Build and Inspect OCSP Requests with OpenSSL
You will finish with a DER-encoded OCSP request, a readable inspection of its certificate identifier, and a safe pattern for sending it to a responder. The examples use the installed openssl ocsp command. The local package is OpenSSL 3.0.13, while the executable currently first on this machine is OpenSSL 3.6.1, so check the version on the host where a result matters. Allow about fifteen minutes, plus access to the issuer certificate, the certificate being checked and the responder URL.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide makes requests and reads responses. It does not revoke a certificate, change a CA database or enable a service. The commands normally run as an ordinary user. Use elevated privileges only if your certificate files are deliberately protected and your local policy permits access.
1. Confirm the command and its version
Start by confirming which executable and package you are using:
$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
The manpage installed under the Ubuntu openssl package identifies OpenSSL 3.0.13. A different executable can have different defaults or option details, so keep this checkpoint with any diagnostic record. To see the options supported by the executable, run:
$ openssl ocsp -help
Checkpoint: you should see separate client and responder options, including -issuer, -cert, -reqout, -url, -respin and -text.
2. Gather the matching certificates
An OCSP request identifies a certificate through its issuer and serial number. Put the issuer certificate and the certificate being checked in readable files. The issuer must be the CA that issued the target certificate, not merely a root certificate that happens to be trusted on the machine.
$ ls -l /path/to/issuer.pem /path/to/certificate.pem
$ openssl x509 -in /path/to/certificate.pem -noout -subject -issuer -serial
subject=CN = service.example.test
issuer=CN = Example Issuing CA
serial=03E9
Compare the displayed issuer with the issuer certificate you plan to pass. If they do not match, stop and find the correct issuing certificate. Do not guess from filenames. A request can be syntactically valid while asking about the wrong certificate authority.
3. Create a request from a certificate
Pass -issuer before its corresponding -cert. The command may repeat the pair for certificates from different issuers, but each issuer must precede the certificates that use it:
$ openssl ocsp \
-issuer /path/to/issuer.pem \
-cert /path/to/certificate.pem \
-reqout /path/to/ocsp-request.der
$ test -s /path/to/ocsp-request.der && echo 'request written'
request written
The output is DER, not a PEM text file. With a newly created request, this OpenSSL release adds an OCSP nonce by default. A nonce helps match a response to a request, but responders and intermediaries do not all handle it identically. Suppress it only when the responder requires that behaviour:
$ openssl ocsp \
-issuer /path/to/issuer.pem \
-cert /path/to/certificate.pem \
-no_nonce \
-reqout /path/to/ocsp-request-without-nonce.der
Do not overwrite a request you may need for an audit or a comparison. Shell redirection and an existing -reqout destination can replace useful evidence. Choose a new filename or copy the old file first.
4. Inspect the request before sending it
Read the DER request in text form without contacting a responder:
$ openssl ocsp \
-reqin /path/to/ocsp-request.der \
-req_text
OCSP Request Data:
Version: 1 (0x0)
Requestor List:
Certificate ID:
Hash Algorithm: sha1
Issuer Name Hash: ...
Issuer Key Hash: ...
Serial Number: 03E9
Request Extensions:
OCSP Nonce: ...
The exact hashes and nonce are different for every issuer and request. Check the serial number and the presence or absence of the nonce. The default certificate identifier digest in this installed command is SHA-1. That describes the identifier hash, not the security of the certificate's public key or signature. If the responder requires another identifier digest, select it when creating the request:
$ openssl ocsp -sha256 \
-issuer /path/to/issuer.pem \
-cert /path/to/certificate.pem \
-reqout /path/to/ocsp-sha256-request.der
You can use -serial instead of -cert when you know the decimal serial number and have the matching issuer certificate:
$ openssl ocsp \
-issuer /path/to/issuer.pem \
-serial 1001 \
-reqout /path/to/serial-request.der
A value beginning with 0x is interpreted as hexadecimal. Avoid this shortcut when the certificate file is available: using the certificate lets you verify the intended serial before building the request.
5. Send the request and save the response
Use the responder URL supplied by the CA or service operator. Save the binary response and ask for a readable copy on standard output:
$ openssl ocsp \
-issuer /path/to/issuer.pem \
-cert /path/to/certificate.pem \
-url https://ocsp.example.test/ \
-resp_text \
-respout /path/to/ocsp-response.der
A successful network exchange is not the same as a good status result. Read the response text and check its certificate status, response status, validity times and verification messages. A normal responder can report good, revoked or unknown; treat unknown as an operational result that needs investigation, not as proof that the certificate is safe.
For a previously saved response, inspect it without making another network request:
$ openssl ocsp \
-respin /path/to/ocsp-response.der \
-text \
-CAfile /path/to/trusted-ca-bundle.pem
Normally allow response signature and certificate verification to run. The command uses the standard OpenSSL trust locations unless you select -CAfile, -CApath or -CAstore. If the responder omits its signing certificate, -verify_other can supply additional certificates. -VAfile explicitly supplies a trusted responder certificate.
6. Keep verification failures meaningful
Do not add -noverify to make a failed production check look successful. It disables verification of the response signature and nonce and is intended for debugging. The narrower options -no_signature_verify, -no_cert_verify and -no_cert_checks also weaken checks and should be confined to controlled tests.
The default five-minute validity tolerance exists because responder and client clocks are not perfectly synchronised. A response can still be stale or unusable. Use -validity_period only when you have an explicit operational reason, and use -status_age when a response without nextUpdate must not be older than a defined age:
$ openssl ocsp \
-respin /path/to/ocsp-response.der \
-CAfile /path/to/trusted-ca-bundle.pem \
-status_age 3600
When diagnosing a failure, preserve the original response and record the command, OpenSSL version, trust input and system time. Do not replace a failed response with one produced using relaxed verification unless the file is clearly labelled as a test artefact.
7. Treat responder mode as a test tool
The same command can act as a small responder when -index is supplied. It requires a CA certificate and a responder signing certificate:
$ openssl ocsp \
-index /path/to/demoCA/index.txt \
-CA /path/to/demoCA/cacert.pem \
-rsigner /path/to/responder.pem \
-rkey /path/to/responder-key.pem \
-port 8888 \
-nrequest 1
This is suitable for a local demonstration or a test harness, not a general production OCSP service. The manpage describes simple HTTP handling, POST-only queries, serial processing and an inefficient text index. Binding a test listener can expose certificate status information or a private key if permissions are wrong, so keep the files private and use a controlled interface. Port 8888 is an example, not a recommendation to open a firewall.
-nrequest 1 makes the test process exit after one request. Without it, responder mode continues until stopped. If you started a foreground test accidentally, press Ctrl-C. The command does not modify the CA index, but any separate process that writes that index can change future responses.
Done means
- The executable and OpenSSL version were recorded.
- The issuer certificate was checked against the target certificate's issuer.
- A DER request was written and inspected for the expected serial number.
- Nonce and identifier digest choices were made deliberately.
- Responses were saved before inspection and verified with the appropriate trust input.
- Relaxed verification flags were not used for a production decision.
- Any local responder was treated as a temporary test service and stopped afterwards.