Modest Proposal for Preserving OCSP

Because this idea has now come up a few times here (also in this thread: Sunsetting of OCSP in favor of older technology?) I have setup a public test site so that you can see whether your browser/TLS client actually supports OCSP must-staple.

The site is deliberately broken: It uses a cert with must-staple extension, but doesn't actually staple OCSP. A conforming TLS client must fail the connection. If your client connects nevertheless, it does not support OCSP must staple.

https://must-staple-test.germancoding.com/

Spoiler: The results aren't great.

11 Likes