According to the RFC at https://tools.ietf.org/html/rfc5280#section-6.3, certificate CRL validation needs to be provided by Sterling Control Center that uses x.509 certificates for TLS/SSL connections.
We propose a local caching mechanism to be implemented for SCC. We use Microsoft PKI certificates. It publishes CRL lists periodically. We'd like to see SCC to cache the CRL on the local nodes and refresh it every 24 hours. So the CRL check will be done via this caching mechanism. Please see Microsoft site at https://technet.microsoft.com/en-us/library/ee619754(d=printer,v=ws.10).aspx for more info.