Subversion of online certificate validation processes can enable malicious use of revoked certificates. An attacker who can prevent a certificate from reaching the certificate revocation list can impersonate a legitimate actor and execute malicious activity. Such decisions need to be part of the initial design discussions based on the needs of the organization, such as online certificate status protocol (OCSP) or authentication, authorization and accounting (AAA) It is worth noting that any private keys deployed in the revocation process must be protected equally with the keys that form the basis of the issuing process.”]
Source: https://gizmodo.com/the-nypd-is-planning-a-simulated-chemical-attack-for-ne-5995391