<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error starting Internal CA on ISE 1.3 Patch 4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726560#M54365</link>
    <description>&lt;P&gt;It seems our Internal CA is unable to start because of a missing keystore password file. We tried disabling/enabling the Internal CA which did not help. We'd like to regenerate the Internal CA certificate, but we are getting a&amp;nbsp;"No message defined" error, presumably because the CA service is not running properly. Anyone know of a way to force ISE to generate the missing file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;[2015-05-26 16:13:11,582] [] [WARN]&lt;/DIV&gt;&lt;DIV&gt;could not read from /opt/CSCOcpm/appsrv/apache-tomcat-ca/conf/ca_nssdb_password.txt&lt;/DIV&gt;&lt;DIV&gt;java.io.FileNotFoundException: /opt/CSCOcpm/appsrv/apache-tomcat-ca/conf/ca_nssdb_password.txt (No such file or directory)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.open(Native Method)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.DataUtil.loadFile(DataUtil.java:83)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:133)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.init(CaStore.java:113)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;init&amp;gt;(CaStore.java:67)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;clinit&amp;gt;(CaStore.java:60)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.bootstrap.CaServerSeeding.main(CaServerSeeding.java:43)&lt;/DIV&gt;&lt;DIV&gt;[2015-05-26 16:13:11,598] [] [WARN]&lt;/DIV&gt;&lt;DIV&gt;could not initialize KeyStore&lt;/DIV&gt;&lt;DIV&gt;com.cisco.cpm.caservice.CARuntimeException: java.lang.NullPointerException&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:155)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.init(CaStore.java:113)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;init&amp;gt;(CaStore.java:67)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;clinit&amp;gt;(CaStore.java:60)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.bootstrap.CaServerSeeding.main(CaServerSeeding.java:43)&lt;/DIV&gt;&lt;DIV&gt;Caused by: java.lang.NullPointerException&lt;/DIV&gt;&lt;DIV&gt;at java.lang.String.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:133)&lt;/DIV&gt;&lt;DIV&gt;... 4 more&lt;/DIV&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:59:16 GMT</pubDate>
    <dc:creator>smp</dc:creator>
    <dc:date>2019-03-11T05:59:16Z</dc:date>
    <item>
      <title>Error starting Internal CA on ISE 1.3 Patch 4</title>
      <link>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726560#M54365</link>
      <description>&lt;P&gt;It seems our Internal CA is unable to start because of a missing keystore password file. We tried disabling/enabling the Internal CA which did not help. We'd like to regenerate the Internal CA certificate, but we are getting a&amp;nbsp;"No message defined" error, presumably because the CA service is not running properly. Anyone know of a way to force ISE to generate the missing file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;[2015-05-26 16:13:11,582] [] [WARN]&lt;/DIV&gt;&lt;DIV&gt;could not read from /opt/CSCOcpm/appsrv/apache-tomcat-ca/conf/ca_nssdb_password.txt&lt;/DIV&gt;&lt;DIV&gt;java.io.FileNotFoundException: /opt/CSCOcpm/appsrv/apache-tomcat-ca/conf/ca_nssdb_password.txt (No such file or directory)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.open(Native Method)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at java.io.RandomAccessFile.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.DataUtil.loadFile(DataUtil.java:83)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:133)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.init(CaStore.java:113)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;init&amp;gt;(CaStore.java:67)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;clinit&amp;gt;(CaStore.java:60)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.bootstrap.CaServerSeeding.main(CaServerSeeding.java:43)&lt;/DIV&gt;&lt;DIV&gt;[2015-05-26 16:13:11,598] [] [WARN]&lt;/DIV&gt;&lt;DIV&gt;could not initialize KeyStore&lt;/DIV&gt;&lt;DIV&gt;com.cisco.cpm.caservice.CARuntimeException: java.lang.NullPointerException&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:155)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.init(CaStore.java:113)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;init&amp;gt;(CaStore.java:67)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.&amp;lt;clinit&amp;gt;(CaStore.java:60)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.bootstrap.CaServerSeeding.main(CaServerSeeding.java:43)&lt;/DIV&gt;&lt;DIV&gt;Caused by: java.lang.NullPointerException&lt;/DIV&gt;&lt;DIV&gt;at java.lang.String.&amp;lt;init&amp;gt;(Unknown Source)&lt;/DIV&gt;&lt;DIV&gt;at com.cisco.cpm.caservice.CaStore.load(CaStore.java:133)&lt;/DIV&gt;&lt;DIV&gt;... 4 more&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726560#M54365</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2019-03-11T05:59:16Z</dc:date>
    </item>
    <item>
      <title>Hi Scott, I see a similar</title>
      <link>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726561#M54366</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see a similar issue being reported after an internal search and a DDTS was opened:&lt;/P&gt;&lt;P&gt;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;&lt;A href="https://cdetsng.cisco.com/webui/#view=CSCus54289"&gt;CSCus54289&lt;/A&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;A href="http://wwwin.cisco.com/ops/infra/pds/cbms/cdets/legend.shtml" target="_blank" title="Help"&gt;&lt;FONT size="1"&gt;&lt;IMG border="0" height="15" src="http://cdetsweb-prd.cisco.com/apps/files/xslt/help.png" width="15" /&gt;&lt;/FONT&gt;&lt;/A&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;OCSP Services not running and Internal CA certs missing post 1.3 upgrade&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;Workaround- Reimage the device with 1.3 and that resolved the issue.&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;Regards,&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;Kanwal&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT style="font-size: large;"&gt;&lt;B&gt;Note: Please mark answers if they are helpful.&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:12:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726561#M54366</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-08-18T19:12:29Z</dc:date>
    </item>
    <item>
      <title>Thank you for the response</title>
      <link>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726562#M54367</link>
      <description>&lt;P&gt;Thank you for the response Kanwal, but I sure want to avoid reimaging the device. Our deployment is pretty large, and would cause quite a disruption in service. I'm pursuing a couple of different avenues ATM, but that bug number will be a helpful reference. I will post something back if I find a successful alternative.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 13:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726562#M54367</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2015-08-19T13:14:27Z</dc:date>
    </item>
    <item>
      <title>We were able to fix this</title>
      <link>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726563#M54368</link>
      <description>&lt;P&gt;We were able to fix this after some conversation between our Solution Architect and a BU engineer, without re-imaging the device. At a high level:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Install root patch&lt;/LI&gt;&lt;LI&gt;Remove three security db files&lt;/LI&gt;&lt;LI&gt;restart the internal CA service (which generates the missing password file)&lt;/LI&gt;&lt;LI&gt;restart the Tomcat service&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 19 Aug 2015 18:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-starting-internal-ca-on-ise-1-3-patch-4/m-p/2726563#M54368</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2015-08-19T18:28:15Z</dc:date>
    </item>
  </channel>
</rss>

