Effective June 27, 2025, we’re ending OCSP stapling support from our systems:
- Custom certificates with OCSP Must-Staple Extension
Our systems will no longer accept TLS certificates that include the OCSP Must-Staple extension. - Discontinuation of OCSP Stapling Response
We will cease adding “TLS Certificate Status Request” extensions (also known as OCSP Stapling) to certificates we present to clients. This means that custom certificates that include “OCSP Must-Staple” will not be considered valid by TLS clients, since they will not have staple information when presented to them. TLS clients that expect staple information will also fail.
These changes only have the potential to affect customers utilizing custom TLS certificates. However, we have verified that no currently active customers are using certificates with the OCSP Must-Staple extension. Customers using Let’s Encrypt-provided certificates are not impacted, as Let’s Encrypt removed OCSP support on May 7, 2025.
We’re phasing out OCSP stapling due to industry-wide shifts away from the protocol and towards more reliable and privacy focused alternatives like CRL / CRLite and shorter lived certificates. OCSP stapling adds operational complexity and can fail silently leading to inconsistent client behavior. These platform changes align with moves by CAB Forum (Certificate Authority/Browser Forum) to deprecate OCSP in favor of these more resilient mechanisms.
What you need to do:
We’ve confirmed that none of our currently active customers are using TLS certificates with the OCSP Must-Staple extension, so no action is required at this time. However, starting June 27, 2025, our systems will no longer include OCSP stapling information in TLS handshakes. If your infrastructure or clients (such as security-hardened browsers, firewalls, or API consumers) expect a stapled OCSP response, we recommend verifying that they can gracefully handle connections without it. Future custom certificates must also not require OCSP Must-Staple to remain compatible.
More information on managing custom certificates is available in our documentation: https://docs.wpvip.com/tls/custom-cert/
If you have any questions or need support, please feel free to open a ticket.