So far all customers who support OCSP perform the check in the apache web server during the MTLS connection setup. If for some reason that was not possible, you could make the OCSP request from a person authn interception script. I haven't personally seen any implementations of SCEP. What is the exact use case? The answer is probably that cert enrollment could take place during the authentication phase (also implemented in a Person Authn interception script)