Definition · TLS & Certificates

What is OCSP?

OCSP (Online Certificate Status Protocol) is a protocol, defined in RFC 6960, that lets clients ask a certificate authority whether a specific certificate is still valid or has been revoked. It was designed as a lighter-weight alternative to downloading full certificate revocation lists (CRLs): the client sends the certificate’s serial number to the CA’s OCSP responder and receives a signed good, revoked, or unknown answer.

Problems with plain OCSP

  • Privacy — every OCSP query tells the CA which sites a user is visiting
  • Latency — the extra round-trip slows down TLS handshakes
  • Soft-fail behaviour — if the responder is unreachable, most clients proceed anyway, so an attacker who can block OCSP traffic defeats the check

OCSP stapling

OCSP stapling addresses these problems by having the web server fetch its own OCSP response periodically and “staple” the time-stamped, CA-signed response to the TLS handshake. Clients get fresh revocation status without contacting the CA, removing the privacy leak and the extra round-trip. The OCSP Must-Staple certificate extension can make a stapled response mandatory.

Current status

The ecosystem is moving away from live OCSP: major browsers stopped performing per-connection OCSP lookups years ago in favour of pushed revocation summaries, and Let’s Encrypt ended its OCSP service in 2025, returning to CRL-based revocation. Stapling remains relevant for certificates from CAs that still operate responders.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.