Would it be possible to use a probabilistic data structure (e.g. Bloom filter) to create a privacy-enabled CRL as a service?
The hard thing would be to generate an accurate whitelist.
I updated my key and certificate, and for the browser-visible certificate metadata only the fingerprint changed.