[openssl-users] Problem checking certificate with OCSP

Walter H. walter.h at mathemainzel.info
Mon Oct 5 11:58:15 UTC 2015


Hello,

attached is the certificate and its chain of  https://revoked.grc.com/

doing this:

openssl ocsp -no_nonce -issuer chain.pem -cert cert.pem -text -url
http://ocsp2.globalsign.com/gsdomainvalg2

goves the following:

OCSP Request Data:
    Version: 1 (0x0)
    Requestor List:
        Certificate ID:
          Hash Algorithm: sha1
          Issuer Name Hash: 45658DA20174402FF48B3A6AC0BC69208095C7CA
          Issuer Key Hash: 96ADFAB05BB983642A76C21C8A69DA42DCFEFD28
          Serial Number: 112155688D380775DA34C5DF97433ED3F6A7
Error querying OCSP responsder
139928584042312:error:27076072:OCSP routines:PARSE_HTTP_LINE1:server response
error:ocsp_ht.c:250:Code=403,Reason=Forbidden

where is the problem for this strange error?

I'm running CentOS 6.7 64-bit, and OpenSSL is the latest provided update
from repository;

Thanks;

Greetings,
Walter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: cert.pem
Type: application/octet-stream
Size: 1798 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20151005/55428823/attachment.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: chain.pem
Type: application/octet-stream
Size: 2878 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20151005/55428823/attachment-0001.obj>


More information about the openssl-users mailing list