Dear Colleagues,
I found the answer to my own problem -- the root.crl (Certificate
revocation list) was malformed. When I deleted the root.crl files from
the client and server locations, everything works as advertised.
For anyone who looked at my problem, thank you.
Cheers,
Bob