| Has an extension in the SingleResponse |
| |
| $ openssl ocsp -resp_text -respin <([OCSP RESPONSE]) |
| OCSP Response Data: |
| OCSP Response Status: successful (0x0) |
| Response Type: Basic OCSP Response |
| Version: 1 (0x0) |
| Responder Id: CN = Test Intermediate CA |
| Produced At: Mar 2 00:00:00 2017 GMT |
| Responses: |
| Certificate ID: |
| Hash Algorithm: sha1 |
| Issuer Name Hash: 449B1C5B31C6E9990966523E49C3F773C024190A |
| Issuer Key Hash: 2A860071C9B1A207C3B00BDDA94112233D2320B8 |
| Serial Number: 05 |
| Cert Status: good |
| This Update: Mar 1 00:00:00 2017 GMT |
| Response Single Extensions: |
| 1.2.3.4: |
| DEADBEEF |
| |
| Signature Algorithm: sha1WithRSAEncryption |
| Signature Value: |
| b3:51:ca:54:c8:7f:6b:5b:ed:55:32:06:d4:f3:6e:a2:cb:05: |
| 92:3f:0a:c8:6a:e2:1a:4f:7d:de:8b:5a:5e:d2:76:39:43:9e: |
| 0a:91:b9:16:3b:23:c0:7d:f6:a0:61:21:1b:28:d4:4e:fd:62: |
| f5:1d:26:bf:08:53:f6:19:98:5e:be:90:24:81:94:87:69:5c: |
| 7d:ef:bc:dc:e9:43:1c:44:10:38:77:b0:16:c3:0e:ae:3d:53: |
| d3:7e:0b:ef:df:77:a9:43:3b:e5:62:a8:0c:0b:66:16:89:73: |
| b2:93:8e:2b:ab:9e:66:ef:7b:87:70:ae:89:ac:d9:11:e4:95: |
| 3b:ba:55:e9:c8:0c:ed:9a:26:90:11:4c:5c:fc:95:ea:8b:3a: |
| 83:2e:fc:5f:69:0c:86:8c:a4:9f:68:0f:9b:87:bb:3f:02:7d: |
| bc:51:9b:28:a7:9d:75:bf:89:ae:8b:79:b3:97:90:16:c4:12: |
| 8d:00:f7:a4:05:70:8b:c8:a3:c5:97:46:90:55:45:6b:af:a6: |
| ec:bc:29:74:88:56:2b:85:c3:95:c5:bf:e4:17:4c:43:fd:8c: |
| 45:dd:64:bc:b3:a5:d6:d5:de:7b:12:39:8b:03:3e:7c:a6:20: |
| f1:ea:ca:bf:19:cf:1d:92:1a:d0:71:d5:55:4c:fe:e4:b9:26: |
| 89:db:90:6f |
| -----BEGIN OCSP RESPONSE----- |
| MIIBzQoBAKCCAcYwggHCBgkrBgEFBQcwAQEEggGzMIIBrzCBmqEhMB8xHTAbBgNVBAMMFFRlc3Q |
| gSW50ZXJtZWRpYXRlIENBGA8yMDE3MDMwMjAwMDAwMFowZDBiMDgwBwYFKw4DAhoEFESbHFsxxu |
| mZCWZSPknD93PAJBkKBBQqhgBxybGiB8OwC92pQRIjPSMguAIBBYAAGA8yMDE3MDMwMTAwMDAwM |
| FqhEzARMA8GAyoDBAQIREVBREJFRUYwCwYJKoZIhvcNAQEFA4IBAQCzUcpUyH9rW+1VMgbU826i |
| ywWSPwrIauIaT33ei1pe0nY5Q54KkbkWOyPAffagYSEbKNRO/WL1HSa/CFP2GZhevpAkgZSHaVx |
| 977zc6UMcRBA4d7AWww6uPVPTfgvv33epQzvlYqgMC2YWiXOyk44rq55m73uHcK6JrNkR5JU7ul |
| XpyAztmiaQEUxc/JXqizqDLvxfaQyGjKSfaA+bh7s/An28UZsop511v4mui3mzl5AWxBKNAPekB |
| XCLyKPFl0aQVUVrr6bsvCl0iFYrhcOVxb/kF0xD/YxF3WS8s6XW1d57EjmLAz58piDx6sq/Gc8d |
| khrQcdVVTP7kuSaJ25Bv |
| -----END OCSP RESPONSE----- |
| |
| $ openssl x509 -text < [CA CERTIFICATE] |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: 2 (0x2) |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Test CA |
| Validity |
| Not Before: Jan 1 00:00:00 2017 GMT |
| Not After : Jan 1 00:00:00 2018 GMT |
| Subject: CN=Test Intermediate CA |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:de:22:c5:9e:27:40:df:a6:99:7e:b2:52:1e:af: |
| e1:57:7b:f1:49:3c:1c:f6:4d:ca:de:9f:5a:5a:5f: |
| 98:d6:74:e7:20:f7:ea:c4:d7:46:19:0a:47:2b:50: |
| 8e:04:80:eb:e6:6e:35:95:f8:82:d0:eb:21:50:08: |
| e2:08:14:40:7b:4f:06:92:81:d2:2e:59:a0:28:82: |
| b9:ea:f9:dc:14:d4:a3:d8:39:b6:fe:c7:83:78:cb: |
| d2:2a:ed:6f:9a:3a:09:a7:65:43:66:63:d4:67:90: |
| a0:1f:67:ca:73:8c:ad:f9:d4:c5:67:02:3b:94:06: |
| ae:ff:2b:de:5c:81:34:76:af:51:34:41:84:45:f6: |
| 51:30:cd:90:2e:ba:44:07:08:1d:85:12:f3:65:ac: |
| f3:f5:b2:8c:4a:71:54:84:4e:df:b7:7c:84:97:be: |
| b4:71:99:0f:2d:4f:35:3c:01:57:4b:8e:7f:f4:98: |
| 35:1b:a9:88:1d:4b:ba:5b:45:34:c4:e6:94:50:b3: |
| 36:aa:7d:38:40:25:38:46:f1:78:52:da:af:63:54: |
| 40:d2:06:e5:84:b9:a6:a6:46:a9:23:04:c2:33:10: |
| 59:63:59:1f:39:37:2d:e9:4c:97:59:77:2e:6f:ae: |
| 13:c3:7a:6b:68:74:86:6a:c8:28:b8:5f:3a:3d:1c: |
| 4e:53 |
| Exponent: 65537 (0x10001) |
| Signature Algorithm: sha256WithRSAEncryption |
| Signature Value: |
| 9c:3a:ce:62:9c:a2:0c:58:8a:f7:4f:9b:04:b4:ce:12:f5:e0: |
| c0:22:0f:07:67:91:90:71:44:ec:8e:d1:4b:d7:81:0f:c2:ea: |
| 30:8e:20:15:6a:aa:ab:13:a7:fe:c2:c2:43:2d:fa:39:77:83: |
| 30:b3:c0:76:0b:7c:4d:99:61:75:86:96:45:ba:61:45:c7:51: |
| 88:59:78:e4:c5:41:fa:c4:0f:49:a8:6e:7e:34:9d:85:19:a2: |
| bb:d9:09:17:d2:f2:4a:a5:7b:35:54:0a:b8:d6:8f:f8:5c:e2: |
| 10:9d:0a:ec:c8:a1:12:b0:6f:9a:cb:c5:c3:d6:a9:ec:2e:67: |
| e6:77:59:ce:bc:43:4a:b6:52:b8:49:ea:bc:55:6e:f3:3a:92: |
| ee:41:e7:63:b4:8c:c6:8f:93:62:08:08:0f:dd:84:fe:6d:e3: |
| 15:fb:0b:3a:3b:64:ab:4e:32:9c:28:71:eb:3e:2d:fe:98:69: |
| 3f:94:8d:c7:3d:d6:b8:56:c6:fd:cf:33:d7:91:b0:4b:ea:06: |
| 15:9a:5f:18:21:cf:59:67:d5:06:15:84:14:6c:2d:fb:5d:0f: |
| 8f:32:87:6f:35:aa:0f:d1:ef:7a:75:86:c7:d7:91:a3:06:eb: |
| 42:4d:f8:34:32:60:e8:9f:e8:ff:01:6a:b3:6c:fc:de:51:49: |
| 6c:0b:77:61 |
| -----BEGIN CA CERTIFICATE----- |
| MIICqjCCAZKgAwIBAgIBAjANBgkqhkiG9w0BAQsFADASMRAwDgYDVQQDDAdUZXN0IENBMB4XDTE |
| 3MDEwMTAwMDAwMFoXDTE4MDEwMTAwMDAwMFowHzEdMBsGA1UEAwwUVGVzdCBJbnRlcm1lZGlhdG |
| UgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDeIsWeJ0Dfppl+slIer+FXe/FJP |
| Bz2Tcren1paX5jWdOcg9+rE10YZCkcrUI4EgOvmbjWV+ILQ6yFQCOIIFEB7TwaSgdIuWaAogrnq |
| +dwU1KPYObb+x4N4y9Iq7W+aOgmnZUNmY9RnkKAfZ8pzjK351MVnAjuUBq7/K95cgTR2r1E0QYR |
| F9lEwzZAuukQHCB2FEvNlrPP1soxKcVSETt+3fISXvrRxmQ8tTzU8AVdLjn/0mDUbqYgdS7pbRT |
| TE5pRQszaqfThAJThG8XhS2q9jVEDSBuWEuaamRqkjBMIzEFljWR85Ny3pTJdZdy5vrhPDemtod |
| IZqyCi4Xzo9HE5TAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAJw6zmKcogxYivdPmwS0zhL14MAi |
| DwdnkZBxROyO0UvXgQ/C6jCOIBVqqqsTp/7CwkMt+jl3gzCzwHYLfE2ZYXWGlkW6YUXHUYhZeOT |
| FQfrED0mobn40nYUZorvZCRfS8kqlezVUCrjWj/hc4hCdCuzIoRKwb5rLxcPWqewuZ+Z3Wc68Q0 |
| q2UrhJ6rxVbvM6ku5B52O0jMaPk2IICA/dhP5t4xX7Czo7ZKtOMpwoces+Lf6YaT+Ujcc91rhWx |
| v3PM9eRsEvqBhWaXxghz1ln1QYVhBRsLftdD48yh281qg/R73p1hsfXkaMG60JN+DQyYOif6P8B |
| arNs/N5RSWwLd2E= |
| -----END CA CERTIFICATE----- |
| |
| $ openssl x509 -text < [CERTIFICATE] |
| Certificate: |
| Data: |
| Version: 3 (0x2) |
| Serial Number: 5 (0x5) |
| Signature Algorithm: sha256WithRSAEncryption |
| Issuer: CN=Test Intermediate CA |
| Validity |
| Not Before: Jan 1 00:00:00 2017 GMT |
| Not After : Jan 1 00:00:00 2018 GMT |
| Subject: CN=Test Cert |
| Subject Public Key Info: |
| Public Key Algorithm: rsaEncryption |
| Public-Key: (2048 bit) |
| Modulus: |
| 00:9a:21:a4:62:e0:6e:af:0b:2d:44:00:f2:a9:68: |
| b3:44:08:10:81:24:4e:8d:64:d1:35:18:a0:71:84: |
| 38:7a:f8:45:29:02:36:6e:f8:4e:34:22:ae:83:a4: |
| 40:b7:88:33:92:29:26:e4:79:4a:28:f2:f7:ee:91: |
| 24:64:34:20:b0:ee:67:e3:69:0c:42:80:cb:43:8e: |
| d8:b8:70:45:db:e3:e9:37:6c:da:61:61:aa:57:e1: |
| f4:58:b9:47:92:4a:80:25:e1:79:7b:7c:db:43:88: |
| 1d:34:da:2d:b1:d9:73:ae:5b:05:ac:5c:8f:91:2d: |
| 2b:4a:67:55:06:a7:84:94:31:e1:77:48:10:77:0a: |
| 40:55:17:fe:62:14:3e:68:23:c4:b3:95:44:2f:6a: |
| 38:9c:04:16:b4:67:37:80:29:78:f6:cc:ee:9c:e1: |
| 86:60:4f:8c:65:7d:28:8e:f2:36:46:54:e2:09:28: |
| 61:ad:cd:f4:68:83:67:2d:60:5c:a1:97:43:54:19: |
| f5:fa:60:04:14:f8:a8:1f:02:86:a9:38:dc:da:fd: |
| 35:37:35:f5:ce:16:4d:6e:ec:90:ca:78:3b:65:dd: |
| c7:1e:a1:32:69:d8:3a:84:8c:5a:bf:6b:24:0b:9f: |
| 5f:48:64:1d:cc:b9:a9:ba:ea:f1:34:1d:66:71:42: |
| a9:db |
| Exponent: 65537 (0x10001) |
| Signature Algorithm: sha256WithRSAEncryption |
| Signature Value: |
| 77:5d:e9:cc:a7:aa:eb:90:6d:24:c1:6b:4d:2a:bd:95:30:40: |
| 18:f2:ea:6a:b9:98:f6:78:f8:c2:0b:95:3a:8c:e4:2e:cd:ff: |
| 47:01:48:5e:08:8d:e2:c6:4c:3c:be:ad:51:77:23:0d:4d:88: |
| 74:e2:ff:89:01:26:f3:a3:99:bb:a9:7f:17:1a:61:d6:0f:1f: |
| eb:d8:02:a0:8a:b9:61:c4:e0:b3:20:df:b2:c5:1f:74:de:08: |
| 53:32:cf:d3:0f:38:7e:d6:3c:64:b6:e3:f1:a6:44:53:bf:35: |
| 5a:2b:93:07:1d:89:68:9d:10:07:b0:22:f0:b7:d6:69:f1:f8: |
| 5b:d9:a1:86:96:b0:ff:02:1e:10:48:ed:74:6e:f5:43:08:89: |
| 1b:19:4e:8e:63:c5:b4:1c:c6:33:bf:50:c3:6b:78:12:fb:cb: |
| e1:b2:a3:b5:c1:b8:8f:c1:ed:4c:c6:3a:bb:37:3f:94:be:11: |
| 32:7d:a6:1a:07:b0:67:2a:0a:25:30:fa:06:3d:b2:d8:80:6c: |
| da:34:3c:ec:f9:fb:53:08:4a:7c:98:4c:0c:1a:0a:73:c5:81: |
| 7f:c4:5d:23:be:60:18:d7:86:8e:9d:c8:27:30:34:1f:06:19: |
| 4c:a1:d4:ba:4f:02:3b:41:bb:38:8e:b0:77:15:5c:9c:a5:d4: |
| c8:d2:ac:51 |
| -----BEGIN CERTIFICATE----- |
| MIICrDCCAZSgAwIBAgIBBTANBgkqhkiG9w0BAQsFADAfMR0wGwYDVQQDDBRUZXN0IEludGVybWV |
| kaWF0ZSBDQTAeFw0xNzAxMDEwMDAwMDBaFw0xODAxMDEwMDAwMDBaMBQxEjAQBgNVBAMMCVRlc3 |
| QgQ2VydDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJohpGLgbq8LLUQA8qlos0QIE |
| IEkTo1k0TUYoHGEOHr4RSkCNm74TjQiroOkQLeIM5IpJuR5Sijy9+6RJGQ0ILDuZ+NpDEKAy0OO |
| 2LhwRdvj6Tds2mFhqlfh9Fi5R5JKgCXheXt820OIHTTaLbHZc65bBaxcj5EtK0pnVQanhJQx4Xd |
| IEHcKQFUX/mIUPmgjxLOVRC9qOJwEFrRnN4ApePbM7pzhhmBPjGV9KI7yNkZU4gkoYa3N9GiDZy |
| 1gXKGXQ1QZ9fpgBBT4qB8Chqk43Nr9NTc19c4WTW7skMp4O2Xdxx6hMmnYOoSMWr9rJAufX0hkH |
| cy5qbrq8TQdZnFCqdsCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAd13pzKeq65BtJMFrTSq9lTBA |
| GPLqarmY9nj4wguVOozkLs3/RwFIXgiN4sZMPL6tUXcjDU2IdOL/iQEm86OZu6l/Fxph1g8f69g |
| CoIq5YcTgsyDfssUfdN4IUzLP0w84ftY8ZLbj8aZEU781WiuTBx2JaJ0QB7Ai8LfWafH4W9mhhp |
| aw/wIeEEjtdG71QwiJGxlOjmPFtBzGM79Qw2t4EvvL4bKjtcG4j8HtTMY6uzc/lL4RMn2mGgewZ |
| yoKJTD6Bj2y2IBs2jQ87Pn7UwhKfJhMDBoKc8WBf8RdI75gGNeGjp3IJzA0HwYZTKHUuk8CO0G7 |
| OI6wdxVcnKXUyNKsUQ== |
| -----END CERTIFICATE----- |
| |
| $ openssl asn1parse -i < [OCSP REQUEST] |
| 0:d=0 hl=2 l= 66 cons: SEQUENCE |
| 2:d=1 hl=2 l= 64 cons: SEQUENCE |
| 4:d=2 hl=2 l= 62 cons: SEQUENCE |
| 6:d=3 hl=2 l= 60 cons: SEQUENCE |
| 8:d=4 hl=2 l= 58 cons: SEQUENCE |
| 10:d=5 hl=2 l= 9 cons: SEQUENCE |
| 12:d=6 hl=2 l= 5 prim: OBJECT :sha1 |
| 19:d=6 hl=2 l= 0 prim: NULL |
| 21:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:449B1C5B31C6E9990966523E49C3F773C024190A |
| 43:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:2A860071C9B1A207C3B00BDDA94112233D2320B8 |
| 65:d=5 hl=2 l= 1 prim: INTEGER :05 |
| -----BEGIN OCSP REQUEST----- |
| MEIwQDA+MDwwOjAJBgUrDgMCGgUABBREmxxbMcbpmQlmUj5Jw/dzwCQZCgQUKoYAccmxogfDsAv |
| dqUESIz0jILgCAQU= |
| -----END OCSP REQUEST----- |