<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trusted Certificates | Default self-signed server certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320052#M566641</link>
    <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;&lt;BR /&gt;How do we renew our ISE Trusted Default Self-Signed Cert?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-04-07 at 17.59.00.png" style="width: 797px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108331i4DE0DFB0C5A63739/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-04-07 at 17.59.00.png" alt="Screenshot 2021-04-07 at 17.59.00.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Apr 2021 17:00:32 GMT</pubDate>
    <dc:creator>Xividar</dc:creator>
    <dc:date>2021-04-07T17:00:32Z</dc:date>
    <item>
      <title>Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320052#M566641</link>
      <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;&lt;BR /&gt;How do we renew our ISE Trusted Default Self-Signed Cert?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-04-07 at 17.59.00.png" style="width: 797px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108331i4DE0DFB0C5A63739/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-04-07 at 17.59.00.png" alt="Screenshot 2021-04-07 at 17.59.00.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 17:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320052#M566641</guid>
      <dc:creator>Xividar</dc:creator>
      <dc:date>2021-04-07T17:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320067#M566645</link>
      <description>&lt;P&gt;To re-gen self signed certs go to: Administration-&amp;gt;System-&amp;gt;Certificates-&amp;gt;Certificate Management-&amp;gt;System Certificates-&amp;gt;'Generate Self Signed Certificate'&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 17:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320067#M566645</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-07T17:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320072#M566646</link>
      <description>&lt;P&gt;Hi Mike,&lt;BR /&gt;&lt;BR /&gt;Are you saying that once the default self-signed ISE Root Cert expires, we need to move services off of it? Is there no way to renew it?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 17:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320072#M566646</guid>
      <dc:creator>Xividar</dc:creator>
      <dc:date>2021-04-07T17:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320241#M566650</link>
      <description>&lt;P&gt;The 'Default self-signed server certificate' in the Trusted Certificates store is simply a copy of the same cert in the System Certificates store. Depending on the version of ISE you are using, you should be able to edit the cert in the System Certificates store and use the Renew Self Signed Certificate option at the bottom to extend the expiration date. The changes should also be reflected in the Trusted Certificates store.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screen Shot 2021-04-08 at 9.22.33 am.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108372iBC1E82E059FAE38B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-08 at 9.22.33 am.png" alt="Screen Shot 2021-04-08 at 9.22.33 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 23:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4320241#M566650</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-04-07T23:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4402829#M567290</link>
      <description>&lt;P&gt;You should NEVER renew a self-signed certificate.&lt;/P&gt;
&lt;P&gt;Use a public-CA signed certificate or enterprise CA.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 20:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4402829#M567290</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-05-13T20:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4584206#M573828</link>
      <description>&lt;P&gt;Dear Greg,&lt;/P&gt;&lt;P&gt;Other than extending the renewal period, what else needs to be done if we are using the self signed cert for PEAP (EAP with MSCHAPv2) authentication?&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 05:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4584206#M573828</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-04-03T05:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4584640#M573838</link>
      <description>&lt;P&gt;The self-signed certificates should only be bound to services that are not actually in use in your environment (pxGrid, RADIUS DTLS, SAML, etc). I would only use the renew self signed certificate option for those certificates. The other option would be to generate new self-signed certs for these unused services upon expiry of the old ones.&lt;/P&gt;&lt;P&gt;Self-signed certificates should never be used for services like EAP. This is NOT recommended and would require re-enrollment of all EAP clients upon any change to the self-signed certificates.&lt;/P&gt;&lt;P&gt;Ideally, an Enterprise CA should sign the ISE and client EAP certificates. Failing that (or for clients that are not managed by your organisation), Public CA signed certificates should be used.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 22:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4584640#M573838</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-04-03T22:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4595888#M574257</link>
      <description>&lt;P&gt;Hi Greg,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Just a question regarding this renewal of the default self-signed certificate. I have 2 ISE in HA and I successfully do the renewal/extension of the default self signed certificate of the primary ISE, however when I do the renewal/extension on the secondary node after I save it and the services restarts the default self signed certificate of the secondary ISE was not renewed. Do I need to switchover the role first for the renewal of the secondary node certificate to take effect? I can't see any documentation regarding this so I appreciate any inputs. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 05:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/4595888#M574257</guid>
      <dc:creator>ryreyes</dc:creator>
      <dc:date>2022-04-20T05:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/5124135#M589824</link>
      <description>&lt;P&gt;I have this problem to. But I can't renew it on ISE 3.2&lt;/P&gt;&lt;P&gt;What is the solution?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 05:27:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/5124135#M589824</guid>
      <dc:creator>Pietro Inderst</dc:creator>
      <dc:date>2024-06-04T05:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Certificates | Default self-signed server certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/5248288#M594266</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt; Can I use this option to renew our certificate on both boxes? Obviously one at a time due the restart of ISE application&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-01-16 132747.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237743i7404080249AFF831/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-01-16 132747.jpg" alt="Screenshot 2025-01-16 132747.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Our environment below with ISE 2.7&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="deployment.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237745i3B7C190A83ED9DC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="deployment.jpg" alt="deployment.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 19:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trusted-certificates-default-self-signed-server-certificate/m-p/5248288#M594266</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2025-01-16T19:34:34Z</dc:date>
    </item>
  </channel>
</rss>

