a revoke does not work. otherwise you would need a massive amount of servers. this is the reason why the certification lifetime will be reduced to 90 days Answer from ProfessionalBee4758 on reddit.com
🌐
SSLShopper
sslshopper.com › ssl-checker.html
SSL Checker
Use our fast SSL Checker to help you quickly diagnose problems with your SSL certificate installation. You can verify the SSL certificate on your web server to make sure it is correctly installed, valid, trusted and doesn't give any errors to any of your users.
🌐
UKC
uk-cheapest.co.uk › how to: check ssl with ssl shopper ssl checker
How to: Check SSL with SSL Shopper SSL Checker - UK-Cheapest.co.uk
January 12, 2024 - SSL Shopper’s SSL Checker is designed to verify the status and correctness of SSL certificates on websites.
Discussions

Well done SSL Shopper
Marketing at it's best. Using your future date cert More on reddit.com
🌐 r/iiiiiiitttttttttttt
7
183
July 31, 2023
Can SSL even be trusted or am I just completely misunderstanding?
a revoke does not work. otherwise you would need a massive amount of servers. this is the reason why the certification lifetime will be reduced to 90 days More on reddit.com
🌐 r/sysadmin
52
13
December 10, 2024
SSL Checker - Get Detailed SSL Certificate Information
Seems much more comprehensive than what I was going to suggest/saw here the other day http://www.ssltest.net/ More on reddit.com
🌐 r/sysadmin
10
8
January 8, 2012
Certificate chain incomplete and not incomplete
try this site https://whatsmychaincert.com More on reddit.com
🌐 r/exchangeserver
9
10
May 6, 2021
People also ask

Does an SSL Checker work for wildcard or multi-domain certificates?
Yes, most SSL Checkers support wildcard and multi-domain certificates, providing details for all covered subdomains and domains.
🌐
cyberpanel.net
cyberpanel.net › blog › ssl-checker
SSL Checker: Check SSL/TLS Certificates for Website Security
How do I know if my website is using an SSL certificate?
Check for a padlock symbol in the browser address bar and ensure the URL begins with "https://". You can also use an SSL Checker for detailed verification.
🌐
cyberpanel.net
cyberpanel.net › blog › ssl-checker
SSL Checker: Check SSL/TLS Certificates for Website Security
What is the validity period of an SSL certificate?
SSL certificates typically last between 1 to 2 years, depending on the issuing authority. Regular renewal is essential to maintain secure connections.
🌐
cyberpanel.net
cyberpanel.net › blog › ssl-checker
SSL Checker: Check SSL/TLS Certificates for Website Security
🌐
GitHub
github.com › bobbyiliev › bash-ssl-checker-tool
GitHub - bobbyiliev/bash-ssl-checker-tool: A simple Bash script to check SSL certificate details for any domain from the command line, inspired by https://sslshopper.com
A simple Bash script to check SSL certificate details for any domain from the command line, inspired by https://sslshopper.com - bobbyiliev/bash-ssl-checker-tool
Starred by 50 users
Forked by 19 users
Languages   Shell
🌐
Reddit
reddit.com › r/iiiiiiitttttttttttt › well done ssl shopper
r/iiiiiiitttttttttttt on Reddit: Well done SSL Shopper
July 31, 2023 - 357K subscribers in the iiiiiiitttttttttttt community. Hello, IT. Have you tried turning it off and on again?
🌐
CyberPanel
cyberpanel.net › blog › ssl-checker
SSL Checker: Check SSL/TLS Certificates for Website Security
April 28, 2025 - SSL Shopper checks for the validity of the certificate with expiration dates, issuer details, and domain matching. It is quite user-friendly and best for beginners. GlobalSign SSL Configuration Checker provides insights into the SSL certificate ...
Find elsewhere
🌐
ResearchGate
researchgate.net › figure › SSL-Shopper-Certificate-Checker_fig20_341509518
SSL Shopper Certificate Checker | Download Scientific Diagram
Download scientific diagram | SSL Shopper Certificate Checker from publication: Security analysis of website certificate validation Report for the Computer Security at the Politecnico di Torino | Certification, Computer Security and Websites | ResearchGate, the professional network for scientists.
🌐
IPSERVERONE
ipserverone.info › knowledge-base › how-to-check-ssl-certificate-details-using-ssl-checker-and-firefox
How to check SSL certificate details using SSL Checker and Firefox - IPSERVERONE
SSL Checker from SSL Shopper is a useful website to verify whether the SSL certificate installed on your domain is functioning properly.
🌐
Reddit
reddit.com › r/sysadmin › can ssl even be trusted or am i just completely misunderstanding?
r/sysadmin on Reddit: Can SSL even be trusted or am I just completely misunderstanding?
December 10, 2024 -

This is now the second time within probably six months I have checked on a website certificate because an end user is getting an SSL revocation block from our antivirus software. I am running into the same frustration as I did the first time I had this happen. I checked various SSL checkers and some are saying the SSL is revoked and others are saying it's fine.

I go to the source of the certificate in question (Sectigo) in this case https://www.sectigostore.com/ssl-tools/ssl-checker.php and it shows the URL I am checking on in this case is just fine: https://kern.facilitysoft.org.

All the Chromium based browsers show that it's fine. Firefox seems to know better. Same in the first time I did this. Firefox was the browser that reliably told me the certificate was revoked.

Thanks to GPT I was able to use openssl on the cli in both cases to check the source for the revocation status. And sure enough, Sectigo's OCSP is telling me it was revoked on the 3rd.

I reached out to Sectigo support (I am not even a customer) and they sent me to another site https://www.sslshopper.com/ssl-checker.html?hostname=+kern.facilitysoft.org+ as proof that it was good.

Here is another checker that confirms it's revoked: https://www.ssllabs.com/ssltest/analyze.html?d=kern.facilitysoft.org&latest.

I also ran the following commands to verify myself direct from the source:

wget 

openssl x509 -inform DER -in SectigoRSADomainValidationSecureServerCA.crt -out issuer_cert.pem -outform PEMhttp://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt

I exported the certificate chain to the Base64 PEM chain file from the browser.

openssl ocsp -issuer issuer_cert.pem -cert kern.facilitysoft.org.pem -url 

WARNING: no nonce in response
Response verify OK
kern.facilitysoft.org.pem: revoked
This Update: Dec  8 00:29:44 2024 GMT
Next Update: Dec 15 00:29:43 2024 GMT
Revocation Time: Dec  3 22:18:42 2024 GMThttp://ocsp.sectigo.com

Sure enough it gives me the exact date and time the certificate was revoked.

I followed the same steps for a sister site they have as a sanity check. I had to also export the certificate as a Base64 PEM chain file first just like on the other site above.

openssl ocsp -issuer issuer_cert.pem -cert losrios.facilitysoft.org.pem  -url 

WARNING: no nonce in response
Response verify OK
losrios.facilitysoft.org.pem: good
This Update: Dec  8 12:09:55 2024 GMT
Next Update: Dec 15 12:09:54 2024 GMThttp://ocsp.sectigo.com

And sure enough, no revocation on the sanity check site.

This is just like the first time I ran across this. Luckily in the first case I was able to find out how to contact the IT for the site and after arguing with them they submitted a ticket and fixed it about 24 hours later once I was able to prove they were using a revoked certificate.

In this case I cannot figure out how to contact them. I could ask my end user if they have more information, but I am almost certain that won't fly in this case. I am probably just going to make an exception in our AV policy for this site.

Am I completely misunderstanding the situation or do I have legitimate reason to question the validity of the whole SSL structure in the first place? This doesn't make sense to me. It seems to void the whole purpose in my mind and shows me it cannot be trusted.

The certificate was revoked. How can I trust this whole SSL system if this is the second time I am running into this issue from a different issuer and getting unreliable results.

I am asking because I really want to know if I am missing something here.

Top answer
1 of 7
31
a revoke does not work. otherwise you would need a massive amount of servers. this is the reason why the certification lifetime will be reduced to 90 days
2 of 7
16
Firstly, SSL/TLS can be trusted most of the time and yes, it does work in a vast number of cases but I get your frustration. Unfortunately I've even known Microsoft to mess up and forget to renew a certificate and yeah, that's not the same as revocation but staying on top of certs is hard work, especially now the consensus is to make the durations shorter. It's weird that you've had 2 revocation issues so close together but at the end of the day there are millions of websites using TLS and it all works, most of the time. It's now time for my routine whinge/rant/lecture but I think it's always worth remembering that TLS says nothing about the legitimacy of the website content behind the certificate. All TLS does is ensure that the tunnel between device y and server z is secure; I've got into a few spats on twitter about this but my view is, technically there's nothing wrong with self signed certificates because they perform the end to end encryption. The reason for having a publicly trusted cert is trust. That said, anyone can buy a cert and put anything behind it - malware, phishing etc. TLS is just an encryption system at the end of the day, and it can be used by anyone, good or bad. (I've deliberately skipped over the huge number of algorithms on offer with TLS because it's so arcane - RSA, AES, ECDHE etc. I've also not mentioned the fun game of "Can I get a perfect score on SSL labs' website checker?", because after 20 years I never achieved more than 90% despite trying every config I can think of)
🌐
Hostcheetah
community.hostcheetah.com › topic › 493 › ssl-checker-online-tools-and-resources
SSL Checker Online Tools and Resources | LiquidLayer.net | Tech | Page 1
JavaScript must be enabled to use this website · Shared Web Hosting · Domains · VPS Servers · Dedicated Hosting · Data Centers · Blog Layer · Contact Us · Advanced Search · forum login
🌐
GeoCerts
geocerts.com › ssl-checker
Check SSL Certificate - GeoCerts
SSL Installation Checker · SSL Labs Server Test · CSR Decoder · Certificate Decoder · Certificate Key Matcher · Generate CSR · Install SSL · Support Desk · VMC & CMC Mark Certificates · Trust Lifecycle Manager (TLM) Software Trust Manager (STM) Basic DV SSL ·
🌐
SSL Checker
sslchecker.com › sslchecker
SSL Certificate Checker
Receive infrequent updates on hottest SSL deals. No spam. Ever
🌐
SSL Labs
ssllabs.com › ssltest
SSL Server Test (Powered by Qualys SSL Labs)
A comprehensive free SSL test for your public web servers.
🌐
SSLShopper
sslshopper.com › csr-decoder.html
CSR Decoder - Check CSR to verify its contents
Use this CSR Decoder to decode your SSL Certificate Signing Request and verify that it has the correct information. This tool will decode CSRs so you can easily see their contents.
🌐
SSL Checker
sslchecker.com › certdecoder
SSL Certificate Decoder
Receive infrequent updates on hottest SSL deals. No spam. Ever