Check SSL validity, issuer, expiry, and OCSP/CRL revocation status.
Public checks · 5 per page · newest first
No public results yet. Check a domain with public display enabled.
Tap to learn about CRL and revocation reasons.
A Certificate Revocation List is a signed list published by a Certificate Authority (CA). It contains serial numbers of certificates that were revoked before their normal expiry date. Clients and checkers download the CRL from the certificate’s CRL Distribution Points and look up the serial number. If the serial appears on the list, the certificate must not be trusted—even if the dates still look valid. CRLs are updated periodically; OCSP is a live query alternative, and this tool checks both when available.
When a CA revokes a certificate, it may attach a standard reason code (CRLReason). That code explains why trust was withdrawn. Below are the common RFC 5280 reasons you may see in OCSP or CRL results.
Send a message to the site administrators.