Currently, EJBCA always generates a CRL when renewing a CA, even if the same CA key is used. In this case it is not necessary to generate a new CRL.
CRL generation can take a really long time (which can in turn trigger transaction timeouts in the application server). And renewing without rekeying is the common case for SubCAs.
We should skip the CRL generation when the CA is renewed with the existing key.