Handshake Papers
Handshake Papers
@HandshakePapers

Does OCSP stapling actually solve certificate revocation?

Does OCSP stapling actually solve certificate revocation?

The advice "enable OCSP stapling and revocation is handled" overstates a real but partial fix. OCSP (Online Certificate Status Protocol, RFC 6960) lets a client ask whether a certificate is revoked. Classic OCSP leaks the user's browsing to the CA and adds latency; stapling (RFC 6066) has the server fetch a signed, time-stamped status and attach it to the handshake, removing both problems.

But stapling does not make revocation reliable. Without the must-staple extension (RFC 7633), a client that receives no stapled response simply soft-fails — it proceeds anyway. An attacker holding a stolen key just strips the stapled response, and the client connects. Soft-fail is the default in major browsers precisely because hard-fail breaks availability when OCSP responders are down.

This is why the industry has been retreating from OCSP entirely. Let's Encrypt announced in 2024 it would stop providing OCSP, pushing toward short-lived certificates and CRLite-style browser-pushed revocation as the real answer.

— Stapling fixes privacy and latency, not enforcement
— Soft-fail makes stripping trivial
— Must-staple closes the gap but is rarely deployed

Further reading: RFC 6960, RFC 7633; Let's Encrypt, "Intent to End OCSP Service" (2024).
Bottom line: Stapling improves OCSP's mechanics but doesn't guarantee a revoked certificate is rejected. Short certificate lifetimes are the structural fix.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.