<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3987968#M455921</link>
    <description>&lt;P&gt;Here is a list of information we will be putting into the official ISE admin guide . we are also hoping to have a more comprehensive listing after the thanksgiving holiday here in the U.S. I will update then&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;CSCvr90534 Doc: A Document for description of default imported Trusted Certificates is necessary&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Everything should be good here now! Take a look!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www-author3.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www-author3.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do let me know if any further changes are required!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-Problemstatement"&gt;Problem statement&lt;/H1&gt;
&lt;P&gt;"&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;" intermediate CA certificate that comes part of ISE by default in ISE for Cisco Services is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;expiring on Feb 2020&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The issuer of this certificate is "VeriSign Class 3 Public Primary Certification Authority - G5" and this Root CA is valid up to&amp;nbsp;Wed, 16 Jul 2036. This Root CA certificate is trusted by default in ISE for Cisco Services.&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-TrustedforCiscoServices"&gt;Trusted for Cisco Services&lt;/H1&gt;
&lt;P&gt;"&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;" is trusted for Cisco Services by default in ISE.&lt;/P&gt;
&lt;P&gt;Cisco Services can be categorized to following items:&lt;/P&gt;
&lt;P&gt;Posture, Profiler and Client Provisioning (&lt;EM&gt;&lt;STRONG&gt;Group 1&lt;/STRONG&gt;&lt;/EM&gt;). These are using a different certificate chain and not "&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;".&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-Othertrustconfigurations"&gt;Other trust configurations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;It is possible that following services can be internally using this trust certificate for third party verification.&lt;BR /&gt;MDM, SMS, TC-NAC, pxGrid, and CRL/OCSP&amp;nbsp; (&lt;EM&gt;&lt;STRONG&gt;Group 2&lt;/STRONG&gt;&lt;/EM&gt;)&lt;/LI&gt;
&lt;LI&gt;It is possible that customer may have referred this certificate in system certificates, Secure syslog and Secure ldap (&lt;EM&gt;&lt;STRONG&gt;Group 3&lt;/STRONG&gt;&lt;/EM&gt;)&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-GuidelinestosafelyremovethiscertificatefromISE"&gt;Guidelines to safely remove this certificate from ISE&lt;/H1&gt;
&lt;P&gt;Schedule a MW and follow the below guidelines to safely remove this certificate from ISE.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As a first step, go ahead and export this certificate and keep it safe for future purpose. It can be imported back if any of the services in ISE breaks after deleting this certificate.&lt;/LI&gt;
&lt;LI&gt;Disable the certificate and check whether Group 1, 2 and 3 continue to work. Not all the customers use all the services. Test only the relevant services.&lt;/LI&gt;
&lt;LI&gt;Delete the certificate. The delete will not be allowed if certificate is referenced by Group 3. Make configuration changes to remove the references and then delete.&lt;/LI&gt;
&lt;LI&gt;Test Group1, 2 and 3 to make sure all the services continue to work.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 20 Dec 2019 12:08:21 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-12-20T12:08:21Z</dc:date>
    <item>
      <title>[ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3953875#M455897</link>
      <description>&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;Hi Expert,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;I'd like to know how to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;My customer is using the ISE V2.3.7 and they said the above certificate will be expired on Feb 08, 2020 so they want to renew it before it expires.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;Does anyone know what this certificate is for? From my checking, I couldn't find any related guide for that.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;Thank in advance.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;Jihye.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;#Trusted Certificates&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 09:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3953875#M455897</guid>
      <dc:creator>Jihye Han</dc:creator>
      <dc:date>2019-11-06T09:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3953900#M455898</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/848362"&gt;@Jihye Han&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificates in the ISE Trusted Certificates are public certificates. Users do not (and cannot) renew these certificates. If users don't know why a certain certificate is in the Trusted Certificates store in ISE, then you should ignore them. Once they have expired, delete them. Cisco put those certs there but the list is far from complete. Cisco only chose to put a few Root CA certs into ISE but you can install all manner of CA certs (public or private CA's).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certs in the Trusted Cert store are there to allow ISE to perform checks on the validity of certs that it encounters, potentially signed by those CA's in the Trusted Store. But regardless of that, once those trusted certs have expired, they are useless - delete them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Arne&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 07:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3953900#M455898</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-07T07:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954482#M455899</link>
      <description>&lt;P&gt;Hi Arne,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the great explanations.&lt;/P&gt;
&lt;P&gt;I fully understood.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Jihye.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 04:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954482#M455899</guid>
      <dc:creator>Jihye Han</dc:creator>
      <dc:date>2019-11-07T04:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954856#M455900</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/848362"&gt;@Jihye Han&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificates in the ISE Trusted Certificates are public certificates. Users do not (and cannot) renew these certificates. If users don't know why a certain certificate is in the Trusted Certificates store in ISE, then you should ignore them. Once they have expired, delete them. Cisco put those certs there but the list is far from complete. Cisco only chose to put a few Root CA certs into ISE but you can install all manner of CA certs (public or private CA's).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certs in the Trusted Cert store are there to allow ISE to perform checks on the validity of certs that it encounters, potentially signed by those CA's in the Trusted Store. But regardless of that, once those trusted certs have expired, they are useless - delete them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Arne&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;TRUE! also Cisco will update any roots that are critical to its needs on ISE in a patch when coming close to renewal time. Another reason to keep things fresh &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 15:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954856#M455900</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-07T15:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954860#M455912</link>
      <description>&lt;P&gt;I do not think this still in-use so should be safe to delete. It was imported earlier for one of our feed services because either cisco.com or ise.cisco.com or perfigo.com used to use certificates issued by that CA.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 15:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3954860#M455912</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-11-07T15:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957122#M455913</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I currently have the same problem with a client, his "VeriSign Class 3 Secure Server CA - G3" certificate expires in February 2020. How do I know if he uses it? He would like to renew it, is it possible and how do we do it? According to your answer it is not possible to renew this certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 10:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957122#M455913</guid>
      <dc:creator>ciscogo</dc:creator>
      <dc:date>2019-11-12T10:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957599#M455916</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect this is going to be a commonly asked question, because I also found this cert expiration warning on my ISE 2.4 system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This cert was shipped with ISE, but since Cisco doesn't tell us why, it's anyone's guess. I may have seen mention things along the lines of, "ISE needed this cert back in the day to connect to Cisco Call Home, Smart Licensing, or Cisco Profiler Feed Service, or the BYOD Client Provisioning download feature etc." - all these features built into ISE that rely on a TLS connection to trust the end system. But this is a legacy cert and it doesn't appear to be needed for anything that ISE is doing internally.&lt;/P&gt;
&lt;P&gt;As a proof point, I just deleted it and then tested all the "ISE Internet Services" that I could find - and they all still work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's my advice. Before deleting this cert, export it through ISE GUI and then save the file somewhere in case you need it in the next 90 days before it expires. Once the cert has expired, it's no good to anyone. So then you may as well delete it. But if you want to prove to customer that deleting the cert won't break anything, then save a copy before deleting it. If something breaks then they can re-install it and then you'll know what it's for. It's highly unlikely that your customer needs this cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 21:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957599#M455916</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-12T21:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957666#M455918</link>
      <description>Also, there was one defect filed recently to have the details of these certificates documented. &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr90534/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr90534/?rfs=iqvred&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Nov 2019 00:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3957666#M455918</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-11-13T00:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3987968#M455921</link>
      <description>&lt;P&gt;Here is a list of information we will be putting into the official ISE admin guide . we are also hoping to have a more comprehensive listing after the thanksgiving holiday here in the U.S. I will update then&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;CSCvr90534 Doc: A Document for description of default imported Trusted Certificates is necessary&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Everything should be good here now! Take a look!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www-author3.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www-author3.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_0111.html#concept_wzh_vgl_bkb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_0111.html#concept_wzh_vgl_bkb&lt;/A&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do let me know if any further changes are required!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-Problemstatement"&gt;Problem statement&lt;/H1&gt;
&lt;P&gt;"&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;" intermediate CA certificate that comes part of ISE by default in ISE for Cisco Services is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;expiring on Feb 2020&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The issuer of this certificate is "VeriSign Class 3 Public Primary Certification Authority - G5" and this Root CA is valid up to&amp;nbsp;Wed, 16 Jul 2036. This Root CA certificate is trusted by default in ISE for Cisco Services.&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-TrustedforCiscoServices"&gt;Trusted for Cisco Services&lt;/H1&gt;
&lt;P&gt;"&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;" is trusted for Cisco Services by default in ISE.&lt;/P&gt;
&lt;P&gt;Cisco Services can be categorized to following items:&lt;/P&gt;
&lt;P&gt;Posture, Profiler and Client Provisioning (&lt;EM&gt;&lt;STRONG&gt;Group 1&lt;/STRONG&gt;&lt;/EM&gt;). These are using a different certificate chain and not "&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;".&lt;/P&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-Othertrustconfigurations"&gt;Other trust configurations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;It is possible that following services can be internally using this trust certificate for third party verification.&lt;BR /&gt;MDM, SMS, TC-NAC, pxGrid, and CRL/OCSP&amp;nbsp; (&lt;EM&gt;&lt;STRONG&gt;Group 2&lt;/STRONG&gt;&lt;/EM&gt;)&lt;/LI&gt;
&lt;LI&gt;It is possible that customer may have referred this certificate in system certificates, Secure syslog and Secure ldap (&lt;EM&gt;&lt;STRONG&gt;Group 3&lt;/STRONG&gt;&lt;/EM&gt;)&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1 id="VeriSignClass3SecureServerCA–G3expiresonFri,7Feb2020-GuidelinestosafelyremovethiscertificatefromISE"&gt;Guidelines to safely remove this certificate from ISE&lt;/H1&gt;
&lt;P&gt;Schedule a MW and follow the below guidelines to safely remove this certificate from ISE.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As a first step, go ahead and export this certificate and keep it safe for future purpose. It can be imported back if any of the services in ISE breaks after deleting this certificate.&lt;/LI&gt;
&lt;LI&gt;Disable the certificate and check whether Group 1, 2 and 3 continue to work. Not all the customers use all the services. Test only the relevant services.&lt;/LI&gt;
&lt;LI&gt;Delete the certificate. The delete will not be allowed if certificate is referenced by Group 3. Make configuration changes to remove the references and then delete.&lt;/LI&gt;
&lt;LI&gt;Test Group1, 2 and 3 to make sure all the services continue to work.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 20 Dec 2019 12:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/3987968#M455921</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-20T12:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4000496#M455922</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any validated, detaild information about the "&lt;STRONG&gt;VeriSign Class 3 Secure Server CA – G3&lt;/STRONG&gt;"&amp;nbsp; Certificate?&lt;/P&gt;&lt;P&gt;As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&amp;nbsp; mentioned, &amp;nbsp;It is "possible" that following services can be internally using this trust certificate.&lt;/P&gt;&lt;P&gt;How should customers and partners intepret this statement "possible"?&lt;/P&gt;&lt;P&gt;- Does not Cisco know if what exactly the different Trusted Certificates within ISE is used for- related to&amp;nbsp; PxGrid, TC-NAC and so on?&lt;/P&gt;&lt;P&gt;- or Is this something customers them selves can configure to use explicit for TC-NAC? - "How would this typically be done"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Somehow i intepret the answer as: "we have no clue what we are doing - but disable it and see what happends..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 09:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4000496#M455922</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2019-12-18T09:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4000787#M455923</link>
      <description>as stated above we are going to provide a concise guide on this and put it in the admin guide, there is a defect to track</description>
      <pubDate>Wed, 18 Dec 2019 18:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4000787#M455923</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-18T18:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4001831#M455930</link>
      <description>&lt;P&gt;I would have expected a Cisco Field Notice for this since it affects every version of ISE I have come across - at least 2.2 and onwards. &amp;nbsp;(it’s even shipping in ISE 2.7)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Surely a patch would be released to remove this cert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: Another major Wireless vendor sent out a field notice today about this same issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 11:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4001831#M455930</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-12-20T11:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4002327#M455935</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I would have expected a Cisco Field Notice for this since it affects every version of ISE I have come across - at least 2.2 and onwards. &amp;nbsp;(it’s even shipping in ISE 2.7)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Surely a patch would be released to remove this cert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: Another major Wireless vendor sent out a field notice today about this same issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;will see what we can do, for now the guidance is in the guides&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2019 14:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4002327#M455935</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-21T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4013589#M455938</link>
      <description>&lt;P&gt;Thanks Arne for your response on this! Wish there was a field notice from Cisco regarding this as it impacts all the ISE customers!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 16:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4013589#M455938</guid>
      <dc:creator>rsijori@</dc:creator>
      <dc:date>2020-01-17T16:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4018798#M455939</link>
      <description>Hi, sorry for bugging, I have the same symptom , its gonna expire on Fri, 7, 2020,&lt;BR /&gt;&lt;BR /&gt;What does it mean: it impacts all the ISE customers? will it affect the services?&lt;BR /&gt;&lt;BR /&gt;sorry Im not following up&lt;BR /&gt;&lt;BR /&gt;Im running a very old version though, 2.0.236&lt;BR /&gt;&lt;BR /&gt;@ all&lt;BR /&gt;&lt;BR /&gt;has anyone deleted and has encountered any issues?&lt;BR /&gt;&lt;BR /&gt;can I delete it before expiration or should i just wait until it expires?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 27 Jan 2020 14:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4018798#M455939</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2020-01-27T14:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4019108#M455940</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/298280"&gt;@Kn1ghtR1d3rOfD00m&lt;/a&gt;&amp;nbsp; - the question you need to answer is whether any of your ISE 2.0 nodes use Internet based services. If the answer is a categorical NO, then you're ok - delete the cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that Cisco cannot tell us what this cert is used for in ISE (not to my knowledge - correct me if I am wrong)&lt;/P&gt;
&lt;P&gt;Examples of ISE 2.4/2.6 Internet based services are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Profiler Feed Update (ise.cisco.com)&lt;/LI&gt;
&lt;LI&gt;Posture Updates (&lt;A href="https://www.cisco.com/web/secure/spa/posture-update.xml" target="_blank"&gt;https://www.cisco.com/web/secure/spa/posture-update.xml&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Cisco Call Home (and indirectly Smart Licensing)&amp;nbsp; (tools.cisco.com)&lt;/LI&gt;
&lt;LI&gt;Client Provisioning Updates (&lt;A href="https://www.cisco.com/web/secure/spa/provisioning-update.xml" target="_blank"&gt;https://www.cisco.com/web/secure/spa/provisioning-update.xml&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There have been some URL changes since ISE 2.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only way to be sure is to open a TAC case - or reverse engineer the box with tcpdump and analyse the TLS negotiation to see what certs are presented by the foreign servers. Very time consuming ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 22:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4019108#M455940</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-01-27T22:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4026901#M455941</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I opened a TAC case and was advised to download and install two new certificates instead.&lt;/P&gt;&lt;P&gt;These ones are called HydrantID and QuoVadis Root CA 2.&lt;/P&gt;&lt;P&gt;They serve to connect to Cisco.com via SSL in order to obtain binary and data updates for Posture and BYOD.&lt;/P&gt;&lt;P&gt;I estimate that the obsolete Verisign cert was used for this in the past.&lt;/P&gt;&lt;P&gt;You can download them from:&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/283801620/type/283802505/release/cisco.com-certs" target="_blank" rel="noopener"&gt;https://software.cisco.com/download/home/283801620/type/283802505/release/cisco.com-certs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And here is the Field Notice describing the purpose of these certificates and how they should be installed.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/701/fn70122.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/701/fn70122.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;Wini&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 15:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4026901#M455941</guid>
      <dc:creator>derobbacher</dc:creator>
      <dc:date>2020-02-10T15:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4029072#M455942</link>
      <description>&lt;P&gt;I started getting log messages "&lt;SPAN class="td-span"&gt;Smart Licensing Authorization Renewal Failure&lt;/SPAN&gt;" on the same day the cert expired.&amp;nbsp; I don't believe in coincidences.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 15:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4029072#M455942</guid>
      <dc:creator>decubed</dc:creator>
      <dc:date>2020-02-13T15:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4029365#M455943</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/385467"&gt;@decubed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Smart Licensing is still working despite me having deleted the expired Verisign cert.&amp;nbsp; That story about the QuoVadis/Hydrant CA cert is quite old and it was all over the news back then. Perhaps people didn't act on the field notice then, but most systems that have this installed will be ok. Have a look if that fixes your issue.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 21:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4029365#M455943</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-02-13T21:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3.7] How to renew the 'VeriSign Class 2 Secure Server CA - G3 in Trusted Certificates.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4076665#M559984</link>
      <description>&lt;P&gt;With ISE 2.4, we got an error message when trying to delete this cert (VeriSign Class 2 Secure Server CA - G3).&lt;/P&gt;&lt;P&gt;Temporarily disabling all logging (Admin - System - Remote Logging Targets) allowed us to delete the cert even though none of our logging setup appeared to reference that cert.&lt;/P&gt;&lt;P&gt;Our issue and error message appears very similar to: &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvk76680" target="_blank" rel="noopener"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvk76680&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 20:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-7-how-to-renew-the-verisign-class-2-secure-server-ca-g3/m-p/4076665#M559984</guid>
      <dc:creator>innovative_elephant</dc:creator>
      <dc:date>2020-04-29T20:30:58Z</dc:date>
    </item>
  </channel>
</rss>

