Skip to content

OCSP

Start the service

openssl ocsp -index ca/component-ca01/db/component-ca01.db -port 80 -rsigner certs/ocsp.crt -rkey certs/ocsp.key -CA ca/component-ca01/component-ca01.crt -text

start the service with a log file and in background

openssl ocsp -index ca/component-ca01/db/component-ca01.db -port 80 -rsigner certs/ocsp.crt -rkey certs/ocsp.key -CA ca/component-ca01/component-ca01.crt -text -out log.txt &

Check a valid certificate

openssl ocsp -CAfile ca/root-ca01/root-ca01.crt -issuer ca/component-ca01/component-ca01.crt -cert ca/component-ca01/archives/02.pem -url http://localhost:80 -resp_text

Check a revoked certificate

openssl ocsp -CAfile ca/root-ca01/root-ca01.crt -issuer ca/component-ca01/component-ca01.crt -cert ca/component-ca01/archives/01.pem -url http://localhost:80 -resp_text