I think you are using a private certificate issued by your own CA and you are not able to reach the CRL list from the ASA to check if the client cert is valid.In ASDM go to Configuration, Certificate Management, CA Certificates and make sure you have...