PSA: LetsEncrypt is shutting down its OCSP server during 2025:
https://letsencrypt.org/2024/12/05/ending-ocsp/
This is due to security issues with OCSP; read the article . The preference now is to use CRLs, for checking revocations.
If you passed OCSP Must Staple and/or your web server needs valid OCSP, you should reconfigure accordingly; make OCSP optional or turn it off, in your httpd, and revoke+renew your certs if you passed --must-staple in certbot.
I already done it on my sites (I was using OSCP Must Staple).