Home / Alt manpages / openssl-ocsp(1ssl)

  • openssl-ocsp(1ssl)
  • OpenSSL command
  • linux

Build and Inspect OCSP Requests with OpenSSL

You will finish with a DER-encoded OCSP request, a readable inspection of its certificate identifier, and a safe pattern for sending it to a responder. The examples use the installed openssl ocsp command. The local package is OpenSSL 3.0.13, while the executable currently first on this machine is OpenSSL 3.6.1, so check the version on the host where a result matters. Allow about fifteen minutes, plus access to the issuer certificate, the certificate being checked and the responder URL.

This guide makes requests and reads responses. It does not revoke a certificate, change a CA database or enable a service. The commands normally run as an ordinary user. Use elevated privileges only if your certificate files are deliberately protected and your local policy permits access.

1. Confirm the command and its version

Start by confirming which executable and package you are using:

$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026

The manpage installed under the Ubuntu openssl package identifies OpenSSL 3.0.13. A different executable can have different defaults or option details, so keep this checkpoint with any diagnostic record. To see the options supported by the executable, run:

$ openssl ocsp -help

Checkpoint: you should see separate client and responder options, including -issuer, -cert, -reqout, -url, -respin and -text.

2. Gather the matching certificates

An OCSP request identifies a certificate through its issuer and serial number. Put the issuer certificate and the certificate being checked in readable files. The issuer must be the CA that issued the target certificate, not merely a root certificate that happens to be trusted on the machine.

$ ls -l /path/to/issuer.pem /path/to/certificate.pem
$ openssl x509 -in /path/to/certificate.pem -noout -subject -issuer -serial
subject=CN = service.example.test
issuer=CN = Example Issuing CA
serial=03E9

Compare the displayed issuer with the issuer certificate you plan to pass. If they do not match, stop and find the correct issuing certificate. Do not guess from filenames. A request can be syntactically valid while asking about the wrong certificate authority.

3. Create a request from a certificate

Pass -issuer before its corresponding -cert. The command may repeat the pair for certificates from different issuers, but each issuer must precede the certificates that use it:

$ openssl ocsp \
    -issuer /path/to/issuer.pem \
    -cert /path/to/certificate.pem \
    -reqout /path/to/ocsp-request.der
$ test -s /path/to/ocsp-request.der && echo 'request written'
request written

The output is DER, not a PEM text file. With a newly created request, this OpenSSL release adds an OCSP nonce by default. A nonce helps match a response to a request, but responders and intermediaries do not all handle it identically. Suppress it only when the responder requires that behaviour:

$ openssl ocsp \
    -issuer /path/to/issuer.pem \
    -cert /path/to/certificate.pem \
    -no_nonce \
    -reqout /path/to/ocsp-request-without-nonce.der

Do not overwrite a request you may need for an audit or a comparison. Shell redirection and an existing -reqout destination can replace useful evidence. Choose a new filename or copy the old file first.

4. Inspect the request before sending it

Read the DER request in text form without contacting a responder:

$ openssl ocsp \
    -reqin /path/to/ocsp-request.der \
    -req_text
OCSP Request Data:
    Version: 1 (0x0)
    Requestor List:
        Certificate ID:
          Hash Algorithm: sha1
          Issuer Name Hash: ...
          Issuer Key Hash: ...
          Serial Number: 03E9
    Request Extensions:
        OCSP Nonce: ...

The exact hashes and nonce are different for every issuer and request. Check the serial number and the presence or absence of the nonce. The default certificate identifier digest in this installed command is SHA-1. That describes the identifier hash, not the security of the certificate's public key or signature. If the responder requires another identifier digest, select it when creating the request:

$ openssl ocsp -sha256 \
    -issuer /path/to/issuer.pem \
    -cert /path/to/certificate.pem \
    -reqout /path/to/ocsp-sha256-request.der

You can use -serial instead of -cert when you know the decimal serial number and have the matching issuer certificate:

$ openssl ocsp \
    -issuer /path/to/issuer.pem \
    -serial 1001 \
    -reqout /path/to/serial-request.der

A value beginning with 0x is interpreted as hexadecimal. Avoid this shortcut when the certificate file is available: using the certificate lets you verify the intended serial before building the request.

5. Send the request and save the response

Use the responder URL supplied by the CA or service operator. Save the binary response and ask for a readable copy on standard output:

$ openssl ocsp \
    -issuer /path/to/issuer.pem \
    -cert /path/to/certificate.pem \
    -url https://ocsp.example.test/ \
    -resp_text \
    -respout /path/to/ocsp-response.der

A successful network exchange is not the same as a good status result. Read the response text and check its certificate status, response status, validity times and verification messages. A normal responder can report good, revoked or unknown; treat unknown as an operational result that needs investigation, not as proof that the certificate is safe.

For a previously saved response, inspect it without making another network request:

$ openssl ocsp \
    -respin /path/to/ocsp-response.der \
    -text \
    -CAfile /path/to/trusted-ca-bundle.pem

Normally allow response signature and certificate verification to run. The command uses the standard OpenSSL trust locations unless you select -CAfile, -CApath or -CAstore. If the responder omits its signing certificate, -verify_other can supply additional certificates. -VAfile explicitly supplies a trusted responder certificate.

6. Keep verification failures meaningful

Do not add -noverify to make a failed production check look successful. It disables verification of the response signature and nonce and is intended for debugging. The narrower options -no_signature_verify, -no_cert_verify and -no_cert_checks also weaken checks and should be confined to controlled tests.

The default five-minute validity tolerance exists because responder and client clocks are not perfectly synchronised. A response can still be stale or unusable. Use -validity_period only when you have an explicit operational reason, and use -status_age when a response without nextUpdate must not be older than a defined age:

$ openssl ocsp \
    -respin /path/to/ocsp-response.der \
    -CAfile /path/to/trusted-ca-bundle.pem \
    -status_age 3600

When diagnosing a failure, preserve the original response and record the command, OpenSSL version, trust input and system time. Do not replace a failed response with one produced using relaxed verification unless the file is clearly labelled as a test artefact.

7. Treat responder mode as a test tool

The same command can act as a small responder when -index is supplied. It requires a CA certificate and a responder signing certificate:

$ openssl ocsp \
    -index /path/to/demoCA/index.txt \
    -CA /path/to/demoCA/cacert.pem \
    -rsigner /path/to/responder.pem \
    -rkey /path/to/responder-key.pem \
    -port 8888 \
    -nrequest 1

This is suitable for a local demonstration or a test harness, not a general production OCSP service. The manpage describes simple HTTP handling, POST-only queries, serial processing and an inefficient text index. Binding a test listener can expose certificate status information or a private key if permissions are wrong, so keep the files private and use a controlled interface. Port 8888 is an example, not a recommendation to open a firewall.

-nrequest 1 makes the test process exit after one request. Without it, responder mode continues until stopped. If you started a foreground test accidentally, press Ctrl-C. The command does not modify the CA index, but any separate process that writes that index can change future responses.

Done means

  • The executable and OpenSSL version were recorded.
  • The issuer certificate was checked against the target certificate's issuer.
  • A DER request was written and inspected for the expected serial number.
  • Nonce and identifier digest choices were made deliberately.
  • Responses were saved before inspection and verified with the appropriate trust input.
  • Relaxed verification flags were not used for a production decision.
  • Any local responder was treated as a temporary test service and stopped afterwards.