Public key infrastructure (PKI) underpins trust for the web, email, code, devices and more. Recently, browsers and some public CAs have changed how they handle revocation for public TLS certificates. That raises a common question: is OCSP finished?
The short answer: for mainstream browsers, yes – live checks are being de-emphasised. But for everything else, absolutely not. OCSP remains the most efficient and essential way to check certificate revocation across enterprise, regulated and device PKIs.
Goodbye OCSP (for browsers). Long live OCSP (for everything else).
Browsers have long struggled with live, per-connection OCSP checks due to latency, privacy, and reliability trade-offs. To solve this, the industry is shifting towards browser-managed revocation feeds and short-lived certificates, instead of relying on live OCSP lookups during every TLS handshake.
Takeaway for public websites: Expect less reliance on live OCSP and more on short lifetimes, stapling where appropriate, Certificate Transparency (CT) monitoring, and browser-distribution mechanisms like CRLite and CRLSets.
Outside the consumer browser, revocation is often mission-critical. Many environments require hard-fail decisions if a certificate is revoked, and auditors demand provable evidence of status at the time of validation. OCSP is what enables this.
OCSP stapling remains a best-practice optimisation whenever clients support it. The TLS Feature (RFC 7633), often called “Must-Staple”, lets you enforce stapled responses (fail if missing). This is especially valuable in controlled environments such as enterprise browsers and internal services, though it’s not universally enforced by public browsers.
Ascertia’s ADSS OCSP Server (Validation Authority) provides high-performance, RFC 6960/RFC 5019-compliant OCSP with flexible deployment options, from high availablilty and delegated signers to fine-grained policy control. It’s built for enterprise TLS, VPN, S/MIME, code signing and IoT ecosystems.
For organisations modernising validation across complex environments, the ADSS OCSP Server integrates seamlessly with Ascertia’s ADSS Server services (SCVP, CRL monitoring, timestamping) to create complete, audit-ready validation workflows.
Revocation checking is evolving, but it’s far from disappearing. While browsers are reducing their reliance on live OCSP, regulated industries, enterprises, and connected devices depend on it more than ever.
Ascertia helps organisations strike the right balance: combining OCSP with stapling, policy enforcement, and futureproof validation services.
Is your organisation planning its next phase of PKI? Let’s explore how Ascertia’s trusted solutions can help you build resilient, compliant, and forward-looking validation strategies.