_(originally recorded as RADSECPROXY-49)_ > Even when CRLCheck is enabled and CacheExpiry is reasonable, existing connections don't get torn down when their certificate show up in the CRL. > > Reported by Adam Smutnicki.