A signed list, published by a certificate authority, of certificates it has revoked before their expiry. Relying parties download the CRL from the location named in a certificate's CDP extension and reject any certificate whose serial number appears on the list. CRLs have a validity window, so a stale or unreachable CRL is a common cause of authentication failures in certificate-based systems.
CRL
Certificate Revocation List