> Sounds like letsencrypt is being quite premature by turning off OCSP.
Not really, since they now offer six-day certs, which makes revocation effectively irrelevant: https://letsencrypt.org/docs/profiles/#shortlived