<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Portal tag is already assigned to the following certificate(s) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4549815#M572721</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ISE version 3.0 Patch 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal certificate is expiring in about 5 week time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to Generate a CSR to replace this certificate with a newer one. I have added in all the info except that the friendly name has 2022 in it and the old cert does not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I check Submit, I get the following warning:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; The Portal tag is already assigned to the following certificate(s). If you proceed, it will be removed from the existing&amp;nbsp; &amp;nbsp; certificates, and affected portals will be restarted. Do you want to proceed?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2022_Cert_Portal_ISE_01&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to click "Yes" in case I cause an outage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anthony.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 18:25:30 GMT</pubDate>
    <dc:creator>Anthony O'Reilly</dc:creator>
    <dc:date>2022-02-10T18:25:30Z</dc:date>
    <item>
      <title>The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4549815#M572721</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ISE version 3.0 Patch 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal certificate is expiring in about 5 week time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to Generate a CSR to replace this certificate with a newer one. I have added in all the info except that the friendly name has 2022 in it and the old cert does not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I check Submit, I get the following warning:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; The Portal tag is already assigned to the following certificate(s). If you proceed, it will be removed from the existing&amp;nbsp; &amp;nbsp; certificates, and affected portals will be restarted. Do you want to proceed?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2022_Cert_Portal_ISE_01&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to click "Yes" in case I cause an outage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anthony.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 18:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4549815#M572721</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-02-10T18:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4549940#M572730</link>
      <description>&lt;P&gt;The Portal Tag is not really part of the CSR or the certificate itself. It's just an internal mapping in ISE.&lt;/P&gt;
&lt;P&gt;You can create the CSR with a new dummy Portal Tag to get the signed cert from your CA. Once you have the signed certificate, you can either:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Specify the real Portal Tag when binding the certificate to the CSR, at which point the affected portals will be restarted&lt;/LI&gt;
&lt;LI&gt;Bind the certificate to the CSR using the dummy Portal Tag and edit the cert at a later date to move it to the real Portal Tag (at which point the affected portals will be restarted)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;You should note that the portal restart happens very quickly and may not even be noticeable to end users. It is not the same as the ISE services restarting.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 22:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4549940#M572730</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-02-10T22:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4550325#M572737</link>
      <description>&lt;P&gt;In case we click yes, would the existing portal remain with no certificate associated until the renewed one is bound?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 09:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4550325#M572737</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-02-11T09:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4550327#M572738</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your quick response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I take from this is:&lt;/P&gt;&lt;P&gt;1. Generate a CSR, fill out all the fields I require but do not ticket the Portal option&lt;/P&gt;&lt;P&gt;2. When cert is returned from the CA, import it to ISE&lt;/P&gt;&lt;P&gt;3. Edit the imported cert and tick the Portal option. The service will restart but it may not be service affecting as this is instantaneous.&lt;/P&gt;&lt;P&gt;4. Delete old cert a few days later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do this step for both ISE appliances. We only have two ISE appliances and both certs are expiring on the same day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 09:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4550327#M572738</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-02-11T09:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551413#M572754</link>
      <description>&lt;P&gt;It didn't make sense that ISE would pull the cert off since it only supports HTTPS, so I tested it in my lab. As I suspected, the CSR creation itself does not pull the cert from the portals or restart the portal. It only moves the cert and restarts the portals using the same Tag when the certificate is bound to the CSR.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Feb 2022 22:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551413#M572754</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-02-13T22:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551422#M572757</link>
      <description>&lt;P&gt;That's why I was wondering! Thanks for spending the time to lab this up and confirm.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Feb 2022 23:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551422#M572757</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-02-13T23:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551777#M572767</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I right in my thinking here?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 09:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4551777#M572767</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-02-14T09:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: The Portal tag is already assigned to the following certificate(s)</title>
      <link>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4552188#M572780</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Creating a CSR requires the selection of a Usage. If you select the 'Multi-Use' Usage for the CSR, the procedure you describe will work. You would select the Portal usage and Tag at the time binding the signed cert to the CSR.&lt;/P&gt;
&lt;P&gt;Alternatively, you could select Portal Usage and correct Portal Tag at the time of creating the CSR and ignore the warning (as it only applies at the time of binding the cert to the CSR, as I described in the previous post).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 21:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/the-portal-tag-is-already-assigned-to-the-following-certificate/m-p/4552188#M572780</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-02-14T21:07:13Z</dc:date>
    </item>
  </channel>
</rss>

