#ocsp
In anticipation of Let's Encrypt dropping Must-Staple support on May 7th and OCSP 3 months later, our services previously using OCSP stapling and Must-Staple have been moved to the Let's Encrypt `tlsserver` profile made publicly usable a couple weeks ago.

community.letsencrypt.org/t/removing-o...
Removing OCSP URLs from Certificates
Let’s Encrypt will be removing OCSP URLs from certificates on May 7, 2025 as part of our plan to drop OCSP support and instead support certificate revocation information exclusively via CRLs. Subscri...
community.letsencrypt.org
May 5, 2025 at 2:17 AM
The built-in nginx support for OCSP stapling doesn't have a way to properly save the last valid result and reuse it but nginx fully supports handling it via an external service. We use github.com/tomwassenber... for reliable OCSP stapling and it has always worked very well for us.
GitHub - tomwassenberg/certbot-ocsp-fetcher: A tool that primes the OCSP cache of nginx for certificates managed by Certbot, in order to make OCSP stapling work reliably.
A tool that primes the OCSP cache of nginx for certificates managed by Certbot, in order to make OCSP stapling work reliably. - tomwassenberg/certbot-ocsp-fetcher
github.com
December 12, 2024 at 3:35 PM
We're very disappointed Let's Encrypt is ending support for proper revocation checks via OCSP Must-Staple which is the only efficient, private and secure method not depending on a browser-specific service:

letsencrypt.org/2024/12/05/e...

No replacement is being offered for the feature.
Ending OCSP Support in 2025
Earlier this year we announced our intent to provide certificate revocation information exclusively via Certificate Revocation Lists (CRLs), ending support for providing certificate revocation informa...
letsencrypt.org
December 12, 2024 at 3:34 PM
原来今年开始 Let's Encrypt 就不再支持 OCSP 了,怪不得今天配置 SSL 的时候提示证书不包含 OCSP 验证地址
letsencrypt.org/2024/12/05/e...
Ending OCSP Support in 2025
Earlier this year we announced our intent to provide certificate revocation information exclusively via Certificate Revocation Lists (CRLs), ending support for providing certificate revocation informa...
letsencrypt.org
May 27, 2025 at 7:18 AM
Drone Forces struck three air defense systems in three days

Operators of the Asgard battalion within the 412th Nemesis SBS Brigade, in cooperation with the 12th OCSP and the special unit of the Ukrainian Ministry of Defense's GUR "Kabul 9", hit three expensive enemy SAM
November 28, 2025 at 2:12 PM
世界最大の認証局のLet’s Encryptが「オンライン証明書状態プロトコル(OCSP)」のサポートを打ち切ると発表
https://gigazine.net/news/20240724-letsencrypt-ocsp/
世界最大の認証局のLet’s Encryptが「オンライン証明書状態プロトコル(OCSP)」のサポートを打ち切ると発表
証明書認証局(CA)のLet's Encryptが、公開鍵の証明書の失効状態を取得する通信プロトコルであるオンライン証明書状態プロトコル(OCSP)のサポートを終了することを明らかにしました。
gigazine.net
July 24, 2024 at 6:17 AM
Operators of the Asgard battalion as part of the 412th Nemesis SBS Brigade, in cooperation with the 12th OCSP and the special unit of the GUR of the Ministry of Defense of Ukraine "Kabul 9", hit three expensive enemy SAM systems:

• "Buk-M1"
• "Buk-M2"
• "Tor-M2"
November 28, 2025 at 10:35 PM
Should your locally operated PKI follow Let's Encrypt's decision to move from OCSP to CRL? Methinks not, and here's why: it-pro-berlin.de/2025/01/ocsp...
OCSP – Should I stay or should I go? – Evgenij Smirnov – IT Pro aus Berlin
it-pro-berlin.de
January 12, 2025 at 10:30 PM
Let’s Encrypt to End Support for Online Certificate Status Protocol (OCSP)
Let’s Encrypt to End Support for Online Certificate Status Protocol (OCSP)
Let’s Encrypt, a leading provider of free SSL/TLS certificates, has officially announced its timeline for discontinuing support for the Online Certificate Status Protocol (OCSP) in favor of Certificate Revocation Lists (CRLs).
cybersecuritynews.com
December 10, 2024 at 2:58 AM
No, because Let's Encrypt is going to stop providing an OCSP server in the certificates. There will no longer be any non-expired certificates with an OCSP server specified when they take down their OCSP server.
December 12, 2024 at 4:32 PM
Nginx 1.31 introduces HTTP forward proxy support and addresses security vulnerabilities in HTTP/2, HTTP/3, OCSP, and core modules.
linuxiac.com/nginx-1-31-r...

#Nginx #OpenSource
Nginx 1.31 Released with HTTP Forward Proxy Support
Nginx 1.31 introduces HTTP forward proxy support and addresses security vulnerabilities in HTTP/2, HTTP/3, OCSP, and core modules.
linuxiac.com
May 13, 2026 at 8:38 PM
However, there are reliable implementations of OCSP stapling including Caddy and the generic certbot-ocsp-fetcher which is designed for use with nginx's support for configuring using an OCSP response from storage instead of having nginx fetch it at runtime since it doesn't save that anywhere.
December 12, 2024 at 4:36 PM
horseglue
YouTube video by Ekko Astral - Topic
music.youtube.com
October 26, 2025 at 3:52 PM
(b) Private keys are stolen and attackers can impersonate the certificate holder until the certificate becomes invalid. Even if revocation mechanisms (CRLs, OCSP) fail, expiration puts a limit on misuse.
August 12, 2025 at 10:11 AM
Enforcing OCSP hard fail means enforcing that a valid OCSP response was either stapled by the server or the client was able to obtain one itself from the OCSP server. Non-stapling approach is the privacy issue: it informs a CA server about a user connecting to a server with a given certificate.
December 12, 2024 at 4:33 PM
Your lap warmer and quiet companion awaits: Brooklyn, located in Fountain Valley, CA.

Learn more: https://www.petfinder.com/cat/brooklyn-74070840/ca/fountain-valley/ocsp-cat-rescue-ca1579/
December 14, 2024 at 9:00 PM
Just because…NBA Playoffs hoops🏀📺🔇 … 🍻🎶🎙️🥁🎸🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊🔊

m.youtube.com/watch?v=ocsP...
April Fool (2022 Remaster)
YouTube video by Soul Asylum - Topic
m.youtube.com
April 26, 2026 at 9:35 PM
In 2025, Let’s Encrypt are going to drop support for OCSP revocation checking in their certificates.

This shouldn't cause any problems at all, but I have a funny feeling that it will...

scotthelme.co.uk/lets-encrypt...
Let's Encrypt to end OCSP support in 2025
Well, the writing has been on the wall for some years now, arguably over a decade, but the time has finally come where the largest CA in the World is going to drop support for the Online Certificate S...
scotthelme.co.uk
December 30, 2024 at 11:08 AM
OCSP stapling with Must-Staple was the best path forward for working certificate revocation checks but had poor adoption. OCSP responses with signed revocation data for a certificate from the Certificate Authority generally had several days of validity. 6 day validity certificates sidestep all this.
May 5, 2025 at 2:23 AM
It’s the end of OCSP as we know it, and I feel fine! https://lists.cabforum.org/pipermail/servercert-wg/2023-April/003685.html
[Servercert-wg] Discussion Period Begins - Ballot SC-063: “Make OCSP Optional and Incentivize Automation”
lists.cabforum.org
April 27, 2023 at 2:29 PM
Ok, this looks like good stuff and is what I’m looking for. Coming out of the TLM and OCSP this is all new. Thanks
November 16, 2025 at 6:01 PM
"But I'm just validating an X509 certificate."
"Did you check where the crl or ocsp endpoint is? You know there's a library for this."
July 22, 2025 at 1:49 PM