There are two work items Turris Team to do:
- Temporarily switch to a CA that provides OCSP, e.g. Google Trust Services
- update pkgupdate (or other relevant piece of software) not to assume that a certificate always has a OCSP URL in the Authority Information Access field.