Then, optionally, a URL is configured to allow Skyhigh CASB to query the Certificate Revocation List to verify that the existing certs are valid. When a device requests access to an endpoint, Skyhigh ...Then, optionally, a URL is configured to allow Skyhigh CASB to query the Certificate Revocation List to verify that the existing certs are valid. When a device requests access to an endpoint, Skyhigh CASB checks the endpoint for a required certificate, which must be signed by the CA public certificate (which is imported into Skyhigh CASB). The Cloud Access Policies page is located at Policy > Access Control > Access Policies.