<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to renew a self signed certificate used for PEAP authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584205#M573827</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are using a self signed certificate for admin, &lt;SPAN&gt;PEAP (EAP-MSCHAPv2)&lt;/SPAN&gt; authentication.&lt;/P&gt;&lt;P&gt;I know its not recommended, will have to plan and start using a CA signed cert.&lt;/P&gt;&lt;P&gt;But for now, need to renew it as it will expire soon.&lt;/P&gt;&lt;P&gt;I know how to extend the time on it in system certificates, will it fix the issue? what about certificate in end user machines?&lt;/P&gt;&lt;P&gt;Please help as I am new to ISE.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
    <pubDate>Sat, 02 Apr 2022 11:37:03 GMT</pubDate>
    <dc:creator>engineer467</dc:creator>
    <dc:date>2022-04-02T11:37:03Z</dc:date>
    <item>
      <title>How to renew a self signed certificate used for PEAP authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584205#M573827</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are using a self signed certificate for admin, &lt;SPAN&gt;PEAP (EAP-MSCHAPv2)&lt;/SPAN&gt; authentication.&lt;/P&gt;&lt;P&gt;I know its not recommended, will have to plan and start using a CA signed cert.&lt;/P&gt;&lt;P&gt;But for now, need to renew it as it will expire soon.&lt;/P&gt;&lt;P&gt;I know how to extend the time on it in system certificates, will it fix the issue? what about certificate in end user machines?&lt;/P&gt;&lt;P&gt;Please help as I am new to ISE.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 11:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584205#M573827</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-04-02T11:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew a self signed certificate used for PEAP authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584562#M573830</link>
      <description>&lt;P&gt;Renew certificates follows the same process. You need to create a new CSR, send it to who can sign it for you and re-install the signed certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp; You need to send this to your clients devices via some kind of MDM or via GPO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, I am confuse about some information you said. You first refers to admin certificate and then you ask for clients certificates. You mentioned PEAP which is Protectec EAP but it is not TLS or DTLS. Make sure you have all the information in order to proceed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 14:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584562#M573830</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-04-03T14:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew a self signed certificate used for PEAP authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584630#M573835</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/157474"&gt;@engineer467&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You say "self-signed" certificate. By that I assume you mean that you are using the ISE EAP System certificate that was created in ISE when it was installed. To renew those is very easy.&lt;/P&gt;
&lt;P&gt;Click on the Self-Signed Certificate and select Edit&lt;/P&gt;
&lt;P&gt;Scroll down to the bottom of the screen and tick the box "Renewal Period" and then enter a value in days. Click Save. Done.&lt;/P&gt;
&lt;P&gt;It will renew the ISE Self-Signed cert and update the Valid From and Valid To dates. The serial number should not change, but the fingerprint should be updated.&lt;/P&gt;
&lt;P&gt;As for your end clients, they will see a new ISE EAP certificate and they will have to trust it all over again - either by manually accepting the new cert, or by you pushing that new ISE cert as a "Trusted Root" to all clients (via Group Policy or MDM etc.)&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 20:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584630#M573835</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-03T20:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew a self signed certificate used for PEAP authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584695#M573839</link>
      <description>&lt;P&gt;Hello Arne,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;I will follow the steps and update here asap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 03:13:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4584695#M573839</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-04-04T03:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to renew a self signed certificate used for PEAP authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4587850#M573937</link>
      <description>&lt;P&gt;Hello Arne,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All worked smoothly after following your steps.&lt;/P&gt;&lt;P&gt;Thanks a lot again.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-renew-a-self-signed-certificate-used-for-peap/m-p/4587850#M573937</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-04-07T06:52:59Z</dc:date>
    </item>
  </channel>
</rss>

