<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO ISE 2.4 	Alarm about expiration certificate (SAML) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4145070#M562639</link>
    <description>&lt;P&gt;Good notes here - thanks for posting.&amp;nbsp; Potential issue avoided!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 11:59:46 GMT</pubDate>
    <dc:creator>r1127hyduk</dc:creator>
    <dc:date>2020-09-02T11:59:46Z</dc:date>
    <item>
      <title>CISCO ISE 2.4 	Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4016992#M541022</link>
      <description>&lt;P&gt;Hey Dear ;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust certificate 'Default self-signed server certificate' will expire soon&lt;/P&gt;&lt;P&gt;we would like to know what&amp;nbsp; does mean usage for SAML,&amp;nbsp; and to know if this certificate is really used in my case and how to renew it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alarm Name :&lt;/P&gt;&lt;P&gt;Certificate Expiration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details :&lt;/P&gt;&lt;P&gt;&amp;nbsp;Trust certificate 'Default self-signed server certificate' will expire in 60 days : Server=SRP-01-CISE010&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description :&lt;/P&gt;&lt;P&gt;This certificate will expire soon.&amp;nbsp; When it expires, ISE may fail when attempting to establish secure communications with clients.&amp;nbsp; Inter-node communication may also be affected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Severity :&lt;/P&gt;&lt;P&gt;Warning&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suggested Actions :&lt;/P&gt;&lt;P&gt;Replace the certificate.&amp;nbsp; For a trust certificate, contact the issuing Certificate Authority (CA).&amp;nbsp; For a CA-signed local certificate, generate a CSR and have the CA create a new certificate.&amp;nbsp; For a self-signed local certificate, use ISE to extend the expiration date. You can just delete the certificate if it is no longer used&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 12:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4016992#M541022</guid>
      <dc:creator>Nadia Bbz</dc:creator>
      <dc:date>2020-01-23T12:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE 2.4 	Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4017391#M541058</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/974132"&gt;@Nadia Bbz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I implement my own best practice for these situations: any cert that is not required on my customers' nodes is given a 10 year self-signed cert, to ensure that they don't get any expiration notices for certs they don't need. 10 years is the max - but by then I would assume the system would have been rebuilt anyway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under System Certs, generate a new self-signed cert to replace the current cert. Let's say you want to replace the SAML cert.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="self-signed.PNG" style="width: 884px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/65791i55845F9E6F728AA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="self-signed.PNG" alt="self-signed.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 21:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4017391#M541058</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-01-23T21:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE 2.4 	Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4018402#M541073</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;Thanks so much for helping me , &lt;SPAN&gt;I greatly appreciate it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it's possible to renew certificate just to check the box renewal period and put 10 years or 5 years like the picture below&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="self signed.JPG" style="width: 849px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/65911iA68C0728A9BE7C55/image-size/large?v=v2&amp;amp;px=999" role="button" title="self signed.JPG" alt="self signed.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i have another certificate that will expired soon, should i apply the same method to solve it&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="self signed certificate.JPG" style="width: 749px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/65912iE8A22509645017A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="self signed certificate.JPG" alt="self signed certificate.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks for help &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2020 09:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4018402#M541073</guid>
      <dc:creator>Nadia Bbz</dc:creator>
      <dc:date>2020-01-26T09:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE 2.4 	Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4019090#M541095</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/974132"&gt;@Nadia Bbz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I learned something new! Thank you. I have never used that renew self cert button button. It does exactly what it says. For self-signed certs it seems you can either create a new one and delete the old one, or simply use the renew feature.&lt;/P&gt;
&lt;P&gt;Here's the difference between creating a new cert, and renewing a cert:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create New Cert: creates a new Cert Serial Number - calculate new cert Fingerprint (hash)&lt;/LI&gt;
&lt;LI&gt;Renew Cert: Maintain same Serial Number and update the Validity period - calculate new cert Fingerprint (hash)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Arne&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 21:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4019090#M541095</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-01-27T21:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE 2.4 	Alarm about expiration certificate (SAML)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4145070#M562639</link>
      <description>&lt;P&gt;Good notes here - thanks for posting.&amp;nbsp; Potential issue avoided!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 11:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-alarm-about-expiration-certificate-saml/m-p/4145070#M562639</guid>
      <dc:creator>r1127hyduk</dc:creator>
      <dc:date>2020-09-02T11:59:46Z</dc:date>
    </item>
  </channel>
</rss>

