OCSP stapling is a technique that allows a web server to include the validity status of an SSL certificate itself during the connection, so the visitor’s browser doesn’t need to request it separately from the certificate authority. This saves an extra network request on every secure connection, resulting in faster load times and a smoother HTTPS handshake. On a LiteSpeed server with Plesk, OCSP stapling is easy to enable.
What is OCSP stapling
During a normal SSL connection, the browser checks whether the certificate is still valid via the Online Certificate Status Protocol (OCSP). This is done by sending a separate request to the certificate authority. This takes time and, if the OCSP server is slow or overloaded, can even delay the entire page or result in an error message.
With OCSP stapling, the web server itself periodically requests a signed validity statement from the certificate authority and sends it along directly during the TLS handshake β it “staples” it on. The browser then no longer needs to make a separate request, but relies on the provided statement instead.
Why it matters for your website
Besides speed, OCSP stapling has a few other advantages. Since the browser doesn’t need to contact the certificate authority directly, more information about your visitors stays with your server rather than a third party. It also prevents issues when the certificate authority’s OCSP server responds slowly or is temporarily unreachable: the provided statement simply remains valid until the next renewal.
For high-traffic websites or e-commerce, every millisecond counts. A faster HTTPS handshake directly contributes to a better user experience and can also have a positive effect on how search engines rank your site.
Enabling OCSP stapling
On a LiteSpeed server managed through Plesk, this is usually configured centrally at the server level, so it automatically applies to all domains with SSL.
Log in to Plesk
Go to your Plesk panel and open the domain for which you have enabled SSL.
Open the SSL/TLS settings
Navigate to the SSL/TLS certificates section of the domain and check whether a valid certificate is active.
Check the LiteSpeed web server configuration
OCSP stapling is typically activated at the server level on LiteSpeed servers via the listener settings. At Tandata, this is configured correctly by default, but you can have this checked via your hosting management.
Restart the web server
After adjusting settings, restart the web service so the change takes effect.
Checking whether it works
After enabling OCSP stapling, you’ll want to verify that it’s actually working. This can be done with an online SSL testing tool that checks your domain for OCSP support, or via the command line with an OpenSSL command that analyzes the server response for an OCSP response status.
If the test shows that no stapled response is being sent, check whether the certificate is correctly installed and whether the server has internet access to retrieve the OCSP status from the certificate authority. More background information on SSL and server configuration can be found in the knowledge base.
Stuck, or unsure whether your current provider has set this up properly? Check out the options to switch to Tandata, including web hosting with free SSL and correctly configured LiteSpeed servers.
Frequently Asked Questions
Does OCSP stapling work with every SSL certificate?
Yes, it works with both free certificates such as Let’s Encrypt and paid certificates, as long as the certificate authority supports OCSP responses.
Do I need to set this up per domain?
On a correctly configured LiteSpeed server, OCSP stapling usually applies automatically to all domains with a valid SSL certificate, including domains you use for business email.
Does OCSP stapling affect email?
Indirectly, yes: a correct SSL configuration at the server level contributes to a reliable and fast secure connection, which also benefits the reliability of mail servers.
Can I test this myself without technical knowledge?
Yes, with an online SSL check tool you simply enter your domain name and immediately see whether OCSP stapling is active.
Does OCSP stapling also work for new domain names?
As soon as you link a new domain and activate SSL, the same server configuration applies. Check out the options for domain names if you’re starting a new project.
Conclusion
OCSP stapling ensures faster and more reliable SSL connections by including the certificate status directly instead of having the browser make a separate request. On a well-configured LiteSpeed server with Plesk, this often works automatically already, but it’s always wise to verify it with an SSL testing tool.