I'm still going to ask if you have any idea why it's stalling on CRL downloads....
bash-3.2# tcpdump -i any tcp port 18264
tcpdump: data link type PKTAP
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type PKTAP (Apple DLT_PKTAP), capture size 262144 bytes
15:20:16.057786 IP 10.11.1.238.54585 > ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264: Flags [S], seq 659357598, win 65535, options [mss 1460,nop,wscale 6,nop,nop,TS val 2695332272 ecr 0,sackOK,eol], length 0
15:20:16.093006 IP ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264 > 10.11.1.238.54585: Flags [S.], seq 2486278603, ack 659357599, win 28960, options [mss 1460,sackOK,TS val 7464633 ecr 2695332272,nop,wscale 10], length 0
15:20:16.093121 IP 10.11.1.238.54585 > ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264: Flags [.], ack 1, win 2058, options [nop,nop,TS val 2695332307 ecr 7464633], length 0
15:20:16.094406 IP 10.11.1.238.54585 > ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264: Flags [F.], seq 1, ack 1, win 2058, options [nop,nop,TS val 2695332308 ecr 7464633], length 0
15:20:16.131496 IP ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264 > 10.11.1.238.54585: Flags [F.], seq 1, ack 2, win 29, options [nop,nop,TS val 7464672 ecr 2695332308], length 0
15:20:16.131622 IP 10.11.1.238.54585 > ec2-3-67-225-215.eu-central-1.compute.amazonaws.com.18264: Flags [.], ack 2, win 2058, options [nop,nop,TS val 2695332345 ecr 7464672], length 0
^C
6 packets captured
1462 packets received by filter
0 packets dropped by kernel
(Seeing zero length payloads)