As an aside: there's a reason #CABForum standards aren't supposed to apply to private CAs.
CA/B are moving back to CRLs for #certificate revocation because #OCSP doesn't work well. To keep #CRL size manageable, this requires certificate lifetimes to be very short (they decided on 47 days).
But a private #CA is a completely different animal. A private CA might only issue a few dozen certificates in its entire existence. Its CRL will never get huge.




💕