There is no such thing as a non-signed CRL; the signature field is mandatory, and any system that uses the CRL will verify the signature. In pure X.509, a CRL will be deemed "acceptable" as a source of information about the revocation status of a given certificate E if it is signed by an "allowed revocation issuer": the CRL's signature must match the public key contained in an already certificate.

The CDPs (CRL Distribution Points) of the certificates involved in signing these assemblies are listed here. These are the URLs that you need access to in order to validate the CRLs.

Add CRL hosts, including,, and to your institution’s Proxy server configuration; On your library Web site, add your proxy prefix to all CRL links, including, and; CRL Systems staff receive a number of support calls about off-campus access.

Dear support, I want to configure Certificate Revocation List (CRL) on Cisco ISE version 2.0 but I can not find the configuration section for CRL, however OCSP configuration section is there. I've done some researches and I found that configuring CRL was supported (at least on version 1.2), but on Certificate Revocation List (CRL) Jun 30, 2020 DirectAccess clients may be unable to connect with error