How would that work in the current reality of the DNS? The current reality is that it’s unauthenticated and indeterminately forwarded/cached, neither of which screams success for timely, authentic OCSP responses.

Similarly to how OCSP stapling was supposed to work.

“Supposed to” being operative, I think!