Ok gelöst....
Verify that a CRL URL is published
* Re-issue cert if needed
Verify that the CRL URL can be accessed
Clear the URL cache
* certutil -urlcache crl delete
* certutil -urlcache ocsp delete
Check validity of the URLS in the cert
* certutil -verify -urlfetch C:\foobar2.cer
Clear and Force re-sync of cache
* certutil -setreg chain\chaincacheresyncfiletime @now
Clear and Force re-sync of cache and don’t use cache for 3 days
* certutil -setreg chain\chaincacheresyncfiletime @now+3
2.7. Reboot the System.