What is the relationship between the revoking list and OCSP Stapling?

Hm, RFC 6066 doesn't say anything about it.

"Close to expiration" is a, well, not very hard definition :stuck_out_tongue:

The Baseline Requirements do have some to say about the lifetime:

4.9.10 On‑line revocation checking requirements

(...)
4. For OCSP responses with validity intervals greater than or equal to sixteen hours,
then the CA SHALL update the information provided via an Online Certificate
Status Protocol at least eight hours prior to the nextUpdate, and no later than four
days after the thisUpdate.

So regular (≥16 hours) OCSP responses are renewed at least every 4 days, probably earlier. See also this incident: 2021.09.07 Delay updating OCSP responses

Therefore, webservers might choose to update the OCSP responses also at least every 4 days, so it'll always have a "fresh" one.

4 Likes