1Is a REVOKE response for the cert with a reason 2 3$ openssl ocsp -resp_text -respin <([OCSP RESPONSE]) 4OCSP Response Data: 5 OCSP Response Status: successful (0x0) 6 Response Type: Basic OCSP Response 7 Version: 1 (0x0) 8 Responder Id: CN = Test Intermediate CA 9 Produced At: Mar 2 00:00:00 2017 GMT 10 Responses: 11 Certificate ID: 12 Hash Algorithm: sha1 13 Issuer Name Hash: 449B1C5B31C6E9990966523E49C3F773C024190A 14 Issuer Key Hash: 7F765910653BB5704124C41E94AEFCF940431A66 15 Serial Number: 04 16 Cert Status: revoked 17 Revocation Time: Feb 1 00:00:00 2017 GMT 18 Revocation Reason: keyCompromise (0x1) 19 This Update: Mar 1 00:00:00 2017 GMT 20 21 Signature Algorithm: sha1WithRSAEncryption 22 b6:ce:d1:6e:78:bd:54:e6:a7:c4:b3:3c:af:1c:5c:14:27:9b: 23 54:a4:9d:b2:cb:90:99:37:26:1e:3e:2f:ce:81:44:56:66:7d: 24 8f:cd:be:b0:0d:ad:7f:c5:a1:86:92:a8:15:3d:1a:e4:ba:16: 25 f8:b4:35:25:88:68:9d:bd:6d:93:b1:c9:1b:13:f0:ef:4c:0b: 26 a0:30:54:ee:1a:9c:4d:43:41:51:00:fe:36:50:84:41:cd:c1: 27 9d:14:d7:98:6f:88:5e:ba:8f:33:33:55:c9:a2:44:0d:f0:6d: 28 c8:95:7d:1c:22:9e:f2:07:1d:66:72:03:67:ad:ab:ad:4b:82: 29 78:cf 30-----BEGIN OCSP RESPONSE----- 31MIIBTQoBAKCCAUYwggFCBgkrBgEFBQcwAQEEggEzMIIBLzCBm6EhMB8xHTAbBgNVBAMMFFRlc3Q 32gSW50ZXJtZWRpYXRlIENBGA8yMDE3MDMwMjAwMDAwMFowZTBjMDgwBwYFKw4DAhoEFESbHFsxxu 33mZCWZSPknD93PAJBkKBBR/dlkQZTu1cEEkxB6Urvz5QEMaZgIBBKEWGA8yMDE3MDIwMTAwMDAwM 34FqgAwoBARgPMjAxNzAzMDEwMDAwMDBaMAsGCSqGSIb3DQEBBQOBgQC2ztFueL1U5qfEszyvHFwU 35J5tUpJ2yy5CZNyYePi/OgURWZn2Pzb6wDa1/xaGGkqgVPRrkuhb4tDUliGidvW2TsckbE/DvTAu 36gMFTuGpxNQ0FRAP42UIRBzcGdFNeYb4heuo8zM1XJokQN8G3IlX0cIp7yBx1mcgNnrautS4J4zw 37== 38-----END OCSP RESPONSE----- 39 40$ openssl x509 -text < [CA CERTIFICATE] 41Certificate: 42 Data: 43 Version: 3 (0x2) 44 Serial Number: 1 (0x1) 45 Signature Algorithm: sha1WithRSAEncryption 46 Issuer: CN = Test CA 47 Validity 48 Not Before: Jan 1 00:00:00 2017 GMT 49 Not After : Jan 1 00:00:00 2018 GMT 50 Subject: CN = Test Intermediate CA 51 Subject Public Key Info: 52 Public Key Algorithm: rsaEncryption 53 RSA Public-Key: (1024 bit) 54 Modulus: 55 00:c5:fb:81:a7:1b:6a:61:38:1c:6a:de:dd:db:22: 56 61:64:7a:22:a3:3b:1d:e5:92:54:17:ad:39:2e:fe: 57 81:ff:46:0a:70:d6:84:a5:d5:bd:05:d3:f2:a5:98: 58 90:fd:e4:ff:d8:d2:cf:7c:d1:f2:78:0d:4a:a1:80: 59 c8:6a:70:75:84:04:c1:c2:4b:af:17:9b:a2:29:2b: 60 a7:be:f1:f9:19:80:f3:6a:d4:10:28:51:38:26:97: 61 ed:ad:06:96:85:a7:b7:7c:78:38:90:44:df:d7:10: 62 e4:52:a2:49:22:6c:98:71:51:f5:b2:13:6a:7f:08: 63 34:7c:d0:c6:99:6f:79:98:f9 64 Exponent: 65537 (0x10001) 65 Signature Algorithm: sha1WithRSAEncryption 66 7d:67:0f:39:4e:7c:e3:ba:f2:63:b9:ed:6e:ec:61:f2:8a:4f: 67 1e:82:e2:4b:44:04:f8:a5:a1:5a:bc:8c:72:91:6d:bf:03:27: 68 21:10:9e:5c:8a:cf:4b:87:83:e0:c2:d7:72:55:d5:42:d3:d1: 69 2b:76:b3:42:84:e0:e8:3b:80:b2:5f:55:e7:e0:f6:b6:21:c6: 70 fd:91:b5:c9:ba:fa:d8:ba:5c:8b:e1:f6:de:5d:cf:39:e6:92: 71 22:85:31:1f:c3:ed:19:db:0a:0b:f9:ef:a7:36:4d:e1:54:af: 72 8e:c0:59:25:43:e5:69:47:c4:e0:00:1e:21:eb:e6:b4:13:8f: 73 30:01 74-----BEGIN CA CERTIFICATE----- 75MIIBqTCCARKgAwIBAgIBATANBgkqhkiG9w0BAQUFADASMRAwDgYDVQQDDAdUZXN0IENBMCIYDzI 76wMTcwMTAxMDAwMDAwWhgPMjAxODAxMDEwMDAwMDBaMB8xHTAbBgNVBAMMFFRlc3QgSW50ZXJtZW 77RpYXRlIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDF+4GnG2phOBxq3t3bImFkeiKjO 78x3lklQXrTku/oH/Rgpw1oSl1b0F0/KlmJD95P/Y0s980fJ4DUqhgMhqcHWEBMHCS68Xm6IpK6e+ 798fkZgPNq1BAoUTgml+2tBpaFp7d8eDiQRN/XEORSokkibJhxUfWyE2p/CDR80MaZb3mY+QIDAQA 80BMA0GCSqGSIb3DQEBBQUAA4GBAH1nDzlOfOO68mO57W7sYfKKTx6C4ktEBPiloVq8jHKRbb8DJy 81EQnlyKz0uHg+DC13JV1ULT0St2s0KE4Og7gLJfVefg9rYhxv2Rtcm6+ti6XIvh9t5dzznmkiKFM 82R/D7RnbCgv576c2TeFUr47AWSVD5WlHxOAAHiHr5rQTjzAB 83-----END CA CERTIFICATE----- 84 85$ openssl x509 -text < [CERTIFICATE] 86Certificate: 87 Data: 88 Version: 3 (0x2) 89 Serial Number: 4 (0x4) 90 Signature Algorithm: sha1WithRSAEncryption 91 Issuer: CN = Test Intermediate CA 92 Validity 93 Not Before: Jan 1 00:00:00 2017 GMT 94 Not After : Jan 1 00:00:00 2018 GMT 95 Subject: CN = Test Cert 96 Subject Public Key Info: 97 Public Key Algorithm: rsaEncryption 98 RSA Public-Key: (1024 bit) 99 Modulus: 100 00:d1:d2:a7:fd:5f:56:b8:4a:4a:00:c4:f0:36:48: 101 0d:99:1e:ba:ca:8d:8c:0e:e9:5a:f4:31:94:26:f4: 102 24:77:0c:2d:76:39:fe:1e:51:9c:b1:3a:b2:61:ae: 103 f6:2b:41:46:92:81:b4:1e:35:73:bb:df:53:d6:63: 104 a4:07:58:e9:0a:40:7a:b7:71:a3:fd:7d:6a:3f:23: 105 ee:5e:76:90:3f:60:ea:85:6b:74:1b:1f:6a:40:27: 106 37:7f:ac:6e:97:ee:13:f7:cb:81:44:26:f3:25:48: 107 56:40:ef:33:84:c8:d7:52:66:8a:40:35:ed:ec:67: 108 95:c1:35:46:9e:db:9b:ce:9b 109 Exponent: 65537 (0x10001) 110 Signature Algorithm: sha1WithRSAEncryption 111 8e:94:5a:91:44:aa:ab:e4:bf:c4:ca:a3:ee:10:67:2d:3e:d5: 112 ac:b8:90:8b:4e:7f:3e:bc:83:bb:b2:c9:0c:a2:ae:fb:6c:b3: 113 5d:b7:40:20:9f:9b:7c:3d:5f:67:bc:0e:f9:20:bc:24:67:27: 114 a9:2e:81:08:e5:3f:ad:e9:b7:eb:a9:c5:58:55:55:f3:26:17: 115 26:46:5f:ef:20:38:c9:f2:81:ba:39:d9:28:4b:e8:83:ff:d7: 116 2e:87:72:36:77:0f:46:9b:a1:fe:d8:d8:20:50:68:c1:7b:66: 117 82:5d:62:94:90:98:71:8b:b9:83:69:a8:65:a4:58:5d:ce:90: 118 0a:53 119-----BEGIN CERTIFICATE----- 120MIIBqzCCARSgAwIBAgIBBDANBgkqhkiG9w0BAQUFADAfMR0wGwYDVQQDDBRUZXN0IEludGVybWV 121kaWF0ZSBDQTAiGA8yMDE3MDEwMTAwMDAwMFoYDzIwMTgwMTAxMDAwMDAwWjAUMRIwEAYDVQQDDA 122lUZXN0IENlcnQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANHSp/1fVrhKSgDE8DZIDZkeu 123sqNjA7pWvQxlCb0JHcMLXY5/h5RnLE6smGu9itBRpKBtB41c7vfU9ZjpAdY6QpAerdxo/19aj8j 1247l52kD9g6oVrdBsfakAnN3+sbpfuE/fLgUQm8yVIVkDvM4TI11JmikA17exnlcE1Rp7bm86bAgM 125BAAEwDQYJKoZIhvcNAQEFBQADgYEAjpRakUSqq+S/xMqj7hBnLT7VrLiQi05/PryDu7LJDKKu+2 126yzXbdAIJ+bfD1fZ7wO+SC8JGcnqS6BCOU/rem366nFWFVV8yYXJkZf7yA4yfKBujnZKEvog//XL 127odyNncPRpuh/tjYIFBowXtmgl1ilJCYcYu5g2moZaRYXc6QClM= 128-----END CERTIFICATE----- 129 130$ openssl asn1parse -i < [OCSP REQUEST] 131 0:d=0 hl=2 l= 66 cons: SEQUENCE 132 2:d=1 hl=2 l= 64 cons: SEQUENCE 133 4:d=2 hl=2 l= 62 cons: SEQUENCE 134 6:d=3 hl=2 l= 60 cons: SEQUENCE 135 8:d=4 hl=2 l= 58 cons: SEQUENCE 136 10:d=5 hl=2 l= 9 cons: SEQUENCE 137 12:d=6 hl=2 l= 5 prim: OBJECT :sha1 138 19:d=6 hl=2 l= 0 prim: NULL 139 21:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:449B1C5B31C6E9990966523E49C3F773C024190A 140 43:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:7F765910653BB5704124C41E94AEFCF940431A66 141 65:d=5 hl=2 l= 1 prim: INTEGER :04 142-----BEGIN OCSP REQUEST----- 143MEIwQDA+MDwwOjAJBgUrDgMCGgUABBREmxxbMcbpmQlmUj5Jw/dzwCQZCgQUf3ZZEGU7tXBBJMQ 144elK78+UBDGmYCAQQ= 145-----END OCSP REQUEST----- 146