OCSP server sending expired responses + stapling breaks Chrome

It’s not limited to chrome, we have Java client/server apps with the clients making Rest calls over HTTPS.
Recents JDK do check OCSP validity periods making the applications unusable for the time being.
A workaround is to disable OCSP checking in the JDK preferences but that’s not easy to explain to a customer…

1 Like