<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import root certificate with same subject and issuer name in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3695315#M508064</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Hosuk&lt;/SPAN&gt; for your response. It answered my questions.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Aug 2018 07:15:31 GMT</pubDate>
    <dc:creator>Neelesh Marathe</dc:creator>
    <dc:date>2018-08-27T07:15:31Z</dc:date>
    <item>
      <title>Import root certificate with same subject and issuer name</title>
      <link>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3691935#M508060</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have total 22 ISE nodes ( Including Admin+Mnt) in cluster and using ISE 2.4 version. We have already installed identity certificate for every node from private CA and assigned "Admin" role in ISE. We have also installed root certificate in Trusted store.&amp;nbsp;All the certificates are SHA1 certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now customer has upgraded the same Certificate Authority server to support SHA 2 and provided us new identity and root certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While importing the new root certificate, it is giving the following error.&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;STRONG&gt;"There is one system certificate with the same subject name and issuer but having a different serial number. Importing was aborted. For successful importing, you need to remove the other certificate first&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My questions are,&lt;/P&gt;
&lt;P&gt;1. If I remove the earlier root certificate, not changing identity certificate role, will it impact ISE functionality?&lt;/P&gt;
&lt;P&gt;2. Do I need to change "Admin role" to some other certificate first and then remove the root certificate ? and then install new root and Identity certificates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please guide us the correct way of importing the certificates in this scenarios&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Neelesh Marathe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 07:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3691935#M508060</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2018-08-21T07:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Import root certificate with same subject and issuer name</title>
      <link>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3692254#M508062</link>
      <description>&lt;P&gt;1. Yes, but you will not be able to remove the root CA certificate until none of the identity certificates are tied to the old root CA&lt;/P&gt;
&lt;P&gt;2. Yes, but make sure even after using another certificate temporarily, that the communication between PAN and secondary nodes are functioning before proceeding.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 15:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3692254#M508062</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-21T15:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Import root certificate with same subject and issuer name</title>
      <link>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3695315#M508064</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Hosuk&lt;/SPAN&gt; for your response. It answered my questions.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 07:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/import-root-certificate-with-same-subject-and-issuer-name/m-p/3695315#M508064</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2018-08-27T07:15:31Z</dc:date>
    </item>
  </channel>
</rss>

