Let's Encrypt is ending OCSP support in 2025 in favor of Certificate Revocation Lists (CRLs) for improved privacy. The sample certificates on this page use Let's Encrypt and will no longer work after OCSP shutdown.
OCSP response will appear here
Paste certificates and click Check OCSP StatusPerforming OCSP query...
cert.pem -noout -ocsp_uriissuer.pem -cert cert.pem \http://ocsp.example.com -resp_textchain.pem -cert cert.pem \ca-bundle.crt -url http://ocsp.example.comEvery coffee helps keep the servers running. Every book sale funds the next tool I'm dreaming up. You're not just supporting a site — you're helping me build what developers actually need.
OCSP (Online Certificate Status Protocol) defined in RFC 6960 is an Internet protocol used for obtaining the revocation status of X.509 digital certificates. Unlike CRLs (Certificate Revocation Lists), OCSP provides real-time certificate status checking.
| Feature | OCSP | CRL |
|---|---|---|
| Update Frequency | Real-time | Periodic |
| Bandwidth | Low (single cert) | High (full list) |
| Privacy | CA knows which certs you check | Better privacy |
| Availability | Requires online responder | Can be cached |