What Is OCSP Stapling? Enable on Nginx and Apache for Faster HTTPS

What Is OCSP Stapling?

OCSP Stapling (Online Certificate Status Protocol Stapling) is a technique that lets your web server pre-fetch the SSL certificate revocation status from the Certificate Authority (CA) and attach it directly to the TLS handshake. This eliminates the need for the browser to make a separate network request to the CA, significantly reducing handshake latency.

Without OCSP Stapling, every time a user connects to your HTTPS site, their browser contacts the CA's OCSP responder to verify the certificate has not been revoked. This adds an extra DNS lookup and round-trip — often 50–300 ms depending on the CA's server location — before the connection is fully established.

With OCSP Stapling enabled, your server queries the CA periodically, caches the signed OCSP response, and "staples" it to every TLS handshake. The browser receives proof of validity instantly without contacting the CA at all.

Why OCSP Stapling Matters

A standard TLS handshake without OCSP Stapling proceeds like this:

  1. Browser sends ClientHello
  2. Server responds with ServerHello + Certificate
  3. Browser sends OCSP request to CA (adds 50–300 ms latency)
  4. CA returns certificate status
  5. Browser verifies and generates session keys
  6. HTTPS connection established

Steps 3–4 are what OCSP Stapling eliminates. For sites targeting global audiences where CA servers may be located far away, this overhead can noticeably impact Time to First Byte (TTFB) and Core Web Vitals scores.

Three key benefits: (1) Reduces TLS handshake latency by 50–300 ms (2) Protects user privacy — the CA never learns which users visit your site (3) Reduces load on CA OCSP responders, improving overall service stability

Enabling OCSP Stapling on Nginx

Nginx has supported OCSP Stapling since version 1.3.7. Add the following directives to your server block:

Step 1 — Add OCSP Stapling directives

server {
    listen 443 ssl http2;
    server_name example.com www.example.com;

    ssl_certificate     /etc/ssl/certs/example.com.crt;
    ssl_certificate_key /etc/ssl/private/example.com.key;

    # OCSP Stapling
    ssl_stapling on;
    ssl_stapling_verify on;
    ssl_trusted_certificate /etc/ssl/certs/chain.pem;

    # DNS resolver for OCSP lookup
    resolver 8.8.8.8 1.1.1.1 valid=300s;
    resolver_timeout 5s;
}

Step 2 — Prepare the Certificate Chain file

The file specified in ssl_trusted_certificate should contain only the Intermediate + Root certificates (not your domain certificate). Most SSL providers include a file named ca-bundle.crt or chain.pem which works directly here.

Step 3 — Test and reload Nginx

nginx -t && systemctl reload nginx

Step 4 — Verify OCSP Stapling is active

openssl s_client -connect example.com:443 -status 2>/dev/null | grep -A 5 "OCSP Response"

A successful output shows OCSP Response Status: successful and Cert Status: good.

Enabling OCSP Stapling on Apache

Apache supports OCSP Stapling since version 2.3.3 via mod_ssl. Add these directives to your VirtualHost configuration:

<VirtualHost *:443>
    ServerName example.com
    SSLEngine on
    SSLCertificateFile      /etc/ssl/certs/example.com.crt
    SSLCertificateKeyFile   /etc/ssl/private/example.com.key
    SSLCertificateChainFile /etc/ssl/certs/chain.pem

    # OCSP Stapling
    SSLUseStapling on
    SSLStaplingResponderTimeout 5
    SSLStaplingReturnResponderErrors off
</VirtualHost>

# Add this outside VirtualHost (global scope)
SSLStaplingCache shmcb:/run/apache2/ssl_stapling(128000)

Enable mod_ssl and reload

a2enmod ssl
apachectl configtest && systemctl reload apache2

Verifying With Online Tools

Beyond the command line, use these free tools to confirm OCSP Stapling is working:

Common Issues and Fixes

Nginx: OCSP response not appearing immediately

Nginx fetches the OCSP response on the first real connection after reload, not immediately. Send a test request and check again. Also verify the resolver directive is configured — without it, Nginx cannot perform DNS lookups for the OCSP responder.

Apache: SSLStaplingCache not defined

The SSLStaplingCache directive must be placed outside any VirtualHost block. Add it to your main httpd.conf or create a dedicated ssl-stapling.conf in your conf-enabled directory.

Does OCSP Stapling work with Let's Encrypt?

Yes, Let's Encrypt fully supports OCSP Stapling. However, Let's Encrypt's OCSP responder can occasionally be slower than commercial CA responders. For sites requiring maximum TLS performance, paid SSL certificates from providers like RapidSSL or GeoTrust offer more predictable OCSP response times.

OCSP Stapling and TLS 1.3

TLS 1.3 (RFC 8446) reduced the standard handshake from 2 round-trips to 1-RTT, dramatically cutting connection setup time. OCSP Stapling remains fully supported in TLS 1.3 through the same Certificate Status Request extension used in TLS 1.2. Key points:

TLS Version Round Trips OCSP Stapling Notes
TLS 1.2 2-RTT Supported Legacy standard
TLS 1.3 1-RTT Supported Recommended
TLS 1.3 (0-RTT) 0-RTT N/A PSK resumption — no cert exchange

OCSP Stapling on LiteSpeed and Caddy

Nginx and Apache are not the only web servers that support OCSP Stapling. Two popular alternatives handle it differently:

LiteSpeed Web Server

LiteSpeed enables OCSP Stapling automatically by default since version 5.4. No additional configuration is required. You can verify or adjust the setting in LiteSpeed Admin Console under Virtual Hosts → SSL → OCSP Stapling.

Caddy

Caddy enables OCSP Stapling automatically for every HTTPS site, including certificates it manages through Let's Encrypt. For externally provided certificates, simply declare the certificate files and Caddy handles stapling without any extra directives:

# Caddyfile — OCSP Stapling is automatic
example.com {
    tls /etc/ssl/certs/example.com.crt /etc/ssl/private/example.com.key
    root * /var/www/html
    file_server
}

Comparison of OCSP Stapling configuration effort across servers:

Advanced Debugging for OCSP Stapling

If the openssl s_client check returns no OCSP response, work through these diagnostic steps:

Find the OCSP URI embedded in the certificate

openssl x509 -in /etc/ssl/certs/example.com.crt -noout -text | grep -A 3 "OCSP"

This reveals the OCSP responder URL (e.g., http://ocsp.digicert.com) your server needs to reach.

Test the OCSP responder directly

openssl ocsp \
  -issuer /etc/ssl/certs/chain.pem \
  -cert /etc/ssl/certs/example.com.crt \
  -url http://ocsp.digicert.com \
  -text

If the output shows Response verify OK and good, the CA is responding correctly and the problem is in your server configuration — not the certificate.

Check Nginx error logs

tail -n 50 /var/log/nginx/error.log | grep -i ocsp

A missing or misconfigured resolver directive is the most common cause. Without it, Nginx cannot perform DNS lookups to reach the OCSP responder.

Check Apache error logs

grep -i "stapl" /var/log/apache2/error.log | tail -20

Apache logs warnings like ssl stapling_init_OCSP_cache: cache not configured when SSLStaplingCache is missing from the global scope.

What Is OCSP Must-Staple?

OCSP Must-Staple is an optional certificate extension that instructs browsers to require a valid OCSP staple with every connection. If the server fails to provide one, browsers will refuse the connection. This provides the strongest possible revocation enforcement but requires OCSP Stapling to be reliably operational at all times.

Frequently Asked Questions

How is OCSP Stapling different from standard OCSP?

Standard OCSP requires the browser to contact the CA directly on every connection, adding latency and revealing the user's IP to the CA. OCSP Stapling lets the server pre-fetch and cache the CA's response, delivering it to the browser as part of the handshake — faster and more private.

Should I enable OCSP Stapling on every HTTPS site?

Yes. There are no downsides to enabling OCSP Stapling, and virtually every HTTPS site benefits from the reduced handshake overhead and improved user privacy.

Does OCSP Stapling work with HTTP/2?

OCSP Stapling works seamlessly alongside HTTP/2. Since HTTP/2 requires HTTPS, enabling both together maximizes connection setup efficiency and page load performance.

Need an SSL Certificate With Full OCSP Stapling Support?

AsiaGB offers SSL Certificates from RapidSSL, GeoTrust, and DigiCert — DV SSL from 1,000 THB/year, Wildcard SSL from 5,000 THB/year, all with OCSP Stapling and HTTP/2 support.

View All SSL Certificates