Problem solved. Note the Serial Number of the revoked certificate in the
JSS PKI. Then go into the MySQL database and run the following query to
see if the is_revoked status is 1: select * from
certificate_authority_issued where serial_number='XXXXXX...