Select this option to use the certificate
revocation list (CRL) method to verify the revocation status of
certificates. If you also enable Online Certificate Status
Protocol (OCSP), the firewall first tries OCSP; if the OCSP server
is unavailable, the firewall then tries the CRL method. |