<div dir="ltr">Hi,<div><br></div><div>How do I '
Validate the certificates used in the assertion using Certificate Revocation Lists
(CRLs), as well as checking expiration'?</div><div><br></div><div>I've looked at the documentation here and looking to use the dynamic or staticpkix engines:</div><div><a href="https://wiki.shibboleth.net/confluence/display/SP3/PKIX+and+StaticPKIX+TrustEngines">https://wiki.shibboleth.net/confluence/display/SP3/PKIX+and+StaticPKIX+TrustEngines</a> </div><div><br></div><div><TrustEngine type="PKIX"/><br></div><div> Setting my TrustEngine to PKIX doesn't seem to do anything with CRL (looking at the shibd.log 'debug logs') </div><div><br></div></div>