• Check the CRL and OCSP cycle.
  • This should be interpreted as CRL/OCSP.
  • The CA does not publish the certificates per se, for privacy reasons. CRLs only include the serial numbers of the certificates.