OCSP Stapling Moves Certificate Revocation Freshness Into the TLS Endpoint
OCSP Stapling Moves Certificate Revocation Freshness Into the TLS Endpoint A TLS endpoint can present a certificate chain that is cryptographically valid and still rely on separate state to establish that a certificate has not been revoked. When that state comes from the Online Certificate Status Protocol, direct client queries create an awkward dependency: connection establishment can depend on a CA-operated responder, and the query can disclose which certificate the client is checking.