It's not practical to use SEAS for certificate CRL check for Connect:Direct in a large enterprise environment where there are thousands of Connect:Direct nodes. Query-based CRL check via SEAS could greatly degrade the performance of Secure+ file transfers and could create a single point of failure.
We propose a local caching mechanism to be implemented for Connect:Direct for supported OS platforms. We use Microsoft PKI certificates. It publish CRL lists periodically. We'd like to see Connect:Direct to cache the CRL on the local nodes and refresh it every 24 hours. So the CRL check will be done via this caching mechanism. Please see Microsoft site at https://technet.microsoft.com/en-us/library/ee619754(d=printer,v=ws.10).aspx for more info.