blob: 36af3bb4d6b414a49ad9b15284fd71d87df4e15b [file]
Is a REVOKE response for the cert
$ openssl ocsp -resp_text -respin <([OCSP RESPONSE])
OCSP Response Data:
OCSP Response Status: successful (0x0)
Response Type: Basic OCSP Response
Version: 1 (0x0)
Responder Id: CN = Test Intermediate CA
Produced At: Mar 2 00:00:00 2017 GMT
Responses:
Certificate ID:
Hash Algorithm: sha1
Issuer Name Hash: 449B1C5B31C6E9990966523E49C3F773C024190A
Issuer Key Hash: 345CB28B1D8CDD6CBFF8F5CCF46521E87A8DF391
Serial Number: 05
Cert Status: revoked
Revocation Time: Feb 1 00:00:00 2017 GMT
This Update: Mar 1 00:00:00 2017 GMT
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
27:77:76:ac:42:76:34:53:47:46:51:13:38:7f:b5:9a:d9:54:
f0:2a:5a:14:44:8b:49:d1:60:c6:9a:14:32:bc:cb:d2:84:69:
40:e6:3c:ac:83:12:c3:50:e5:ec:4c:09:dd:af:57:07:cc:d0:
3a:42:bf:07:65:a9:e4:47:46:39:9e:a9:b8:a2:05:73:24:bd:
57:6f:4b:40:ce:09:34:b0:98:e8:bb:9e:6e:15:d5:77:98:89:
af:58:b8:04:ea:2f:b4:5c:02:3b:b0:df:4b:35:fc:88:80:43:
76:f8:08:16:51:f6:6d:ec:0e:09:56:26:a7:ae:88:b4:2f:14:
bc:9f:15:f3:24:8d:68:fe:8f:70:94:12:b5:e0:01:d9:31:eb:
f5:a1:76:19:0c:7b:52:54:3f:c4:ae:6f:fc:80:9b:d2:0e:27:
a8:fe:43:20:1f:e1:15:12:9a:22:02:4d:fa:0f:da:a6:b3:43:
9d:7f:80:a8:63:c1:85:d7:40:f2:58:c4:95:19:55:7a:85:3d:
2f:f8:fc:3d:53:14:0f:82:f4:0d:5d:e3:86:17:2a:7e:97:f1:
11:ca:56:4e:6a:0b:ea:d9:c9:01:7f:2f:57:69:77:77:ed:d7:
ff:17:f9:13:aa:fc:3b:0a:d5:3a:6e:e5:84:fd:42:ec:04:91:
f8:51:50:00
-----BEGIN OCSP RESPONSE-----
MIIByQoBAKCCAcIwggG+BgkrBgEFBQcwAQEEggGvMIIBqzCBlqEhMB8xHTAbBgNVBAMMFFRlc3Q
gSW50ZXJtZWRpYXRlIENBGA8yMDE3MDMwMjAwMDAwMFowYDBeMDgwBwYFKw4DAhoEFESbHFsxxu
mZCWZSPknD93PAJBkKBBQ0XLKLHYzdbL/49cz0ZSHoeo3zkQIBBaERGA8yMDE3MDIwMTAwMDAwM
FoYDzIwMTcwMzAxMDAwMDAwWjALBgkqhkiG9w0BAQUDggEBACd3dqxCdjRTR0ZREzh/tZrZVPAq
WhREi0nRYMaaFDK8y9KEaUDmPKyDEsNQ5exMCd2vVwfM0DpCvwdlqeRHRjmeqbiiBXMkvVdvS0D
OCTSwmOi7nm4V1XeYia9YuATqL7RcAjuw30s1/IiAQ3b4CBZR9m3sDglWJqeuiLQvFLyfFfMkjW
j+j3CUErXgAdkx6/WhdhkMe1JUP8Sub/yAm9IOJ6j+QyAf4RUSmiICTfoP2qazQ51/gKhjwYXXQ
PJYxJUZVXqFPS/4/D1TFA+C9A1d44YXKn6X8RHKVk5qC+rZyQF/L1dpd3ft1/8X+ROq/DsK1Tpu
5YT9QuwEkfhRUAA=
-----END OCSP RESPONSE-----
$ openssl x509 -text < [CA CERTIFICATE]
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 2 (0x2)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Test CA
Validity
Not Before: Jan 1 00:00:00 2017 GMT
Not After : Jan 1 00:00:00 2018 GMT
Subject: CN=Test Intermediate CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b6:34:d0:4e:c4:a4:f7:e0:90:a6:1f:54:37:d7:
02:5e:33:3d:39:99:9c:15:f5:d6:7a:e5:59:87:bf:
52:53:2d:8b:f6:31:ef:54:a2:e6:74:29:d5:52:54:
6f:25:9e:24:30:29:15:f1:71:68:cd:d9:77:48:94:
e5:96:a3:43:8b:35:2e:5f:da:00:a7:d3:ef:37:e8:
ef:e9:6e:b6:c9:dc:2b:90:cb:64:90:70:32:69:d9:
39:dd:9a:a8:51:98:61:99:0b:36:92:5e:f4:57:54:
8f:c7:9f:b2:28:df:0b:73:bb:2c:c8:96:26:6d:a0:
04:a9:93:a8:77:98:f9:ea:26:e0:92:6f:1b:34:03:
31:bd:fe:36:cc:86:02:21:f9:f3:41:c4:0d:c4:6e:
86:09:35:4b:f1:d6:4c:49:8a:bb:e5:d2:96:fa:fe:
ae:5c:95:8a:83:41:e6:36:9a:e8:3d:f2:73:e1:a6:
93:2d:ef:8f:35:95:67:f2:2b:b7:5e:72:24:de:1b:
c0:8d:cc:8f:2f:b3:94:74:15:cb:cc:5f:e4:dd:ee:
9b:fb:b2:86:64:1d:c3:ae:ac:58:eb:5e:5a:58:28:
4f:ea:49:f8:d3:ce:3a:f8:f1:a5:44:d4:ff:89:71:
dd:88:d5:64:b7:39:02:4b:d7:0e:87:55:9a:be:c3:
a2:6b
Exponent: 65537 (0x10001)
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
48:77:56:03:36:fd:be:c2:46:c7:b8:88:b1:58:a0:e9:34:77:
91:0c:ec:ad:f5:9c:c7:49:0e:d7:f4:22:b1:3b:6a:b5:1a:e1:
ed:16:1e:43:25:8c:2a:27:3a:66:4e:a0:af:6e:e1:d0:4f:f3:
9c:63:08:07:2f:55:c1:af:55:c3:13:ec:a9:62:fc:d7:bb:4f:
6b:6c:09:7e:ce:b5:0f:54:2c:33:94:fe:33:44:d4:db:d3:7c:
ad:7a:62:fb:b7:c5:03:52:20:38:d0:b1:27:81:9f:e2:4f:02:
fb:26:a9:69:16:7b:56:f7:2f:f6:44:7b:31:39:71:40:72:ac:
3b:f7:09:c5:c8:0c:73:c2:2f:9d:5d:bb:e9:fd:66:40:a9:dd:
dc:c9:85:81:d4:0f:6a:9c:01:ff:60:d5:26:5d:d3:af:54:af:
38:44:44:7f:c0:e1:1e:1f:37:f2:df:25:cb:96:91:6a:2f:33:
4f:42:73:05:ee:85:82:3f:33:79:8f:85:be:92:73:dd:49:c7:
da:45:6d:1c:10:ba:d9:29:06:83:c3:c2:4b:70:8d:65:f5:1e:
56:6c:bc:d4:e7:71:0e:13:63:a6:88:41:36:66:a9:6c:92:d1:
de:c5:e6:c4:0d:a5:17:d1:9d:ec:3e:b5:d8:7b:bd:2d:ae:69:
70:1c:13:0c
-----BEGIN CA CERTIFICATE-----
MIICqjCCAZKgAwIBAgIBAjANBgkqhkiG9w0BAQsFADASMRAwDgYDVQQDDAdUZXN0IENBMB4XDTE
3MDEwMTAwMDAwMFoXDTE4MDEwMTAwMDAwMFowHzEdMBsGA1UEAwwUVGVzdCBJbnRlcm1lZGlhdG
UgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC2NNBOxKT34JCmH1Q31wJeMz05m
ZwV9dZ65VmHv1JTLYv2Me9UouZ0KdVSVG8lniQwKRXxcWjN2XdIlOWWo0OLNS5f2gCn0+836O/p
brbJ3CuQy2SQcDJp2TndmqhRmGGZCzaSXvRXVI/Hn7Io3wtzuyzIliZtoASpk6h3mPnqJuCSbxs
0AzG9/jbMhgIh+fNBxA3EboYJNUvx1kxJirvl0pb6/q5clYqDQeY2mug98nPhppMt7481lWfyK7
deciTeG8CNzI8vs5R0FcvMX+Td7pv7soZkHcOurFjrXlpYKE/qSfjTzjr48aVE1P+Jcd2I1WS3O
QJL1w6HVZq+w6JrAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAEh3VgM2/b7CRse4iLFYoOk0d5EM
7K31nMdJDtf0IrE7arUa4e0WHkMljConOmZOoK9u4dBP85xjCAcvVcGvVcMT7Kli/Ne7T2tsCX7
OtQ9ULDOU/jNE1NvTfK16Yvu3xQNSIDjQsSeBn+JPAvsmqWkWe1b3L/ZEezE5cUByrDv3CcXIDH
PCL51du+n9ZkCp3dzJhYHUD2qcAf9g1SZd069UrzhERH/A4R4fN/LfJcuWkWovM09CcwXuhYI/M
3mPhb6Sc91Jx9pFbRwQutkpBoPDwktwjWX1HlZsvNTncQ4TY6aIQTZmqWyS0d7F5sQNpRfRnew+
tdh7vS2uaXAcEww=
-----END CA CERTIFICATE-----
$ openssl x509 -text < [CERTIFICATE]
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 5 (0x5)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Test Intermediate CA
Validity
Not Before: Jan 1 00:00:00 2017 GMT
Not After : Jan 1 00:00:00 2018 GMT
Subject: CN=Test Cert
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:bc:c5:01:1f:1c:20:3b:ab:35:cb:34:13:ce:b0:
27:40:74:52:45:6b:09:87:14:01:12:0c:39:c3:fb:
69:90:2e:d4:4a:4b:16:42:db:9c:77:90:04:2c:ea:
5a:df:98:29:af:e4:eb:e8:a5:54:9b:a2:9b:04:8f:
fe:c6:f3:50:16:95:12:68:01:cc:99:c7:75:cf:a0:
64:77:50:e8:a2:e2:51:6f:c6:b0:8b:43:0b:4e:31:
a5:68:f1:7d:b6:1d:66:ab:cf:15:ba:97:f2:28:1f:
00:c7:4a:5b:8a:24:84:bb:61:2e:da:7e:90:4e:a3:
89:35:19:e1:be:14:9d:c4:93:9e:e6:72:00:80:67:
f7:5c:02:d5:2f:e4:ae:f0:89:ec:b4:94:76:6f:c7:
95:bb:6e:97:c7:ce:59:01:76:bc:b2:85:ca:7c:b0:
e7:a9:02:99:a4:36:73:8f:24:20:0c:d4:7d:67:b6:
8b:03:e2:e5:dc:b7:2b:33:d8:28:65:91:55:61:25:
49:ea:59:1c:9d:21:ec:36:be:a6:92:64:0f:f9:22:
b1:79:d6:a7:fe:53:7c:43:82:53:4f:8f:5e:33:15:
9c:73:30:b1:0c:82:56:85:ba:44:21:c9:bf:0e:f0:
c2:4a:ad:71:7e:35:f5:f8:18:e6:46:66:3d:17:4e:
3b:89
Exponent: 65537 (0x10001)
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
0a:09:92:a3:50:da:d8:d0:78:d1:cc:b4:47:f7:cf:2a:21:b5:
a4:1e:16:89:25:bb:27:82:65:6a:d5:f5:15:d1:28:9a:0f:b5:
74:cc:d3:0b:2a:e3:8b:ff:45:a0:88:f4:49:78:e3:3d:75:77:
61:ce:31:c0:c0:09:2c:6e:98:c0:61:27:aa:41:3b:d3:3b:00:
21:ea:8a:fc:f0:62:d3:b1:b3:84:94:03:43:ce:8d:a9:bd:db:
fe:c0:12:64:1e:ff:27:7d:fe:d8:a5:ce:e0:1f:d6:7f:30:ab:
2d:2e:30:22:20:96:ac:fd:82:39:b1:7f:4b:d2:21:45:94:ce:
b0:45:d1:75:37:31:4c:20:2f:4f:6d:19:70:f1:3a:80:dc:be:
09:f3:12:f1:a2:e4:8a:de:fd:f7:e2:08:53:ce:b0:7f:8c:0f:
01:7d:6c:2a:0f:f3:2d:f4:40:0e:60:41:c4:fb:82:0d:58:d5:
11:55:da:93:3b:1d:43:1b:e0:b8:46:2a:26:12:6a:4b:a0:69:
52:e6:bc:c5:fd:f6:98:49:6f:86:8c:5e:ba:89:51:55:7e:32:
fb:a5:17:ef:e8:4c:de:dc:b5:69:52:be:e4:87:97:e1:7e:78:
19:bb:2d:83:6b:b0:b7:48:30:93:d7:03:95:a5:ac:79:d9:3e:
e0:1b:77:38
-----BEGIN CERTIFICATE-----
MIICrDCCAZSgAwIBAgIBBTANBgkqhkiG9w0BAQsFADAfMR0wGwYDVQQDDBRUZXN0IEludGVybWV
kaWF0ZSBDQTAeFw0xNzAxMDEwMDAwMDBaFw0xODAxMDEwMDAwMDBaMBQxEjAQBgNVBAMMCVRlc3
QgQ2VydDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALzFAR8cIDurNcs0E86wJ0B0U
kVrCYcUARIMOcP7aZAu1EpLFkLbnHeQBCzqWt+YKa/k6+ilVJuimwSP/sbzUBaVEmgBzJnHdc+g
ZHdQ6KLiUW/GsItDC04xpWjxfbYdZqvPFbqX8igfAMdKW4okhLthLtp+kE6jiTUZ4b4UncSTnuZ
yAIBn91wC1S/krvCJ7LSUdm/Hlbtul8fOWQF2vLKFynyw56kCmaQ2c48kIAzUfWe2iwPi5dy3Kz
PYKGWRVWElSepZHJ0h7Da+ppJkD/kisXnWp/5TfEOCU0+PXjMVnHMwsQyCVoW6RCHJvw7wwkqtc
X419fgY5kZmPRdOO4kCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEACgmSo1Da2NB40cy0R/fPKiG1
pB4WiSW7J4JlatX1FdEomg+1dMzTCyrji/9FoIj0SXjjPXV3Yc4xwMAJLG6YwGEnqkE70zsAIeq
K/PBi07GzhJQDQ86Nqb3b/sASZB7/J33+2KXO4B/WfzCrLS4wIiCWrP2CObF/S9IhRZTOsEXRdT
cxTCAvT20ZcPE6gNy+CfMS8aLkit799+IIU86wf4wPAX1sKg/zLfRADmBBxPuCDVjVEVXakzsdQ
xvguEYqJhJqS6BpUua8xf32mElvhoxeuolRVX4y+6UX7+hM3ty1aVK+5IeX4X54Gbstg2uwt0gw
k9cDlaWsedk+4Bt3OA==
-----END CERTIFICATE-----
$ openssl asn1parse -i < [OCSP REQUEST]
0:d=0 hl=2 l= 66 cons: SEQUENCE
2:d=1 hl=2 l= 64 cons: SEQUENCE
4:d=2 hl=2 l= 62 cons: SEQUENCE
6:d=3 hl=2 l= 60 cons: SEQUENCE
8:d=4 hl=2 l= 58 cons: SEQUENCE
10:d=5 hl=2 l= 9 cons: SEQUENCE
12:d=6 hl=2 l= 5 prim: OBJECT :sha1
19:d=6 hl=2 l= 0 prim: NULL
21:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:449B1C5B31C6E9990966523E49C3F773C024190A
43:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:345CB28B1D8CDD6CBFF8F5CCF46521E87A8DF391
65:d=5 hl=2 l= 1 prim: INTEGER :05
-----BEGIN OCSP REQUEST-----
MEIwQDA+MDwwOjAJBgUrDgMCGgUABBREmxxbMcbpmQlmUj5Jw/dzwCQZCgQUNFyyix2M3Wy/+PX
M9GUh6HqN85ECAQU=
-----END OCSP REQUEST-----