tls.cert.not_revoked
Certificate Not Revoked
What we check
We query the certificate authority's revocation endpoints — the OCSP responder and/or CRL distribution point named in the certificate — to ask whether the certificate has been revoked. A signed "good" response from the authority confirms the certificate is not revoked.
What this finding means
The certificate authority confirms that this certificate is valid and has not been revoked. This is the expected, healthy state — the CA vouches for the certificate and no revocation event has been recorded.
How it's graded
A confirmed non-revoked status is a pass and carries no penalty. See Grading Methodology for the full scoring model.
Evidence example
Certificate serial: 04:B2:C3:D4:E5:F6:A7
OCSP status: good
CRL status: not listed