Hi @FXE,
all management database: objects, policies, and packages, is synced to the secondary management server. After pushing the secondary SMS to an active role, it will be able to maintain all management functions fully.
However, it is the Primary Management ICA that signs VPN certificates. That means that CRL distribution point is still on the primary SMS. CLR is cashed on your GWs for 24 hours after being retrieved. That means you have a reasonably long time for your VPN runners to continue working before you fully restore your primary management, and it assumes the active role again.
If your primary management server is irretrievably lost, you can promote the secondary server to become primary. You will need to push policies to all VPN GWs after this step, to make sure the CRL DP change is known to the GWs.