<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - CA Certificates about to expire in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557635#M572921</link>
    <description>&lt;P&gt;You may want to register for the upcoming &lt;STRONG&gt;ISE Digital Certificate Administration&lt;/STRONG&gt; webinar :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://cs.co/ise-webinars" target="_blank"&gt;https://cs.co/ise-webinars&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20220301 Next Month Promo - ISE Digital Certificate Administration.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/144513i2DC5EE4E8AD39C79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20220301 Next Month Promo - ISE Digital Certificate Administration.png" alt="20220301 Next Month Promo - ISE Digital Certificate Administration.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2022 22:24:22 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-02-22T22:24:22Z</dc:date>
    <item>
      <title>ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557313#M572915</link>
      <description>&lt;P&gt;Hi all, I've inherited a working installation of ISE and I'm still wrapping my head around it.&lt;BR /&gt;I ran into this screen (screenshot attached) which seems quite alarming as it&amp;nbsp;says that CA Certificates will expire in less than 2 weeks. The related CAs are disabled; however self-signed System Certificates (SAML, Admin and EAP Authentication -- guest portal is a bought certificate) are expiring in some years. How do I check if they've been signed with the affected CAs?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Am I safe to suppose that users will still be able to connect in two weeks time? Can I renew these certificates? What are my options?&lt;BR /&gt;&lt;BR /&gt;thank you&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 13:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557313#M572915</guid>
      <dc:creator>rg235</dc:creator>
      <dc:date>2022-02-22T13:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557327#M572918</link>
      <description>&lt;P&gt;however self-signed System Certificates (SAML, Admin and EAP Authentication -- guest portal is a bought certificate) are expiring in some years. How do I check if they've been signed with the affected CAs?&lt;/P&gt;
&lt;P&gt;-Navigate to Administration-&amp;gt;System-&amp;gt;Certificates-&amp;gt;Certificate Management-&amp;gt;System Certificates; here you can see what certs are in use and what their respective CA chains are.&lt;BR /&gt;Am I safe to suppose that users will still be able to connect in two weeks time?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-More than likely yes, but double check the system certs in use and make sure the EAP Authentication system cert is not expiring.&lt;/P&gt;
&lt;P&gt;Can I renew these certificates? What are my options?&lt;/P&gt;
&lt;P&gt;-This will help:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank"&gt;How To Implement Digital Certificates in ISE - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 14:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557327#M572918</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-02-22T14:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557635#M572921</link>
      <description>&lt;P&gt;You may want to register for the upcoming &lt;STRONG&gt;ISE Digital Certificate Administration&lt;/STRONG&gt; webinar :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://cs.co/ise-webinars" target="_blank"&gt;https://cs.co/ise-webinars&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20220301 Next Month Promo - ISE Digital Certificate Administration.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/144513i2DC5EE4E8AD39C79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20220301 Next Month Promo - ISE Digital Certificate Administration.png" alt="20220301 Next Month Promo - ISE Digital Certificate Administration.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 22:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557635#M572921</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-02-22T22:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557739#M572923</link>
      <description>&lt;P&gt;I think that should be a well-attended seminar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are the chances that the ISE Web Portal Certs could be enabled to use Letsencrypt ?&amp;nbsp; It would be very handy feature at least for Guest Portals or perhaps even the ISE Admin cert.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 05:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557739#M572923</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-02-23T05:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557999#M572929</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I think it's possible with the manual procedure:&amp;nbsp;&lt;A href="https://eff-certbot.readthedocs.io/en/stable/using.html#manual" target="_blank"&gt;https://eff-certbot.readthedocs.io/en/stable/using.html#manual&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general, I'm not sure if it's a good idea implementing third-part plugins in the Hardening OS's like ISE. But it's only my personal point of view...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 15:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4557999#M572929</guid>
      <dc:creator>tjezer</dc:creator>
      <dc:date>2022-02-23T15:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558338#M572930</link>
      <description>&lt;P&gt;Great documentation. Thank you so much for sharing!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-R&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 20:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558338#M572930</guid>
      <dc:creator>RezSalahuddin68319</dc:creator>
      <dc:date>2022-02-23T20:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558437#M572933</link>
      <description>&lt;P&gt;You may deploy certificates from any CA that you like.&lt;/P&gt;
&lt;P&gt;Hosuk demonstrated the worlds fastest multi-node ISE deployment using a wildcard certificate from LetsEncrypt in our December ISE Webinar.&amp;nbsp; 8-)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" data-source-line="323"&gt;&lt;STRONG&gt;&lt;A class="" title="https://youtu.be/tN_nTEE48Ys" href="https://youtu.be/tN_nTEE48Ys" data-from-md="" target="_blank"&gt;Automated ISE Setup with Infrastructure as Code Tools&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;A title="https://youtu.be/tN_nTEE48Ys&amp;amp;t=2228s" href="https://youtu.be/tN_nTEE48Ys&amp;amp;t=2228s" data-from-md="" target="_blank"&gt;37:08&lt;/A&gt;&lt;/STRONG&gt; Demo: Wildcard Certificate Request with Let's Encrypt&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Demo Code: &lt;A title="https://github.com/hosukw/Full_ISE_Terraform_Ansible_AWS" href="https://github.com/hosukw/Full_ISE_Terraform_Ansible_AWS" data-from-md="" target="_blank"&gt;https://github.com/hosukw/Full_ISE_Terraform_Ansible_AWS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I think what you really are asking for is ACME protocol support directly in ISE and that is not there yet.&lt;/P&gt;
&lt;P&gt;But the new ISE 3.1 &lt;A href="https://developer.cisco.com/docs/identity-services-engine/v1/#!certificate-openapi" target="_self"&gt;&lt;STRONG&gt;Certificate&lt;/STRONG&gt;&lt;/A&gt; APIs are the next best thing!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 00:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558437#M572933</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-02-24T00:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558447#M572934</link>
      <description>&lt;P&gt;oh boy how did I miss that webinar!!!?? It's amazing. Thanks. I will see if I can give that a try. We're not deploying any 3.1 yet or anywhere near AWS .. yet. But I am mostly interested in the certs techniques for now.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 00:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558447#M572934</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-02-24T00:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558627#M572937</link>
      <description>&lt;P&gt;Registered! Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 08:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558627#M572937</guid>
      <dc:creator>rg235</dc:creator>
      <dc:date>2022-02-24T08:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CA Certificates about to expire</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558630#M572938</link>
      <description>&lt;P&gt;Thank you Mike, that helped a lot! System certs are not expiring anytime soon.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 08:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ca-certificates-about-to-expire/m-p/4558630#M572938</guid>
      <dc:creator>rg235</dc:creator>
      <dc:date>2022-02-24T08:07:30Z</dc:date>
    </item>
  </channel>
</rss>

