If the client does not receive a stapled response, it will just contact the OCSP server by itself. ... As a result, clients continue to have verifiable assurance from the certificate authority that the certificate is presently valid (or was quite recently), but no longer need to individually contact the OCSP server.
Is OCSP stapling required?
OCSP must-staple
An attacker with a revoked certificate can simply neglect to provide an OCSP response when a browser connects to it and the browser will accept their revoked certificate. In the OCSP fetching case, a soft-fail approach makes sense.
How do you know if your OCSP has been stapled?
Check if OCSP stapling is enabled.
Go to and in the Server Address box, type in your server address (i.e. ). If OCSP stapling is enabled, under SSL Certificate has not been revoked, to the right of OCSP Staple, it says Good.