<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CERTIFICATE RENEWAL/DELETE ERROR in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686823#M495299</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently running with two node deployment with &lt;STRONG&gt;ISE version 2.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;My SAML certificate got expired on my Secondary node, when I am trying to renew I am getting the error as &lt;EM&gt;&lt;STRONG&gt;ISE Node not Reachable&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;In order to renew From Secondary Node I am not seeing the option to edit the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When trying to delete the certificate I am getting the message as below..........&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"One or more certificates that are selected for delete are shared certificate(s). Deleting the shared certificate will delete the corresponding certificate(s) on rest of the nodes in the deployment. Please confirm this is intended by clicking Delete.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;The following certificate(s) are shared certificates. Are you sure you want to delete them?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Default self-signed saml server certificate - "&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;My concern is that My SAML on Primary certificate will also get deleted if I continue to delete on Secondary node (Please correct me here if I am wrong here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need helpful suggestion for the above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Aug 2018 05:04:05 GMT</pubDate>
    <dc:creator>Ali</dc:creator>
    <dc:date>2018-08-13T05:04:05Z</dc:date>
    <item>
      <title>CERTIFICATE RENEWAL/DELETE ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686823#M495299</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently running with two node deployment with &lt;STRONG&gt;ISE version 2.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;My SAML certificate got expired on my Secondary node, when I am trying to renew I am getting the error as &lt;EM&gt;&lt;STRONG&gt;ISE Node not Reachable&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;In order to renew From Secondary Node I am not seeing the option to edit the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When trying to delete the certificate I am getting the message as below..........&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"One or more certificates that are selected for delete are shared certificate(s). Deleting the shared certificate will delete the corresponding certificate(s) on rest of the nodes in the deployment. Please confirm this is intended by clicking Delete.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;The following certificate(s) are shared certificates. Are you sure you want to delete them?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;Default self-signed saml server certificate - "&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;My concern is that My SAML on Primary certificate will also get deleted if I continue to delete on Secondary node (Please correct me here if I am wrong here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need helpful suggestion for the above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 05:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686823#M495299</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-08-13T05:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE RENEWAL/DELETE ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686902#M495308</link>
      <description>&lt;P&gt;The first question here is, is the secondary node still joined to the cluster?&lt;/P&gt;
&lt;P&gt;If you go to the "Administration &amp;gt; Deployment" page, do you still see the secondary as connected and synchronised without any issues?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's not connected can you force a re-sync? (Caution: this will caue the secondary to reboot)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it won't re-sync, can you SSH to it and give it a reboot?&amp;nbsp; Verify Routing and FW rules are all ok between the two boxes?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 08:19:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686902#M495308</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-08-13T08:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: CERTIFICATE RENEWAL/DELETE ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686965#M495316</link>
      <description>&lt;P&gt;Hello Richa,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the reply&lt;/P&gt;
&lt;P&gt;Yes,&amp;nbsp;both the nodes are in cluster and synchronized.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other option I can try ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-renewal-delete-error/m-p/3686965#M495316</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-08-13T10:14:41Z</dc:date>
    </item>
  </channel>
</rss>

