Conversation

Must-Staple is a flag in the certificate. A wrongly issued certificate wouldn't have it set, so the feature doesn't help with revocation of wrongly issued certificates. Shorter certificate lifetimes would offer the same advantages without needing clients to adopt Must-Staple...