OCSP: URI: http://ocsp.comodoca.com - why not https?

I believe that some kind of industry norms or policies require the availability of an OCSP responder that does not require HTTPS.

This is a privacy problem, a disadvantage in OCSP itself, and it is definitely preferable for privacy purposes for sites to use stapling. The way the unencrypted query leaks the identity of the visited site is a privacy harm to the user, and there may be entities that would otherwise not have been on-path that are logging those queries, but I don’t believe there’s anything Let’s Encrypt could have done to avoid advertising an unencrypted OCSP responder – I think it’s a requirement imposed on us.

Once the service and client are more mature, we will definitely be looking into ways to encourage more widespread use of stapling. As has been mentioned in another thread, it can be done now if you have the right expertise. :smile:

3 Likes