← Back to Articles
Guide2026-08-14•6 min read

What is OCSP Stapling and How to Enable It

· CSR.plus Team

What is OCSP Stapling and How to Enable It
  • •OCSP stapling attaches a time-stamped, CA-signed revocation proof to the TLS handshake — saving one round trip and hiding visitor IPs from the CA.
  • •It removes the online OCSP responder as a single point of failure: if the CA is down, your handshake still completes.
  • •Enable it with one line in Nginx and Caddy; roughly 96% of current clients support it.
1 RTT
Handshake savings
one fewer round trip per connection
96%
Client support
of modern browsers and clients
Zero
Privacy
visitor IPs never sent to the CA
Safe
Failure mode
silently falls back on error

TLS handshake time on a 200 ms RTT network (ms)

TLS handshake time on a 200 ms RTT network (ms)0 ms168.0 ms336.0 ms504.0 ms672.0 ms600 msNo OCSP check490 msTraditional OCSP400 msOCSP staplingFull handshake, client verification included.

Full handshake, client verification included.

OCSP stapling deployment across scanned sites

OCSP stapling deployment across scanned sites100100%Stapling enabled — 35%Not enabled — 45%OCSP disabled entirely — 20%Sample of the top 1M domains, August 2026.

Sample of the top 1M domains, August 2026.

What is OCSP?

OCSP (Online Certificate Status Protocol) is how browsers check whether a certificate has been revoked before trusting it. The browser asks the certificate authority's responder: "is this certificate still valid?" and gets a signed yes/no answer. Without a status check, a compromised or revoked certificate would keep being accepted until it expires.

The three problems with traditional OCSP

First, speed: each new connection triggers an extra network round trip to the CA. Second, availability: if the responder is slow or unreachable, the browser must decide between failing the connection or proceeding unverified (soft-fail). Third, privacy: every visitor's IP address is revealed to the certificate authority, building a browsing history of your users.

How stapling fixes all three

With stapling, the web server fetches a time-stamped, CA-signed revocation proof once (typically every few hours) and attaches it to its own handshake message. The browser verifies the signature without any extra round trip, without contacting the CA, and without revealing who visited. If the stapled proof is expired, the browser simply treats it as "no response" and behaves as before — a safe degradation.

How to enable it

Nginx: add "ssl_stapling on;" and "ssl_stapling_verify on;" inside your server block, and make sure you have a full chain (with intermediates) configured. Apache: set "SSLUseStapling On" and "SSLStaplingCache shmcb:logs/stapling-cache(128000)". Caddy enables OCSP stapling automatically and even manages it during renewal. After changing the config, restart the web server and verify.

How to verify your setup

Use the free SSL/TLS Tracer on csr.plus: it shows you the exact handshake your server sends, including the stapled OCSP response and its "next update" time. Alternatively, run "openssl s_client -connect yourdomain.com:443 -status" and check the OCSP response section. The tools page also lets you inspect the served certificate chain and its validity period.

Common misconceptions

Stapling is not the same as "disabling OCSP" — it keeps revocation checking while removing the drawbacks. It is not a substitute for Certificate Transparency logs. And while clients that do not support stapling (about 4%) simply ignore the extension, you should keep your OSCP responder configured for compatibility — stapling is an optimization on top of a correctly configured OCSP.

FAQ

What is the difference between OCSP and OCSP stapling?

OCSP is a protocol in which the browser queries the CA directly to check revocation. OCSP stapling moves that proof into the TLS handshake itself: the server presents a CA-signed, time-stamped response, so the browser never has to contact the CA.

How much faster is a site with OCSP stapling?

On a typical 200 ms RTT network, the full handshake drops from about 490–600 ms to roughly 400 ms — one fewer round trip per new connection. The benefit is most visible on slow or high-latency connections.

Does OCSP stapling work with all certificate authorities?

Yes. All publicly trusted CAs provide an OCSP responder, and stapling works with any of them. Some CAs also support the newer must-staple extension, which tells browsers to require a stapled response.

How do I enable OCSP stapling on Nginx?

Add "ssl_stapling on;" and "ssl_stapling_verify on;" to your server block, ensure "ssl_certificate" points to the full chain including intermediates, and restart Nginx.

What happens when the stapled OCSP response expires?

Browsers treat an expired or invalid stapled response exactly like a missing one: they fall back to the standard behavior (typically soft-fail). Your server re-fetches a fresh proof periodically, so the window is small — and your site keeps working either way.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles