Overview
To ensure your Domain Controller (DC) can communicate with TruU’s Certificate Revocation List (CRL) endpoints, verify that outbound internet connectivity from the DC is not blocked by a firewall or proxy. There are two ways to verify that CRL files can be downloaded from a Domain Controller.Verify Using a Browser
Log in to the Domain Controller and open a browser, then navigate to the following URL:.crl file downloads successfully, outbound connectivity to the TruU CRL endpoint is working correctly.
You can also navigate to
https://saas.cloudtrust.truu.ai/crl — you will see an Access Denied error, which is expected and confirms DNS resolution and basic connectivity are working.Verify Using a Command
The second option runscertutil, which opens the URL Retrieval Tool and tests retrieval of the CRL files (rootCA crl and issuingCA crl) downloaded from the TruU portal.
You must have the end-user certificate and the issuing CA certificate available on the local drive before running these commands.
-
Run the following command:
- In the pop-up, select CRLs (from CDP).
- Click Retrieve. The tool checks the CDP URL embedded in the certificate and returns a status of Verified or Failed. Run this command once per certificate.

