It appears that it is possible to have tomcat refresh it's CRL specified in the Connector from reading: https://bz.apache.org/bugzilla/show_bug.cgi?id=60762
The bug/feature request seems to have been fixed/implemented, but I haven't found any documentation about how to tell Tomcat when to update the relevant CRL. Do you have to override the connector class or use JMX? Or are there configuration options in the Connector itself?