Revoke command creates expired CRL. I've found this out when tried to use certstrap-produced CRL with nginx which performs expiry check on CRL.