SSL Checker

Check SSL validity, issuer, expiry, and OCSP/CRL revocation status.

Check a domain

Choose single or bulk mode

https://

Results

Public checks · 5 per page · newest first

No public results yet. Check a domain with public display enabled.

Revocation guide

CRL and standard revocation reason codes.

Certificate Revocation List (CRL)

A Certificate Revocation List is a signed list published by a Certificate Authority (CA). It contains serial numbers of certificates that were revoked before their normal expiry date. Clients and checkers download the CRL from the certificate’s CRL Distribution Points and look up the serial number. If the serial appears on the list, the certificate must not be trusted—even if the dates still look valid. CRLs are updated periodically; OCSP is a live query alternative, and this tool checks both when available.

Reasons for revocation

When a CA revokes a certificate, it may attach a standard CRLReason code. These are the common RFC 5280 reasons you may see in OCSP or CRL results.

unspecified
No detailed reason was provided.
keyCompromise
Private key may have been exposed or stolen.
cACompromise
Issuing CA key or systems were compromised.
affiliationChanged
Subject organization or identity changed.
superseded
A newer certificate replaced this one.
cessationOfOperation
Related service or role stopped.
certificateHold
Temporary suspension; may be released later.
removeFromCRL
Used on delta CRLs when a hold is lifted.
privilegeWithdrawn
Privileges granted by the certificate were removed.
aACompromise
Related Attribute Authority was compromised.

Contact

Send a message to the site administrators.