OCSP Checker
Inspect an X.509 certificate, discover its OCSP responder and CA Issuers locations, and review revocation metadata without uploading your certificate.
Certificate input
Paste an end-entity certificate or upload a PEM, CRT, or CER file.
Certificate revocation
Review OCSP responder information before validating certificates
Online Certificate Status Protocol (OCSP) allows applications to determine whether a certificate has been revoked without downloading an entire Certificate Revocation List (CRL).
What this tool inspects
Extract Authority Information Access (AIA) extensions, identify OCSP responder URLs, CA Issuers locations, issuer information, and revocation-related metadata embedded in the certificate.
What this tool does not do
Inspecting a certificate does not contact the OCSP responder or determine whether the certificate is currently revoked. It only analyzes the certificate's embedded revocation information.
Guide
About OCSP and AIA Inspector
The Authority Information Access extension can advertise OCSP responders and issuer-certificate download locations.
This tool extracts OCSP and CA Issuers URIs from an X.509 certificate.
Extracting responder metadata does not itself perform a live revocation check.
What AIA can contain
Common access methods include OCSP and CA Issuers locations.
OCSP purpose
OCSP allows a client to ask a responder for the revocation status of a specific certificate.
Issuer certificate retrieval
CA Issuers URLs can help clients obtain missing intermediate certificates.
Live-check limitations
A full OCSP check requires constructing a request, contacting a responder, validating its signature and freshness, and interpreting the response.
FAQ
Frequently asked questions
Does this tool perform a live OCSP request?
No. It extracts OCSP and CA Issuers metadata from the certificate.
What is Authority Information Access?
AIA is an X.509 extension that identifies services and resources related to the issuing CA.
What is an OCSP responder?
It is a service that returns signed certificate-status responses.
What is a CA Issuers URL?
It commonly points to an issuer certificate that can help build the chain.
Can a certificate have multiple OCSP URLs?
Yes. An AIA extension can contain multiple access descriptions.
Is the certificate uploaded?
Inspection is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
CRL Distribution Point Inspector
Extract CRL Distribution Point and Freshest CRL URLs from X.509 certificates.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Chain Builder
Order X.509 certificates and generate fullchain.pem and chain.pem locally.
PKI & Certificates
SSL/TLS Checker
Inspect a live server's TLS protocol, cipher, certificate chain, expiration, and trust status.
Website Security
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates