Now i tested it with self signed certificates from OPNsense and it worked to.
The secret is to have a crl for all root and intermediate certificates.
All these crl's have to chosen in the public service.
The secret is to have a crl for all root and intermediate certificates.
All these crl's have to chosen in the public service.