<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alarm about expiration certificate (SAML) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3754331#M487784</link>
    <description>&lt;P&gt;how can we know if this certificate is being used? in what config this certificate would be used? thanks for your response&lt;/P&gt;</description>
    <pubDate>Wed, 28 Nov 2018 13:14:10 GMT</pubDate>
    <dc:creator>SupportAC</dc:creator>
    <dc:date>2018-11-28T13:14:10Z</dc:date>
    <item>
      <title>Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3753621#M487723</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are receiving this alarm about certificate expiring. We would like to know what it the use for this certificate and to know if this certificate is being used and how to renew it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alarm Name :&lt;/P&gt;
&lt;P&gt;Certificate Expiration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Details :&lt;/P&gt;
&lt;P&gt;Local certificate 'Default self-signed saml server certificate - CN=SAML_ISE01.COMPANY.COM' will expire in 53 days : Server=ISE01&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Description :&lt;/P&gt;
&lt;P&gt;This certificate will expire soon.&amp;nbsp; When it expires, ISE may fail when attempting to establish secure communications with clients.&amp;nbsp; Inter-node communication may also be affected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Severity :&lt;/P&gt;
&lt;P&gt;Warning&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Suggested Actions :&lt;/P&gt;
&lt;P&gt;Replace the certificate.&amp;nbsp; For a trust certificate, contact the issuing Certificate Authority (CA).&amp;nbsp; For a CA-signed local certificate, generate a CSR and have the CA create a new certificate.&amp;nbsp; For a self-signed local certificate, use ISE to extend the expiration date. You can just delete the certificate if it is no longer used&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 13:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3753621#M487723</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-12-17T13:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3753853#M487725</link>
      <description>&lt;P&gt;That depends on whether or not you are using the certificate for any purpose on the ISE. ISE creates that certificate by default when you install it just in case you need it. If you have not ever used it before or do not intend to use that certificate for any purpose, please feel free to delete it. It will not harm any of your services. Besides, ISE will not allow to delete a certificate if it is being used somewhere.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 20:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3753853#M487725</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-11-27T20:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3754331#M487784</link>
      <description>&lt;P&gt;how can we know if this certificate is being used? in what config this certificate would be used? thanks for your response&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 13:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3754331#M487784</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-11-28T13:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3756632#M487785</link>
      <description>&lt;P&gt;any idea?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 08:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3756632#M487785</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-12-03T08:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3756645#M487786</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the PAN, go to Administration &amp;gt; System &amp;gt; Certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under System Certificates you can see which active usage each certificate has. If it's not in use, its usage will be "Not in Use" and then you can safely remove it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, you can manage the certificates of all nodes of the deployment from this menu.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 08:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3756645#M487786</guid>
      <dc:creator>Nadav</dc:creator>
      <dc:date>2018-12-03T08:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765006#M487787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the certificate but the certificate for ISE01 seems like "Not in use"&lt;/P&gt;
&lt;P&gt;and in the certicifate for ISE1 is used by SAML.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can confirm that SAML is being used? how can i renew the certificate or make sure is being used?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="saml.jpg" style="width: 660px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/26332i6C49141F1A5CDEE8/image-size/large?v=v2&amp;amp;px=999" role="button" title="saml.jpg" alt="saml.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 12:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765006#M487787</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-12-17T12:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765058#M487788</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I went to the IdP provider config and i can confirm that SAML is not being used. So what the recommended option: to renew this certificate or keep it expired?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 14:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765058#M487788</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2018-12-17T14:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765302#M487789</link>
      <description>&lt;P&gt;As the IdP not using it to validate the SAML requests, its expiration has no impact on authentication. Later on, you might need either renew or delete it while upgrading ISE to a later release.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 19:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/3765302#M487789</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T19:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4046751#M558929</link>
      <description>&lt;P&gt;I tried to delete the default self-signed SAML certificate since the customer is not using SAML. But I get a message (see attachment) when trying to delete it. I even generated a new certificate with SAML as the error message stated, but I'm back to the same problem. It just moves the problem, not resolve it. Is it even possible to remove it?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4046751#M558929</guid>
      <dc:creator>toyip</dc:creator>
      <dc:date>2020-03-16T17:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4047020#M558938</link>
      <description>&lt;P&gt;An ISE cluster only supports one certificate bound to the SAML usage. If you create a new self-signed certificate with the SAML usage, it should move the SAML usage to that new certificate. Once that happens, you should be able to delete the old SAML certificate.&lt;/P&gt;&lt;P&gt;If the SAML usage is not moving to the new certificate or SAML is being bound to more than one cert, you will likely need to open a TAC case. They can use the root patch to find and remove certificate linkages directly from the database.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 05:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4047020#M558938</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-03-17T05:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4048071#M558979</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;An ISE cluster only supports one certificate bound to the SAML usage. If you create a new self-signed certificate with the SAML usage, it should move the SAML usage to that new certificate. Once that happens, you should be able to delete the old SAML certificate.&lt;/P&gt;&lt;P&gt;If the SAML usage is not moving to the new certificate or SAML is being bound to more than one cert, you will likely need to open a TAC case. They can use the root patch to find and remove certificate linkages directly from the database.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks Greg. I did create another self-signed cert with SAML, then I was able to delete the old cert. But now I can't delete the new cert with SAML, so I'm back to where I started. Anyway, may need to get TAC involved as you suggested.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 14:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4048071#M558979</guid>
      <dc:creator>toyip</dc:creator>
      <dc:date>2020-03-18T14:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4048441#M558991</link>
      <description>&lt;P&gt;ISE requires a certificate installed for the SAML usage even if you are not using the SAML function (the same is true of the other usages like RADIUS DTLS, pxGrid, etc).&lt;/P&gt;&lt;P&gt;Since the SAML usage can only be assigned to a unique certificate (it cannot be assigned to a certificate with any other usages), you will not be able to delete the new certificate.&lt;/P&gt;&lt;P&gt;This is working as designed.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 01:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/alarm-about-expiration-certificate-saml/m-p/4048441#M558991</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-03-19T01:48:10Z</dc:date>
    </item>
  </channel>
</rss>

