I can comment on the OCSP stapling with respect to CDN. (responding back to Andy's comment earlier)
Even when OCSP stapling is enabled, a CDN may not always respond back with the staple. Typically, the work flow occurs as follows:
1. very first user makes a request. CDN responds without the staple.
2. CDN asynchronously makes a request and pulls down the cert verification status
3. for subsequent requests, the staple is included.
Browsers are supposed to work regardless of a CDN. So the optimization is to ensure that the request for staple verification does not break / slow down a website.