Certificate Revocation List(CRL)
This is basically a singed list that the CA publishes on a website that can be read by the authentication servers
Online Certificate Status Protocol (OCSP)
OSCP allows the authentication server to send a real-time request (similar to an HTTP web request) to the service running on the CA or another device and checking the status of the certificate right then and there
CAP
certificate Authentication Profile- examine a specific field and map it to username for authorization