Follow-up Comment #6, sr #124285 (project xrootd): Hi, Brian, I have tested the config with (from the log): =====> sec.protocol /usr/lib64 gsi -certdir:/etc/grid-security/certificates -cert:/opt/xrootd/xrootd/etc/xrdcert.pem -key:/opt/xrootd/xrootd/etc/xrdkey.pem -crl:2 -authzfun:libXrdLcmaps.so -authzfunparms:--osg,--lcmapscfg,/etc/xrootd/lcmaps.cfg,--loglevel,0|useglobals --gmapopt:2 --gmapto:0 With each restart all the crls are downloaded again. Only crl:1 avoids re-download. For the worker nodes we use fetch-crl and there is a config file: $ cat /etc/sysconfig/fetch-crl export http_proxy=http://squid.fnal.gov:3128 This can be also an acceptable solution for us. Thanks Catalin _______________________________________________________ Reply to this item at: <http://savannah.cern.ch/support/?124285> _______________________________________________ Message sent via/by LCG Savannah http://savannah.cern.ch/