“As it stands today, OCSP is not making anyone more secure. Browsers are either not checking it or are implementing it in a way that provides no security benefits.”
Let’s Encrypt is shutting down OCSP servers that answer 12 billion requests a day. Chrome stopped checking OCSP in 2012 because soft-fail protected nobody. The CA/Browser Forum made it optional in 2023. Revocation checking was theater for over a decade.