<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Serg, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869751#M39348</link>
    <description>&lt;P&gt;Hi Serg,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to make sure you take a backup of the ISE before resetting the config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have a valid contract you can open a case with TAC and they can delete the certificates from the root shell.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jun 2016 03:49:36 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-06-20T03:49:36Z</dc:date>
    <item>
      <title>Cisco ISE 1.2 wrong certificate on admin node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869749#M39342</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I made the mistake of entering the wrong certificate on Administration ISE node. Now i can't to connect to it, because entered certificate can't be used for building https connection. I have access by ssh, but i don't now how to fix this issue from cli.&amp;nbsp;Is it possible?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869749#M39342</guid>
      <dc:creator>Serg Romanovets</dc:creator>
      <dc:date>2019-03-26T00:34:43Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869750#M39343</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've never had this kind of issue. However the cli commands are quite limited.&lt;/P&gt;
&lt;P&gt;There is a command&amp;nbsp;application reset-config ise where the 1st question is initialization of ISE and the 2nd concerning certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this isn't a production server, try this command by saying No at the first question (factory reset of ISE) and No the 2nd question (Retain server certificates).&lt;/P&gt;
&lt;P&gt;If it won't work, you'll need to reply Yes at the 1st and No at the 2nd question but you'll loose all config (rules and AD join).&lt;/P&gt;
&lt;P&gt;If you have a lot of rules,.. I would suggest these steps (Except if someone else has another idea, but on my side I don't see another ways):&lt;/P&gt;
&lt;P&gt;- Make a backup of your actual ISE through CLI (I'll paste after the link of ISE backup/restore command)&lt;/P&gt;
&lt;P&gt;- Reset to factory as per command given before&lt;/P&gt;
&lt;P&gt;- Export self signed certificate (application configure ise)&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/cli_ref_guide/b_ise_CLIReferenceGuide/b_ise_CLIReferenceGuide_chapter_0101.html#ID-1363-0000020d&lt;/P&gt;
&lt;P&gt;- Restore your backup from CLI (you won't be able to connect through https like today)&lt;/P&gt;
&lt;P&gt;- Import back the certificate backup you've done just before (resetting certificate)&lt;/P&gt;
&lt;P&gt;- Now you'll be able to connect and retrieve all your datas.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below a link for backup/restore:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_backup.html#35144&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this answered your question.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2016 23:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869750#M39343</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-19T23:27:35Z</dc:date>
    </item>
    <item>
      <title>Hi Serg,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869751#M39348</link>
      <description>&lt;P&gt;Hi Serg,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to make sure you take a backup of the ISE before resetting the config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have a valid contract you can open a case with TAC and they can delete the certificates from the root shell.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 03:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869751#M39348</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-20T03:49:36Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 do not support import</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869752#M39351</link>
      <description>&lt;P&gt;ISE 1.2&amp;nbsp;do not support import/export certificate from cli, i'll try to update it to 1.3. When i&amp;nbsp;imported&amp;nbsp;self-signed&amp;nbsp;certificate into cert store, all current certificates will be replaced by this one?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 06:00:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869752#M39351</guid>
      <dc:creator>Serg Romanovets</dc:creator>
      <dc:date>2016-06-21T06:00:08Z</dc:date>
    </item>
    <item>
      <title>Yes you're right. It's been a</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869753#M39354</link>
      <description>&lt;P&gt;Yes you're right. It's been a while I'm not using ISE 1.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 11:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-wrong-certificate-on-admin-node/m-p/2869753#M39354</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-21T11:32:01Z</dc:date>
    </item>
  </channel>
</rss>

