I am using Debian Linux on several machines with different services (Apache, Freeradius, etc...) together with a Windows Server 2008R2 CA. I install the CA certificate by downloading it to /usr/local/share/ca-certificates and then calling update-ca-certificates.
How can I keep the corresponding revocation list up to date too in order for the services to reject revoked client certificates? I found the fetch-crl utility, but couldn't find any examples how to use it.