Regarding OCSP (Online Certificate Status Protocol) - have a look at http://en.wikipedia.org/wiki/Moxie_Marlinspike#OCSP_Attacks