TLS Must-Staple Turns OCSP Stapling into Certificate Policy
TLS Must-Staple Turns OCSP Stapling into Certificate Policy OCSP stapling lets a TLS server deliver certificate-status evidence inside the handshake instead of making each client contact the certificate authority’s OCSP responder. That arrangement reduces an extra network dependency for the client, but ordinary stapling is optional: the absence of a stapled response does not, by itself, prove that the certificate is invalid. The X.509 TLS Feature extension changes that condition when it advertises status_request. Commonly called Must-Staple in this use, the certificate states that the server is expected to provide the corresponding TLS feature. A client that both requests the feature and enforces the certificate extension can reject a connection when the required status response is missing.