Cert and CRL bug?

The same way that the bug with the Certs with CRL for OVPN is still not fixed, I stumbled into another issue with CRL on an SSTP link.

I have an SSTP link between two ROS routers using certificates and CA. The CA is linked to an http URI for the CRL.

The link was working fine until last week when I got the error that the CRL was expired. Indeed, I forgot to update the CRL on my server.

I updated and published the new CRL but it seems that ROS never updated it. I waited 24 hours to make sure that it was not a refresh issue, but still I got the error that the CRL was expired.

I had to delete my CA certificate from ROS and reimport it to have the new CRL taken into account. Luckily it was a router I had direct access to. Would it have been a remote one, I would not have been able to do it as I was locked out.