make sure that CRT/CRL files are accessible by all clients (which will use your certificates) On CDP/AIA extension planning I would suggest to check my blog post: Designing CRL Distribution Points and Authority Information Access locations. Although, the article was written against Microsoft CA, the same principles apply to any other CA

Nov 21, 2014 Certificate revocation list - Wikipedia In cryptography, a certificate revocation list (or CRL) is "a list of digital certificates that have been revoked by the issuing certificate authority Symmetric systems such as Kerberos also depend on the existence of on-line services (a key distribution center in the case of Kerberos). Updated: Creating a Certificate Revocation List This function of collecting certificate serial numbers (an attribute of the certificate that is guaranteed to be unique within the scope of your PKI), populating a list with the serial numbers, creating the CRL, and then posting the CRL to a CRL distribution point is an essential security component.

Specifies the uniform resource identifier (URI) for the distribution point location of the certificate revocation list (CRL). This is the location from where status information about certificate revocation has been retrieved and/or the location the CRL was published.

Update CRL Distribution Point (CDP) and Authority Choose Extensions tab and edit the CRL Distribution Point (CDP). The first location should be a file path. This is where the CRL is stored on your server. This is the Physical Path of the Virtual Directory you create for the CDP. The second path is through LDAP. Change this path to only have the Publish CRLs to this location and Publish Delta

DistributionPoint (5.61 API Documentation)

PKI - CRL Distribution Points (CDP) Extension The CRL distribution points is an X.509 v3 certificate extension which identifies the location of the CRL from which the revocation of this certificate can be checked. The application that processes the certificate can get the location of the CRL from this extension, download the CRL and then check the revocation of this certificate. Setup CRL Distribution Points – ITFreeTraining