SSL Checker

Check SSL validity, issuer, expiry, and OCSP/CRL revocation status.

Check a domain

Choose single or bulk mode

https://

Results

Public checks · 5 per page · newest first

No public results yet. Check a domain with public display enabled.

Revocation guide

Tap to learn about CRL and revocation reasons.

Certificate Revocation List (CRL)

A Certificate Revocation List is a signed list published by a Certificate Authority (CA). It contains serial numbers of certificates that were revoked before their normal expiry date. Clients and checkers download the CRL from the certificate’s CRL Distribution Points and look up the serial number. If the serial appears on the list, the certificate must not be trusted—even if the dates still look valid. CRLs are updated periodically; OCSP is a live query alternative, and this tool checks both when available.

Reasons for revocation

When a CA revokes a certificate, it may attach a standard reason code (CRLReason). That code explains why trust was withdrawn. Below are the common RFC 5280 reasons you may see in OCSP or CRL results.

  • Unspecified — No detailed reason was provided.
  • Key compromise — The private key may have been exposed or stolen.
  • CA compromise — The issuing CA’s own key or systems were compromised.
  • Affiliation changed — The subject’s organization or identity details changed.
  • Superseded — A newer certificate replaced this one.
  • Cessation of operation — The service or role tied to the certificate stopped.
  • Certificate hold — Temporary suspension; may be released later.
  • Remove from CRL — Used on delta CRLs when a hold is lifted.
  • Privilege withdrawn — Rights previously granted by the certificate were removed.
  • AA compromise — An Attribute Authority related to the certificate was compromised.

Contact

Send a message to the site administrators.