If you cache the revocation list, you lose all the benefits of instant revocation making the whole process pointless.

OCSP is dead. We don't have that luxury anymore. By caching I meant for 12-24 hrs.

Again, if you need to revoke a certificate, it means something terrible happened - someone compromised your server and your website has a good chance to be impersonated by 3rd parties. In all the other cases, you just let the old cert expire. You likely don't want people finding out about the revocation 12-24 hours later.

OCSP-stapling seemed to be fine with 24-48 hour client-side caching, though.