<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is the PAN CA is not there? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457249#M527081</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Forum,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 nodes a primary and a secondary. I'm deploying onboarding for byod but I'm having an issue where my primary PAN/PSN CA certs are not there. I check on the cli and the Cert authority service is running. See the attached image. the issue is that when users are redirected to the primary PSN for onboarding, the get an error regarding SSL session but when I disconnect the primary PSN and the user request goes to secondary PSN they work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice is appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Sep 2017 03:48:45 GMT</pubDate>
    <dc:creator>ffadhilpi</dc:creator>
    <dc:date>2017-09-01T03:48:45Z</dc:date>
    <item>
      <title>Why is the PAN CA is not there?</title>
      <link>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457249#M527081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Forum,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 nodes a primary and a secondary. I'm deploying onboarding for byod but I'm having an issue where my primary PAN/PSN CA certs are not there. I check on the cli and the Cert authority service is running. See the attached image. the issue is that when users are redirected to the primary PSN for onboarding, the get an error regarding SSL session but when I disconnect the primary PSN and the user request goes to secondary PSN they work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice is appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Sep 2017 03:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457249#M527081</guid>
      <dc:creator>ffadhilpi</dc:creator>
      <dc:date>2017-09-01T03:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the PAN CA is not there?</title>
      <link>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457250#M527082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the trust certificate store and verify if see the Root CA cert.&amp;nbsp; Depending on which node was Primary PAN at time of install, root CA may be on secondary PAN now.&amp;nbsp; You can create repository and run export internal CA certs from CLI (under 'application configure ise') and you will see all the cert certs and chain after export in CLI.&amp;nbsp; Check on both nodes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Sep 2017 12:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457250#M527082</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-01T12:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the PAN CA is not there?</title>
      <link>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457251#M527083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Craig's, it appears that your deployment's primary PAN changed the hostname before, because the common name of the root CA looks differently from either node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are going to change the hostname again, I would suggest you to go ahead doing that and then replace the internal CA certificates, which will be single-root. See &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0111.html#task_FF93B4C51BAC4CA196A48B607DAA595D"&gt;Generate Root CA and Subordinate CAs on the PAN and PSN&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Sep 2017 21:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-is-the-pan-ca-is-not-there/m-p/3457251#M527083</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-01T21:41:10Z</dc:date>
    </item>
  </channel>
</rss>

