<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate replication through nodes. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311656#M546644</link>
    <description>&lt;P&gt;Hi, If you've replaced the PAN's admin certificate it should not reboot again. In a distributed cluster you have to upload the certificate for all other nodes from the webgui of the PAN anyway, you just need to ensure you only select the correct PSN to replace the admin certificate, then only that PSN's services will restart not any other PSN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sense?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jan 2018 19:04:22 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2018-01-15T19:04:22Z</dc:date>
    <item>
      <title>Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311628#M546641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a customer who is planning to upload a new certificate (the current one is about expiring). I was able to import it successfully on the PAN without get the services restarted. I've seen if we enable the services the cert is used by (EAP, Admin, Portal) on the primary PAN, this will get restarted and the subsecuences nodes will be restarting too, my question is: ¿If I enable the services on one PSN at time instead of PAN, will the subsequences PSNs will be restarted too?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311628#M546641</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2020-02-21T18:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311643#M546642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only replacing the Admin certificate would result in the services being restarted on the node the certificate is being replaced on. Any other cert (EAP, Portal, pxgrid) would not result in the services being restarted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 18:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311643#M546642</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-01-15T18:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311650#M546643</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you for the quick response,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a lab deployment (1 PAN and 2 PSN) where I replaced the certificate on PAN and enabled the services (EAP,Admin, Portal). I see the&amp;nbsp; PAN get restarted and after some minutes both PSN too. Customer has about 10 Nodes and they don't want to get all the nodes restarted, that's why im wondering if I only upload the new cert on PAN, it won't activate a service restart of the nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 18:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311650#M546643</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2018-01-15T18:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311656#M546644</link>
      <description>&lt;P&gt;Hi, If you've replaced the PAN's admin certificate it should not reboot again. In a distributed cluster you have to upload the certificate for all other nodes from the webgui of the PAN anyway, you just need to ensure you only select the correct PSN to replace the admin certificate, then only that PSN's services will restart not any other PSN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sense?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 19:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311656#M546644</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-01-15T19:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311662#M546645</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;that makes sense 100%, how can I&amp;nbsp;&lt;SPAN&gt;select the correct PSN to replace the admin certificate? Is it under Administration-&amp;gt;Deployment Tab?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 19:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311662#M546645</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2018-01-15T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311666#M546646</link>
      <description>&lt;P&gt;Assuming the PSN nodes are registered to the cluster, to import any certificate for a node in a cluster you'd go to:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Administration &amp;gt; System &amp;gt; Certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From there you can generate CSR's, select which type of certificate and which node the CSR is being generated for and then once the certificate is signed you can bind the signed certificates.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 19:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311666#M546646</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-01-15T19:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate replication through nodes.</title>
      <link>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311688#M546647</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will try this option in Lab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 20:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/certificate-replication-through-nodes/m-p/3311688#M546647</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2018-01-15T20:09:38Z</dc:date>
    </item>
  </channel>
</rss>

