I have reviewed version 03 of draft-ietf-lamps-keyusage-crl-validation and consider it ready for publication. The threat it addresses is important and it is a clear improvement over the existing spec. The security considerations include coversage of he important "what if it's too late?" case. It's slightly concerning that such an asymmetry could sneak through the RFC process but IMO that's the nature of V3 complexity among other things. Good that the authors caught it.