubmV0L2xlZ2FsLXRlcm1zMTkwNwYDVQQLEzAoYykgMjAwOSBF
bnRydXN0LCBJbmMuIC0gZm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxMjAwBgNVBAMT
KUVudHJ1c3QgUm9vdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMSUwIwYD
VQQDExxFbnRydXN0IFZhbGlkYXRpb24gQXV0aG9yaXR5GA8yMDE3MDEyMDE4NTIy
MlowbzBtMEUwCQYFKw4DAhoFAAQUy1zQsw7wYR3nFo4O9IiYQVtCJ8sEFGpyJnrQ
Hu995ztpUdRsjZ+QEmarAgxhoefSAAAAAFHTZqaAABgPMjAxNzAxMjAxODUyMjJa
oBEYDzIwMTcwMTI3MTg1MjIyWjANBgkqhkiG9w0BAQUFAAOCAQEAor3XqBLS9R8B
dbOLWJ09b9sKB7VboOs2+z7f8iVTdrN1i+Mo9+6cen2RONjk1bN0uW9vjNIj131i
FXD+zBtuAHlFVQOSTdYu39tmBP+aAndUgm6a7Im8gP5MATb6YiG4YO7fxS5FXiRb
eQ/2DsNtt2MvL4IRBrA5arZN1tFw5pWMjp4wVI4pxaSw4kKOivcz8+qQ55sPfhO8
dj8ApBfymhSJ9oi53ybUmDmQH/FhwDUBWQszBaXgBI5zl+8fUjk8rijauRN2McFo
NeTTTfaOFOvIAm337HMGCe6VS/4U69TvG8jol81IK3wL9AkD4P4fSKmHP85M0gvM
LP3XWXQS5qCCBRwwggUYMIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqG
SIb3DQEBCwUAMIG+MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5j
LjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcG
A1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVz
ZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHkgLSBHMjAeFw0xNTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMG
A1UEAxMcRW50cnVzdCBWYWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txuf
oeq145I/mT6V7+0IppVM2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4
wy65D9lMPm2ENo5orDtbXqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2
wgIFFZOzIvFZickiHph8tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlO
YaJT/2PXulGGog6A4B+XJkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFb
MjHOMSzHIxdRnGeDmchnBL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TAL
BgNVHQ8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIF
ADAwBgNVHR8EKTAnMCWgI6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2Eu
Y3JsMDMGCCsGAQUFBwEBBCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50
cnVzdC5uZXQwHwYDVR0jBBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0O
BBYEFNUCBLbXoKgts70SJatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQEL
BQADggEBADOiWIKLGjQVR7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWY
DPS/xmPXPMc34VQjqkRFQmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiX
p1ncZctaMa6Jsa6X/DMdB6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAP
fiIkI9zXoL6UeMPISDUk+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurN
yrrGBQaFoZEy+jEKOn0XOph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzs
sKEEqnkXHHoFz9QilxJrgbcV/S1hz9Q=
-----END OCSP RESPONSE-----

Raw OCSP Signing Certificate (PEM encoded)

-----BEGIN CERTIFICATE-----
MIIFFDCCA/ygAwIBAgIMTelQvQAAAABR03NIMA0GCSqGSIb3DQEBCwUAMIG+MQsw
CQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2Vl
IHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkg
RW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQD
EylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjAeFw0x
NTA2MDQxOTE1MzRaFw0xNzA2MDQxOTQ1MzRaMIHlMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5l
dC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAt
IGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3Qg
Q2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMjElMCMGA1UEAxMcRW50cnVzdCBW
YWxpZGF0aW9uIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAMnaiVXp64PVTKleQeIiQG2padA36kGk1CV7txufoeq145I/mT6V7+0IppVM
2A4LL5l2DVGqTsAQCRilF1rbZync50FA3XXTonpvadk4wy65D9lMPm2ENo5orDtb
XqlrHFhcyBrki96K+fdVedlx7+uJZeAC72ZCXzaoVKc2wgIFFZOzIvFZickiHph8
tIGM3ESJKp2Jfo64fPXPmtoTV2GUZMqqucAUD2/s/SlOYaJT/2PXulGGog6A4B+X
JkXBnqwYmHm/20jl1dSGHA5m49jjrMfBuVhIYB0DePFbMjHOMSzHIxdRnGeDmchn
BL/B7vLedf/bgv8ORMzkmF4DpDMCAwEAAaOB6DCB5TALBgNVHQ8EBAMCB4AwEwYD
VR0lBAwwCgYIKwYBBQUHAwkwDwYJKwYBBQUHMAEFBAIFADAwBgNVHR8EKTAnMCWg
I6Ahhh9odHRwOi8vY3JsLmVudHJ1c3QubmV0L2cyY2EuY3JsMDMGCCsGAQUFBwEB
BCcwJTAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AuZW50cnVzdC5uZXQwHwYDVR0j
BBgwFoAUanImetAe733nO2lR1GyNn5ASZqswHQYDVR0OBBYEFNUCBLbXoKgts70S
JatS1NHllo3EMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBADOiWIKLGjQV
R7Sbhzs2OvR5l9pLfzoHnje8iLH3hM5+6mYDzhmt9jWYDPS/xmPXPMc34VQjqkRF
Qmtl8pny1YwDraWyLVJR81WfRMa0Bl3QXK/PzPvNFSiXp1ncZctaMa6Jsa6X/DMd
B6KPMhRu9obdQGPaRv9hf215CuOblmFRmJUo/awWTgAPfiIkI9zXoL6UeMPISDUk
+OkSJWo1znzRX3Cjt1AZz5nlUvgdXZI7lvxdvrJsaurNyrrGBQaFoZEy+jEKOn0X
Oph0sIfpPDw8GlWcXkbw38DjuwRW+SBl11O0uPoESBzssKEEqnkXHHoFz9QilxJr
gbcV/S1hz9Q=
-----END CERTIFICATE-----

Raw OCSP response headers

Cache-Control: [public, no-transform, must-revalidate, max-age=2354]
Content-Length: [1991]
Content-Transfer-Encoding: [Binary]
Content-Type: [application/ocsp-response]
Date: [Fri, 20 Jan 2017 19:20:49 GMT]
Etag: ["17FF9E67C0E47DA3F395FB21D268886E8CFAAF18"]
Expires: [Fri, 20 Jan 2017 20:00:03 GMT]
Last-Modified: [Fri, 20 Jan 2017 18:52:22 GMT]
X-Cache: [TCP_MEM_HIT from a165-254-48-146.deploy.akamaitechnologies.com (AkamaiGHost/8.2.0.0.2-18911410) (-)]
  • OCSP signing certificate is already valid
  • OCSP signing certificate is not expired
  • OCSP signing certificate does not expire before NextUpdate
  • OCSP signing certificate does contain the Extended Key Usage for OCSP Signing
  • OCSP signing certificate does contain the OCSP No Check extension
  • Content-Type in response is set to 'application/ocsp-response'
  • Response is already valid
  • Response is not expired
  • Revocation information is updated at least once every twelve months
  • The value of the NextUpdate field is not more than twelve months beyond the value of the ThisUpdate field
  • Last-Modified header is the same as ThisUpdate (RFC 5019, section 6.2)
  • NextUpdate is after the date in the Expires cache header
  • The Cache-Control max-age header does not outlive NextUpdate
  • ThisUpdate has a date before NextUpdate
  • Expires cache header is not the same as the NextUpdate field (RFC 5019 section 6.2)

Entrust Root Certification Authority - G2 (CA Certificate)

This certificate was cached at
Certificate details for Entrust Root Certification Authority - G2 (At position 2 in certificate chain)
Serial number:
hex: 4a538c28
int: 1246989352
Issued by: Entrust Root Certification Authority - G2
Public Key Algorithm: RSA
Not valid before:
Not valid after:
Organization: Entrust, Inc.
Organization unit: See www.entrust.net/legal-terms
Organization unit: (c) 2009 Entrust, Inc. - for authorized use only
Country: US
  • This certificate does not contain any links to an LDAP server
  • This certificate does not contain any internal server links
  • This certificate does not contain any links with an unknown format

This is a self signed certificate

Check the revocation status for another website

Created by Paul van Brouwershaven
Revoked certificates can't and should not be trusted, these certificate will cause errors like "NET::ERR_CERT_REVOKED" in browsers.