Skip to main content

May 28, 2026

Configure CRL Pre-Fetch Settings

Use this setting to conduct a Certificate Revocation check on a certificate when CRL Distribution Point (CDP) URLs for the certificate are not directly accessible to the Connection Server.

Prerequisites

  • Log in to the Connection Server and configure the CRL Prefetch service Horizon CRL Prefetcher.
    • Configure the service under Log On with the service account which has access to the CDP URLs over the internet.
    • Enable the service by changing the Startup type to Manual and start the service.
    • Repeat this process for each Connection Server where CRL Distribution Point (CDP) URLs are not directly accessible.

Procedure

  1. Navigate to Global Settings > Security Settings > CRL Pre-Fetch Settings.

  2. Enter data in these fields.

    OptionDescription
    Refresh Period Time period in minutes for a CRL refresh. Default is 60 minutes.
    Distribution Point CRL Distribution Point (CDP) URL(s) for certificates. Only http URLs with file extensions CRL and PEM are supported.
    Maximum File Size Maximum size allowed in kilobytes for the CRL file that can be downloaded. The default is 1024 KB.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…