` reads). %> How to Find Out if My Certificate Was Revoked? | TLS Radar Skip to main content
outage-prevention 3 min read By TLS Radar Team

How to Find Out if My Certificate Was Revoked?

You can't tell whether a certificate has been revoked by looking at the file - revocation doesn't change it. Browsers check with the certificate authority directly, through a CRL or OCSP, and you can run the same check yourself, but it's only a snapshot: revocation can happen anytime, and sometimes the check itself is broken because the CA's own CRL or OCSP responder has a problem. TLS Radar reads revocation status on every scan on Business and Enterprise plans, and separately checks CA revocation infrastructure for problems on every scan, free or full, so a broken check is never mistaken for good news.

You can't tell by looking at the certificate file itself - revocation doesn't change a single byte of it. The only way to know is to ask your certificate authority directly whether it has cancelled the certificate. Browsers do this automatically for every visitor, using either a list of cancelled certificates (a CRL) or a server that answers yes-or-no questions about one certificate at a time (OCSP). You can run the same check yourself, or use something that runs it continuously.

How to check revocation status yourself

  1. Open your certificate details in the browser (click the padlock icon) and look for a revocation or validity status - most browsers surface this without any extra tooling.
  2. For a direct check, get the OCSP responder URL from the certificate: openssl x509 -in yourcert.pem -noout -ocsp_uri.
  3. Query it: openssl ocsp -issuer chain.pem -cert yourcert.pem -url <responder-url> -text, then read the response status - "good," "revoked," or "unknown."

The catch is timing. Revocation can happen at any point after issuance, not just at renewal, so a check from last week says nothing about today. A one-off check is a snapshot, not a standing answer.

What it means when the check itself doesn't work

There's a second catch that's easy to miss: sometimes the check itself doesn't work, because your CA's own CRL or OCSP responder is broken, not your certificate. In one week in September 2026, at least two CAs had exactly this problem, both caught by someone outside the CA rather than found internally.

Certum's certificate lists contained an encoding error: the signature algorithm identifier used an incorrect encoding (300c06082a8648ce3d0403030500 instead of the correct 300a06082a8648ce3d040303), deviating from RFC 5758 (Mozilla Bugzilla 2075242). Telia's lists had two separate problems: CRLs for its EC-384 issuer keys were signed with the wrong algorithm for that key size, and the signature field carried a disallowed parameter, a defect Telia traced to its CA software vendor's implementation, not its own configuration (Mozilla Bugzilla 2075488). Telia only found out because a third party reported it on September 23; its own linting tools had missed both issues.

A check that treats no answer as not revoked gives you false confidence at exactly the wrong moment. The two outcomes need to be told apart: a clean "not revoked," and "your CA's checking systems aren't working right now, so nobody can get a reliable answer, including you."

What actually answers the question, reliably

A single manual check answers the question for one moment in time. What actually answers it on an ongoing basis is monitoring that checks status continuously and distinguishes a clean result from a broken check, rather than treating silence as good news.

TLS Radar reads your certificate's revocation status on every scan on Business and Enterprise plans, checking the stapled OCSP response first and falling back to the CRL named by the certificate. We also check your CA's CRL and OCSP responder for problems on every scan, free or full, so a broken check is never silently read as good news.

Check revocation status in our free scanner, no account required

We check your certificate's revocation status and your CA's revocation infrastructure, the same way a browser does.

Create an account to get notified when your certificate is suddenly revoked

TLS Radar reads your certificate's revocation status on every scan, so you don't have to rely on your CA vendor's notification.

Related reading

Frequently asked questions

How do I find out if my certificate was revoked?
You can't tell from the certificate file itself. Check directly with your certificate authority through a CRL or OCSP responder, either manually with a tool like openssl or continuously with a monitoring service.
Why isn't a one-time check enough?
Revocation can happen at any point after issuance, not just at renewal. A check from last week says nothing about whether the certificate has been revoked since.
What does it mean if the check comes back with no answer?
It can mean the certificate is fine, or it can mean the CA's own CRL or OCSP responder is broken and can't give a reliable answer. Treating no answer as not revoked is a mistake - the two cases need to be told apart.
Has a CA's revocation checking actually broken like this?
Yes. In one week in September 2026, Certum's certificate lists had an encoding error and Telia's were signed with the wrong algorithm, so certificates from either CA had no reliable way to be checked for a time (Mozilla Bugzilla 2075242, 2075488).
Does TLS Radar check this for me?
Yes. TLS Radar reads your certificate's revocation status on every scan on Business and Enterprise plans, and checks your CA's CRL and OCSP responder for problems on every scan, free or full.

Get the next post in your inbox

TLS monitoring tips and product updates. No spam, unsubscribe anytime.

Keep reading

Comparing tools? See how TLS Radar stacks up against DigiCert and SSL.com.