<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After upgrade to 2.6 CA process not starting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/3901488#M470818</link>
    <description>&lt;P&gt;&lt;SPAN&gt;After upgrading to v2.6 on primary node,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &lt;/STRONG&gt;&lt;SPAN&gt;is running well. While on secondary node,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &lt;/STRONG&gt;&lt;SPAN&gt;cannot initiate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In v2.4,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;was running well on both nodes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="con-NoMargin hist-break-word"&gt;ISE PROCESS NAME                       STATE            PROCESS ID
--------------------------------------------------------------------
Database Listener                      running          2608
Database Server                        running          119 PROCESSES
Application Server                     running          11194
Profiler Database                      running          5251
ISE Indexing Engine                    running          13422
AD Connector                           running          19174
M&amp;amp;T Session Database                   running          5013
M&amp;amp;T Log Processor                      running          11417
Certificate Authority Service          initializing
EST Service                            not running
SXP Engine Service                     disabled
Docker Daemon                          running          6395
TC-NAC Service                         disabled&lt;/PRE&gt;
&lt;P&gt;We have tried restarting the application many times (stop/start), but same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried this&amp;nbsp;&lt;/P&gt;
&lt;DIV id="a091C000022Mh15QAC" class="hist-container hist-note con-header-external-note"&gt;
&lt;DIV class="detail con-detail-external-note"&gt;
&lt;DIV class="hist-preview"&gt;
&lt;PRE class="con-NoMargin hist-break-word"&gt; &lt;A title="https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698" href="https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698&lt;/A&gt;&lt;/PRE&gt;
&lt;P&gt;But customer does not have Plus License to generate CSR. (EST service is also not running).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="a091C000022Mh1OQAS" class="hist-container hist-note con-header-internal-note"&gt;
&lt;DIV class="hist-record-header"&gt;
&lt;H1 class="hist-header-text"&gt;&amp;nbsp;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2019 14:13:39 GMT</pubDate>
    <dc:creator>ksastoqu</dc:creator>
    <dc:date>2019-08-01T14:13:39Z</dc:date>
    <item>
      <title>After upgrade to 2.6 CA process not starting</title>
      <link>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/3901488#M470818</link>
      <description>&lt;P&gt;&lt;SPAN&gt;After upgrading to v2.6 on primary node,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &lt;/STRONG&gt;&lt;SPAN&gt;is running well. While on secondary node,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &lt;/STRONG&gt;&lt;SPAN&gt;cannot initiate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In v2.4,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority Service &amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;was running well on both nodes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="con-NoMargin hist-break-word"&gt;ISE PROCESS NAME                       STATE            PROCESS ID
--------------------------------------------------------------------
Database Listener                      running          2608
Database Server                        running          119 PROCESSES
Application Server                     running          11194
Profiler Database                      running          5251
ISE Indexing Engine                    running          13422
AD Connector                           running          19174
M&amp;amp;T Session Database                   running          5013
M&amp;amp;T Log Processor                      running          11417
Certificate Authority Service          initializing
EST Service                            not running
SXP Engine Service                     disabled
Docker Daemon                          running          6395
TC-NAC Service                         disabled&lt;/PRE&gt;
&lt;P&gt;We have tried restarting the application many times (stop/start), but same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried this&amp;nbsp;&lt;/P&gt;
&lt;DIV id="a091C000022Mh15QAC" class="hist-container hist-note con-header-external-note"&gt;
&lt;DIV class="detail con-detail-external-note"&gt;
&lt;DIV class="hist-preview"&gt;
&lt;PRE class="con-NoMargin hist-break-word"&gt; &lt;A title="https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698" href="https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/identity-services-engine-ise/error-message-quot-est-service-not-running-quot-since-upgrade-to/td-p/3484698&lt;/A&gt;&lt;/PRE&gt;
&lt;P&gt;But customer does not have Plus License to generate CSR. (EST service is also not running).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="a091C000022Mh1OQAS" class="hist-container hist-note con-header-internal-note"&gt;
&lt;DIV class="hist-record-header"&gt;
&lt;H1 class="hist-header-text"&gt;&amp;nbsp;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 14:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/3901488#M470818</guid>
      <dc:creator>ksastoqu</dc:creator>
      <dc:date>2019-08-01T14:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 2.6 CA process not starting</title>
      <link>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/3903994#M470824</link>
      <description>&lt;P&gt;Please try recreating and engaging our ISE ESC team, if needed.&amp;nbsp;CSCvj11319 is not a known issue for ISE 2.6.&lt;/P&gt;
&lt;P&gt;ISE Plus licenses are not required to run ISE CA services, as to support session exchanges via pxGrid for Cisco subscribers.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 17:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/3903994#M470824</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-08-06T17:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 2.6 CA process not starting</title>
      <link>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/4002076#M470831</link>
      <description>&lt;P&gt;Actually, Plus license is required for internal CA between two ISE nodes.&amp;nbsp; Unfortunately, that does not solve this problem.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 17:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/4002076#M470831</guid>
      <dc:creator>dave.devries</dc:creator>
      <dc:date>2019-12-20T17:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 2.6 CA process not starting</title>
      <link>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/4052744#M559171</link>
      <description>&lt;P&gt;So regenerating the ISE root cert will solve the issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will regenereating the cert impact the registration of the 2 ISE node?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 10:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/after-upgrade-to-2-6-ca-process-not-starting/m-p/4052744#M559171</guid>
      <dc:creator>mattvoon91</dc:creator>
      <dc:date>2020-03-26T10:27:21Z</dc:date>
    </item>
  </channel>
</rss>

