If you use DirectAccess (DA), should you use a certificate on the IP-HTTPS listener from your internal CA or from a third party CA?
If you use a certificate from your internal CA, you’ll have to publish the CRL so it can be reached from the outside. If you don’t do it, external DA clients will remove the CRL from the cache after 24 hours and they will not be able to check if the certificate has been revoked or similar. DA will not work for them until they put their laptop in the internal network, and are able to reach the CRL.
The default time for the cache is 24 hours.
So I would not bother publishing the CRL, but instead use a third party certificate on the IP-HPPS listener.
If you use or consider using DA without UAG, Win8 has a lot of improvements regarding DA (features you only found in UAG).
For a complete list check out http://technet.microsoft.com/nb-no/library/hh831416.aspx