<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.4 EAP certificate renewal issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4101605#M561142</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a four node ISE cluster that one of the EAP certificates has expired.&amp;nbsp; A new certificate has ben issued with the same subject as the exiting one.&amp;nbsp; I am prompted that I can only have two certificates with the same subject when I am replacing one with the same role (I am).&amp;nbsp; I get an Okay prompt but it won't let me continue and I can't remove the expired certificate because it reports "The EAP certificate cannot be deleted".&lt;/P&gt;&lt;P&gt;I did try to replace this before it expired but was running into the same issues.&lt;/P&gt;&lt;P&gt;How do I de-link this certificate for me to be able to replace it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a 2.6 cluster that is currently being configured but would like to get this one ack up a running to give me more breathing space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gavin&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2020 14:50:52 GMT</pubDate>
    <dc:creator>GLiquorish</dc:creator>
    <dc:date>2020-06-11T14:50:52Z</dc:date>
    <item>
      <title>ISE 1.4 EAP certificate renewal issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4101605#M561142</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a four node ISE cluster that one of the EAP certificates has expired.&amp;nbsp; A new certificate has ben issued with the same subject as the exiting one.&amp;nbsp; I am prompted that I can only have two certificates with the same subject when I am replacing one with the same role (I am).&amp;nbsp; I get an Okay prompt but it won't let me continue and I can't remove the expired certificate because it reports "The EAP certificate cannot be deleted".&lt;/P&gt;&lt;P&gt;I did try to replace this before it expired but was running into the same issues.&lt;/P&gt;&lt;P&gt;How do I de-link this certificate for me to be able to replace it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a 2.6 cluster that is currently being configured but would like to get this one ack up a running to give me more breathing space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gavin&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 14:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4101605#M561142</guid>
      <dc:creator>GLiquorish</dc:creator>
      <dc:date>2020-06-11T14:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 EAP certificate renewal issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4101646#M561146</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/616304"&gt;@GLiquorish&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You have two choices here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You click on 'Edit' on another certificate on that node and choose EAP service. That way you can move the EAP service from the current certificate and then delete the expired EAP certificate. Next, add your new certificate and select EAP again. You should now have EAP on the new and shiny certificate.&lt;/LI&gt;
&lt;LI&gt;You create a new CSR, just like the expired EAP certificate, except for a minor change like OU, City, etc. Then you get it signed and bind it the with the CSR. It shouldn't give any warnings.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 11 Jun 2020 15:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4101646#M561146</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-11T15:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.4 EAP certificate renewal issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4104922#M561275</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have managed to delete the old certificate but binding the new certificate to the CSR generates an "&lt;FONT face="courier new,courier" size="3"&gt;Internal error. Ask your system administrator to check the logs for more details&lt;/FONT&gt;" message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The debug logs are showing the following two messages:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;2020-06-17 14:01:26,573 ERROR [admin-http-pool132][] infrastructure.certmgmt.service.impl.LocalCertificateServiceImpl -:::::- Unexpected exception: com.cisco.cpm.infrastructure.certmgmt.api.CertMgmtException: Error occurred while deleting certificate from NSS DB: java.security.KeyStoreException: This PKCS11KeyStore does not support write capabilities&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;com.cisco.cpm.infrastructure.certmgmt.api.CertMgmtException: Error occurred while deleting certificate from NSS DB: java.security.KeyStoreException: This PKCS11KeyStore does not support write capabilities&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it worth rebooting this server and if so, what is the cleanest way to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gavin&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 14:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-4-eap-certificate-renewal-issue/m-p/4104922#M561275</guid>
      <dc:creator>GLiquorish</dc:creator>
      <dc:date>2020-06-17T14:16:09Z</dc:date>
    </item>
  </channel>
</rss>

