<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170754#M563441</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks I already tried that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR was created on an ISE node.&lt;/P&gt;
&lt;P&gt;I was creating two CSRs for the EAP roles on the two PSNs. And the idea was to have the EAP cert signed by the ISE Internal CA, so that I can hand out the ISE Internal Root CA cert to clients. No matter which PSN is used, the client will trust both. This customer has no PKI, therefore it seemed that the ISE CA was ideal.&lt;/P&gt;
&lt;P&gt;The first CSR was accepted by the pxGrid certificate generator and it produced a cert that I was able to bind to ISE01. But it's ISE02 that I am having issues with. I created another CSR just for ISE02 but each time I get this .zip error, and the cert is created (but I cannot access it) - all the fields look correct when I view the cert details.&lt;/P&gt;
&lt;P&gt;The weird thing is that the cert is always generated correctly and I can see it in the issued Certificates list. It seems like a bug in the packaging of the .zip file.&amp;nbsp; I have never seen such an error and I have created a lot of certs on the internal ISE CA.&lt;/P&gt;
&lt;P&gt;I have also stopped and rebooted both nodes - made no difference - still same .zip error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 06:43:56 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2020-10-21T06:43:56Z</dc:date>
    <item>
      <title>ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170196#M563424</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a two node ISE 2.7 patch 2 system I saw a strange error while generating a cert in the pxGrid Services screen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pxGrid cert zip issie.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86499i80327F37EA88C2B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="pxGrid cert zip issie.PNG" alt="pxGrid cert zip issie.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The certificate was in fact generated! - but due to the error message I was unable to download the cert. I don't know any other way to get access to that cert (I can see the cert under the Internal CA Issued Certs)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Short of restarting the ISE node, I don't know what else to try? Anyone seen this before?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 11:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170196#M563424</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-10-20T11:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170672#M563427</link>
      <description>&lt;P&gt;Hello Arne,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If certificate for PxGrid client was generated with CSR in PKCS8 format. If SAN field is configured either in CSR or while generating certificate. If not then try by adding SAN field and check if that resolves the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 04:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170672#M563427</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-10-21T04:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170751#M563439</link>
      <description>&lt;P&gt;hi Arne&lt;/P&gt;&lt;P&gt;hopefully u have already resolved this issue, but isnt there "Export certicficate" element in "Internal CA issued"?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 06:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170751#M563439</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2020-10-21T06:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170754#M563441</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks I already tried that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CSR was created on an ISE node.&lt;/P&gt;
&lt;P&gt;I was creating two CSRs for the EAP roles on the two PSNs. And the idea was to have the EAP cert signed by the ISE Internal CA, so that I can hand out the ISE Internal Root CA cert to clients. No matter which PSN is used, the client will trust both. This customer has no PKI, therefore it seemed that the ISE CA was ideal.&lt;/P&gt;
&lt;P&gt;The first CSR was accepted by the pxGrid certificate generator and it produced a cert that I was able to bind to ISE01. But it's ISE02 that I am having issues with. I created another CSR just for ISE02 but each time I get this .zip error, and the cert is created (but I cannot access it) - all the fields look correct when I view the cert details.&lt;/P&gt;
&lt;P&gt;The weird thing is that the cert is always generated correctly and I can see it in the issued Certificates list. It seems like a bug in the packaging of the .zip file.&amp;nbsp; I have never seen such an error and I have created a lot of certs on the internal ISE CA.&lt;/P&gt;
&lt;P&gt;I have also stopped and rebooted both nodes - made no difference - still same .zip error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 06:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170754#M563441</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-10-21T06:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170763#M563443</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp; - sadly not - I can view or revoke the cert. When I view, there are no further options. Not even a BASE64 format that&amp;nbsp; I could copy and paste.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="issued.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86574i6115607003FFE61C/image-size/large?v=v2&amp;amp;px=999" role="button" title="issued.png" alt="issued.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 06:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4170763#M563443</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-10-21T06:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4172131#M563479</link>
      <description>&lt;P&gt;Check if the 3-level certificate hierarchy can be traced to a single root CA on both nodes.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 21:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4172131#M563479</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2020-10-22T21:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZIP file</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4174711#M563543</link>
      <description>&lt;P&gt;wow I hadn't thought of that - I will check - but ISE should not allow more than one Root CA to be in place.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 00:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4174711#M563543</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-10-28T00:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4447830#M568985</link>
      <description>&lt;P&gt;i have the issue , certificate chain was created correctly but the " zip " process keeps fail , and i am not unable to download it .&lt;/P&gt;&lt;P&gt;is there a way to do that with cli?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 14:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4447830#M568985</guid>
      <dc:creator>eugeniodesideri</dc:creator>
      <dc:date>2021-08-11T14:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4448104#M568997</link>
      <description>&lt;P&gt;Certificates cannot be managed via the CLI. If you're having issues generating certificates from the internal CA for supported BYOD/pxGrid use cases, you might try another browser and regenerating the CA Root Chain from the &lt;STRONG&gt;Generate CSR&lt;/STRONG&gt; menu.&lt;/P&gt;
&lt;P&gt;If you're still having issues, I would suggest opening a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 23:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4448104#M568997</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-08-11T23:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Internal Cert Generation Failed - Something went wrong with ZI</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4449397#M569040</link>
      <description>&lt;P&gt;If the ISE admin server certificate is issued by ISE internal CA, then this is a known issue -- CSCvi85028&lt;/P&gt;
&lt;P&gt;Or, it could be due to CSCvp30790&lt;/P&gt;</description>
      <pubDate>Sat, 14 Aug 2021 04:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-internal-cert-generation-failed-something-went-wrong-with/m-p/4449397#M569040</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-08-14T04:44:53Z</dc:date>
    </item>
  </channel>
</rss>

