Administrators may observe a warning message in the Symantec Management Platform Internet Gateway manager under the Servers tab stating: "X certificate(s) have been revoked." This often raises concerns regarding the health of Cloud Enabled Management (CEM) communications and whether active agents are being blocked from connecting.
ITMS 8.7.x, 8.8
The "Revoked certificate" message is an expected behavior of the ITMS certificate management process. When an agent certificate is discarded—such as during an agent uninstallation, machine retirement, or certificate renewal—the Symantec Management Platform (SMP or Notification Server (NS)) adds that certificate to a Certificate Revocation List (CRL). The Internet Gateway (IGW) downloads this list to ensure it does not allow connections from decommissioned assets. While this follows security best practices, a high volume of revoked certificates can occasionally lead to performance overhead on the Gateway.
The root cause is the standard lifecycle management of CEM agent certificates.
By Design: Every time a CEM agent certificate is superseded or retired, it is added to the CRL to prevent unauthorized reuse of that specific certificate.
Scalability: In large environments, the CRL grows significantly.
NOTE:
In versions prior to 8.8.1, the Gateway processed these lists in a manner that could cause performance degradation when the list became excessively large. That concern has been addressed with the changes coming with ITMS 8.8.1.
If the "revoked" count is high or you suspect Gateway performance issues, you can manually clear the CRL files. This resets the message and forces the Gateway to re-sync only the most current revocation data.
Log in to the SMP Server as an Administrator.
Open the MMC Console (Start > Run > mmc).
Click File > Add/Remove Snap-in..., select Certificates, click Add, and choose Computer account.
Navigate to Trusted Root Certification Authorities > Certificate Revocation List.
Action: Right-click the SMP CA CRL, select All Tasks > Export (to keep a backup), and then Delete the CRL entry.
Repeat this for Intermediate Certification Authorities > Certificate Revocation List if any SMP-related CRLs exist there.
On the Internet Gateway server, open the Services snap-in (services.msc).
Right-click Symantec Management Platform Internet Gateway and select Stop.
Close the Internet Gateway Manager UI.
Open File Explorer and navigate to:
C:\Program Files\Symantec\SMP Internet Gateway\crl
Action: Backup the contents of this folder to a different location, then delete all files within the \crl folder.
Open the Internet Gateway Manager UI.
Navigate to the Servers tab.
Select the Notification Server entry.
Click Remove, then click Add to re-establish the connection to the SMP (or click Refresh if the "Revoked" message clears immediately).
Restart the Symantec Management Platform Internet Gateway service.
Check IGW UI: The "Servers" tab should now show a status of "Connected" with 0 (or a significantly lower) number of revoked certificates or just saying "No revocations".
Log Verification: Check the Gateway logs located in C:\Program Files\Symantec\SMP Internet Gateway\logs for any "Failed to process CRL" errors.