For ASA webvpn we request a certificate from the client which is checked against an internal CA.We have configured revocation-check with protocol ldap and it is working.Certificate has CRL URI:ldap:///CN=xyz.-abc-CA2(4),CN=ABC-CA,CN=CDP,CN=Public%20K...