Check a certificate's revocation status via OCSP.
Checks OCSP stapling first (fast, what browsers actually use), then falls back to querying the CA's OCSP responder directly.