When starting the CA Gateway server, you can use the -e
option to enable CRL checking. See Running the CA Gateway Docker container for details.
When the revocation checking is enabled, all client certificates must include a CDP extension pointing to an up-to-date CRL. Handshakes will not complete if the client certificate does not include a CDP extension or the URL in this extension is unavailable.