Checking for required OCSP URLs

You're safe!

The reason the blog post doesn't say to inspect /etc/letsencrypt/renewal is that not everyone has that directory: it is specific to Certbot, but there are many other ACME clients out there which use different on-disk storage locations and formats.

And don't worry about your openssl output: every cert (until May 7, and unless you request the tlsserver profile) contains an OCSP URI. You only have a problem if the cert also contains the OCSP Must-Staple extension, which yours does not.

7 Likes