When starting the CA Gateway server, you can use the  -e  option to enable CRL checking. See Running the CA Gateway Docker container for details. 

When the revocation checking is enabled, all client certificates must include a CDP extension pointing to an up-to-date CRL. Handshakes will not complete if the client certificate does not include a CDP extension or the URL in this extension is unavailable.