Information
This policy setting controls whether Outlook considers a missing certificate revocation list (CRL) a warning or an error.
Digital certificates contain an attribute that shows where the corresponding CRL is located. CRLs contain lists of digital certificates that have been revoked by their controlling certification authorities (CAs), typically because the certificates were issued improperly, or their associated private keys were compromised.
The recommended state for this setting is: Enabled: Error
If a CRL is missing or unavailable, Outlook cannot determine whether a certificate has been revoked. An improperly issued certificate or one that has been compromised might be used to gain access to data.
Solution
To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Error
Microsoft Outlook 2016\Security\Cryptography\Signature Status dialog box\Missing CRLs
Impact:
Users will be prevented from using certificates when the appropriate CRL is not available to verify them. This could increase desktop support requests.