Do you need to somehow tell openssl to trust the OCSP responder's SSL certificate (NOT the OCSP response signing cert) first? For me the ocsp option never presents a cert from the responder (no client authentication required), even though it works fine over non-SSL.