This incident wasn't just about downtime, it was also about issuing non-functional/non-compliant certificates.
This incident wasn't just about downtime, it was also about issuing non-functional/non-compliant certificates.
Caddy staples Valid OCSP responses to all certificates that have an OCSP responder, so if browsers aren't accepting that, then arguably the clients are broken, because that response is valid until a few days from now. But before the 100% valid and trusted OCSP staple expires, Caddy will get a new staple that presumably says Revoked, and replace them right away before browsers would ever see a Revoked status.
(Revocation is broken ;P)
I wonder if we should be doing some basic sanity checks on newly obtained certificates in Caddy, and treat this as a failure, and try the next configured CA instead.
(Obviously SCT signatures will require some external resource so we would have to weigh that a bit more, maybe make it configurable...)
Issue opened here to discuss, though it does sound troublesome/tedious: https://github.com/caddyserver/certmagic/issues/240