Let's Encrypt to end OCSP support in 2025
scotthelme.co.uk
scotthelme.co.uk
Don't agree with this statement. It's only adding no security when the CA is down. In case a Cert is revoked and the OCSP is up, it will be blocked.
But I understand their reasons to drop it.
Because the CA is not hosted by the server itself, the routing path is very different and only converges near the end user.
I know it's less likely but to say that there is no security at all is not true in my opinion.
We ended up on the following: Either you accept the fact that once signed, it has a life on its own until it expires, or the issuer becomes the single point of failure.
Another issue we dealt with was validating that the person doing the request with a JWT was the owner of the JWT, and not someone who stole it. A possible fix? Distribute private keys to clients, and have them sign the JWTs on the fly. How do you check for revoked private keys? Catch-22.