What is the relationship between the revoking list and OCSP Stapling?

If webservers refuse to serve an OCSP response with "revoked" status but instead keep sending the response with "good", even if it's already invalidated due to the "Next Update" time being in the past, well, then for that specific site it's not beneficial..

That would require the must staple extension in the end leaf certificate.

5 Likes