Currently tl-ldap-certalias only supports CRL that is provided over http which seems a bit legacy. For example dogtag (IPA server) nor EJBCA supports CRL via http, OCSP [1] is whats used in both cases. [1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol