Modest Proposal for Preserving OCSP

There are a lot of servers out there that aren't really being "administrated". If someone needed to upgrade its software or reconfigure it in order for it to continue working, it will probably just stop working. Some of them might make their way here, asking us how they're supposed to log into their system to update it.

But I think the most practical version of what you're suggesting is what they are currently considering, of continuing to support OCSP for must-staple certificates, and only must-staple. This takes a lot of load off of their OCSP systems, and gives the benefit of stapling for servers that do have it set up properly.

I'm not sure how you'd convince the people running all the various servers to either switch to Caddy or to configure however stapling works best on their existing servers, but doing so sounds great to me. It may be that Let's Encrypt trying to push for it might help, but there are many other free CAs that are just a ACME-server configuration option away, so I'm not sure that they really have as much influence as you're hoping. (Certainly Google saying that sites using must-staple would get an SEO boost would be more helpful, but I tend to doubt they'd go that direction.)

4 Likes