Yes and as part of my troubleshooting I've validated that ipa has:
ca.crl.MasterCRL.enableCRLUpdates=true
ca.crl.MasterCRL.enableCRLCache=true
ca.crl.MasterCRL.enableCRLUpdates=true
The CRL files in /var/lib/ipa/pki-ca/publish/ are being generated - but no certificates
that have been revoked since around Dec of last year (when ipa2 became CRL master) have
been added to the CRL.