Unfortunately, not so. “The” revocation problem is actually many problems – and Must-Staple doesn’t solve them. It would solve problems if revocation actually worked, but revocation as a whole is broken. Although Caddy’s OCSP implementation is the best available in the industry for supporting Must-Staple, you still risk bricking your site for a time with factors that are out of your control. That’s why Must-Staple should only be used if you have a very specific reason / threat model that requires it. The only good solution to “the” revocation problem is shorter certificate lifetimes.