How to replace, renew, and revoke certificates in IT Management Suite (ITMS) 8.x
How to replace Cloud-Enabled Management (CEM) certificates in ITMS 8.x
Agents cannot access the Notification Server.
ITMS 8.x
REPLACE CERTIFICATE
To replace a certificate, on the Certificate Management page (Settings > All Settings > Notification Server > Certificate Management), you can do the following:
If you have not enabled the Auto Refresh... option in the Internet Gateway Manager, on the Servers tab, take the following steps to perform the replacement of the NS root certificate:
Note that while the replacement is in progress, you can cancel it. Canceling the replacement process does not break connectivity and the old certificate remains in use.
Note:
One thing to consider during the "Replace" process is the values displayed (for example, "2076 of 2393 agents received the new certificate) means that 2393 agents have the reference of the old certificate in the inventory previously sent and 2076 have received the new one also. This number is unrelated to the number of agents that have the CEM policy applied. If the agent does not report the old certificate - it is not included in this 2393 number. Also if some of the agents haven't communicated for a while, ithey will never get a new web certificate and will be in this statistic until it will be deleted as a resource.
Optional Method:
Many customers want to make sure that the certificate change will work before committing to replacing completely the certificate.
The simplest way to test that the process will work is:
RENEW CERTIFICATE
The renewal task lets you re-create CEM Agent certificates on cloud-enabled agents. This task also lets you re-create an Internet gateway reporting certificate that the Internet gateway uses for sending its inventory to the Notification Server.
To renew a certificate, on the Certificate Management page, you can do the following:
If you have not enabled the Auto Refresh... option in the Internet Gateway Manager, on the Settings tab, take the following steps to perform the renewal of the Internet gateway reporting certificate:
REVOKE CERTIFICATE
Revoking a CEM Agent certificate prevents the managed computer from accessing your network in cloud-enabled mode. For example, if a cloud-enabled laptop computer is lost or stolen you need to revoke its certificate immediately.
To revoke a certificate, on the Certificate Management page, you can do the following:
NOTE:
This information can be found at: Managing Certificates