- allow multiple attempts to setup certificates - use CAB forum BR compliant CRLDistributionPoint for Subordinate CA certificates by referencing their own CRL instead of their parent CA's CRL - store certificates in DER encoded form