Information
Certificates should only be trusted if they have both a satisfactory trust chain and they have not been revoked. OS X can check whether the certificate is still valid based on issued parameters within the certificate. A rogue or compromised certificate should not be trusted
Solution
Run the following commands to enforce the compliant state To set the CRL settings: defaults write com.apple.security.revocation CRLStyle -string RequireIfPresent To set the OCSP settings: defaults write com.apple.security.revocation OCSPStyle -string RequireIfPresent Impact: Network or connectivity issues could interfere with certificate checks for valid certificates