Hacker News new | ask | show | jobs
by woodruffw 273 days ago
How would that work in the current reality of the DNS? The current reality is that it’s unauthenticated and indeterminately forwarded/cached, neither of which screams success for timely, authentic OCSP responses.
1 comments

Similarly to how OCSP stapling was supposed to work.
“Supposed to” being operative, I think!