This CA signs ONLY short lived proxy converting kerberos tickets to X509. The revocation process is maintained centrally via the FNAL Kerberos KDC.