Hi there,
The target host is not able to validate the domain controller certificate, if It fails to obtain a CRL (or OCSP response) due to DNS or network issues, or A certificate in the chain or published CRL has expired.
Check out some additional troubleshooting steps from this forums https://social.technet.microsoft.com/Forums/en-US/d63f9b72-e6bf-4df0-877e-860e364e0481/smart-card-logon-not-working-until-i-disable-revocation-check?forum=winserversecurity
--If the reply is helpful, please Upvote and Accept it as an answer--