<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE nodes with expired admin certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644683#M575935</link>
    <description>&lt;P&gt;I have an ISE environment that we use for Tacacs, we are running version 2.6.&amp;nbsp; &amp;nbsp;The issue that I have is that for whatever reason, someone renewed the production TLS certificate on the primary admin node but didn't update the other nodes.&amp;nbsp; &amp;nbsp;So now when I go into the certificate store area and try to select any of the other two nodes [with expired 3rd party certificate] I get the error you see attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone show me the article that would show someone how to renew certificates on a node that is giving this error?&amp;nbsp; Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 00:34:26 GMT</pubDate>
    <dc:creator>rfountain72</dc:creator>
    <dc:date>2022-07-06T00:34:26Z</dc:date>
    <item>
      <title>ISE nodes with expired admin certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644683#M575935</link>
      <description>&lt;P&gt;I have an ISE environment that we use for Tacacs, we are running version 2.6.&amp;nbsp; &amp;nbsp;The issue that I have is that for whatever reason, someone renewed the production TLS certificate on the primary admin node but didn't update the other nodes.&amp;nbsp; &amp;nbsp;So now when I go into the certificate store area and try to select any of the other two nodes [with expired 3rd party certificate] I get the error you see attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone show me the article that would show someone how to renew certificates on a node that is giving this error?&amp;nbsp; Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644683#M575935</guid>
      <dc:creator>rfountain72</dc:creator>
      <dc:date>2022-07-06T00:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE nodes with expired admin certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644687#M575937</link>
      <description>&lt;P&gt;You should be able to HTTPS directly to the other nodes.&amp;nbsp; On the admin GUI, you can perform certificate operations on the individual nodes.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2503911.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2503911.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644687#M575937</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-06T00:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE nodes with expired admin certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644694#M575938</link>
      <description>&lt;P&gt;Thank you, I'm a bit closer as I'm logged into that node directly but the only choice I have is to "export" certificates.&amp;nbsp; I don't see where I can import the certificate that I exported from the primary PAN.&amp;nbsp; &amp;nbsp;I logged onto the other node as well and same thing, just "export".&amp;nbsp; &amp;nbsp; &amp;nbsp;Does this need to be done via CLI?&amp;nbsp; &amp;nbsp;I'm logging in with the local admin account to make sure I have all rights.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 01:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644694#M575938</guid>
      <dc:creator>rfountain72</dc:creator>
      <dc:date>2022-07-06T01:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE nodes with expired admin certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644698#M575940</link>
      <description>&lt;P&gt;Yeah I misunderstood the original question, for the secondary nodes I’ve always just rebuilt from scratch when I run into this at customer sites. See this thread:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-expired-certificate-on-de-auth-node/td-p/4442884" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-expired-certificate-on-de-auth-node/td-p/4442884&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 01:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4644698#M575940</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-06T01:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE nodes with expired admin certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4645438#M575992</link>
      <description>&lt;P&gt;Or if it's possible to de-register the nodes ? Once they are in Standalone you can manage them directly. But if the de-registration doesn't work then a rebuild is needed&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 21:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-nodes-with-expired-admin-certificate/m-p/4645438#M575992</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-06T21:10:18Z</dc:date>
    </item>
  </channel>
</rss>

