As we do the switch towards making the certificate owner responsible for its own certificate, there is a need for a background service that periodically checks the last issued CRL via the distribution points, and when a service's certificate is revoked it creates a new certificate immediately for the service, and resets the certificate renewal task also running in the background.