Manage revocation services
Revocation status is distributed through OCSP responses and CRLs.
Confirm that:
OCSP and CRL distribution services are enabled for CAs that require them.
Distribution point URLs published in certificates are reachable by relying parties.
CRL generation intervals meet your agency's freshness requirements.
Revocation of a certificate is reflected in OCSP and CRL output.
Include revocation service availability in your organization's monitoring and verify revocation propagation as part of incident response exercises.