tls.cert.not_revoked

Certificate Not Revoked

What we check

We query the certificate authority's revocation endpoints — the OCSP responder and/or CRL distribution point named in the certificate — to ask whether the certificate has been revoked. A signed "good" response from the authority confirms the certificate is not revoked.

What this finding means

The certificate authority confirms that this certificate is valid and has not been revoked. This is the expected, healthy state — the CA vouches for the certificate and no revocation event has been recorded.

How it's graded

A confirmed non-revoked status is a pass and carries no penalty. See Grading Methodology for the full scoring model.

Evidence example

Certificate serial: 04:B2:C3:D4:E5:F6:A7
OCSP status: good
CRL status: not listed

References