Graham, OCSP test case now also decent. The work around was easy (openssl seems to silently add the issuer trusted cert to the main CA -and- not check the https URL it fetches the /ocsp from). Dw. https://github.com/dirkx/nixpkgs/blob/797e03974f2df01b554e7c18870bb290f9c1285e/nixos/tests/redwax-revoke-ocsp.nix