<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Self-signed Root certificates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3997622#M455080</link>
    <description>&lt;P&gt;You should not put self signed certs in the Trusted Store. The Trust Store is for CA certs. Yes - self-signed certs are Root certs and therefore a CA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But -&amp;nbsp; you said you don't use ISE self-signed certs. So why do you want to keep these hanging around?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So to answer your question - an ISE Self-Signed cert originates from the System Certs section.&amp;nbsp; go there and click on the Generate Self-Signed cert to create new ones. Then delete the old one(s).&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2019 04:33:54 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2019-12-12T04:33:54Z</dc:date>
    <item>
      <title>Self-signed Root certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3996500#M455079</link>
      <description>&lt;P&gt;My self signed Root certificates have expired in the Trusted certificates section. They are not being used by any services yet I'd like to renew them. Unlike the System certs there is no option to renew them. Anyone assist ?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 14:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3996500#M455079</guid>
      <dc:creator>fazmeister4</dc:creator>
      <dc:date>2019-12-10T14:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Self-signed Root certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3997622#M455080</link>
      <description>&lt;P&gt;You should not put self signed certs in the Trusted Store. The Trust Store is for CA certs. Yes - self-signed certs are Root certs and therefore a CA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But -&amp;nbsp; you said you don't use ISE self-signed certs. So why do you want to keep these hanging around?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So to answer your question - an ISE Self-Signed cert originates from the System Certs section.&amp;nbsp; go there and click on the Generate Self-Signed cert to create new ones. Then delete the old one(s).&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 04:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3997622#M455080</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-12-12T04:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Self-signed Root certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3998046#M455081</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;You should not put self signed certs in the Trusted Store. The Trust Store is for CA certs. Yes - self-signed certs are Root certs and therefore a CA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But -&amp;nbsp; you said you don't use ISE self-signed certs. So why do you want to keep these hanging around?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So to answer your question - an ISE Self-Signed cert originates from the System Certs section.&amp;nbsp; go there and click on the Generate Self-Signed cert to create new ones. Then delete the old one(s).&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;agree, also check out&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 17:13:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3998046#M455081</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-12T17:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Self-signed Root certificates</title>
      <link>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3999854#M455082</link>
      <description>&lt;P&gt;Thanks, I've removed them now&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 10:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-signed-root-certificates/m-p/3999854#M455082</guid>
      <dc:creator>fazmeister4</dc:creator>
      <dc:date>2019-12-17T10:13:15Z</dc:date>
    </item>
  </channel>
</rss>

