<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove endpoint certificate from ISE internal CA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4714814#M578028</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;If we are revoking the certificate the users are stil able to login.&lt;/P&gt;
&lt;P&gt;We have gone to the internal ca and revoked the certificate but the device is still authenticating and getting on-board.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 12:11:02 GMT</pubDate>
    <dc:creator>saxenanitesh8522</dc:creator>
    <dc:date>2022-11-02T12:11:02Z</dc:date>
    <item>
      <title>Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543839#M537627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it posible to remove endpoint certificates generated by ISE internal CA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 00:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543839#M537627</guid>
      <dc:creator>Eric Pineda</dc:creator>
      <dc:date>2016-09-08T00:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543840#M537633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can revoke an endpoint cert by going to &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Certificates&lt;/STRONG&gt;, choose &lt;STRONG&gt;Endpoint Certificates&lt;/STRONG&gt; from the &lt;STRONG&gt;Left Menu&lt;/STRONG&gt;.&amp;nbsp; Select the cert you would like to revoke and click the &lt;STRONG&gt;X Revoke&lt;/STRONG&gt; button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="endpointCert.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/100066_endpointCert.PNG" style="height: 160px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot is from ISE 2.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 13:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543840#M537633</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-09-08T13:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543841#M537640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can revoke but not remove (delete)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 13:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543841#M537640</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-09-08T13:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543842#M537646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Endpoint certificates will be removed 30 days after its expiry automatically. Revoked certificates will also be removed 30 days after expiry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 14:34:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543842#M537646</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-09-08T14:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543843#M537649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the responses!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 17:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3543843#M537649</guid>
      <dc:creator>Eric Pineda</dc:creator>
      <dc:date>2016-09-08T17:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3759424#M537654</link>
      <description>&lt;P style="padding-left: 30px;"&gt;Hi howon,&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;How if the expired or revoke certificate to be retained or extend listed in endpoint certificate before automatically delete ?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 08:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/3759424#M537654</guid>
      <dc:creator>Looi Siew Key</dc:creator>
      <dc:date>2018-12-07T08:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4663108#M576529</link>
      <description>&lt;P&gt;so, what you saying if the certificate expire in 2 years, it will stay there for 2 years and 30 days before it is gone....WOW&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 16:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4663108#M576529</guid>
      <dc:creator>salprevitera</dc:creator>
      <dc:date>2022-08-03T16:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4714814#M578028</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;If we are revoking the certificate the users are stil able to login.&lt;/P&gt;
&lt;P&gt;We have gone to the internal ca and revoked the certificate but the device is still authenticating and getting on-board.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 12:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4714814#M578028</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2022-11-02T12:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remove endpoint certificate from ISE internal CA</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4715159#M578047</link>
      <description>&lt;P&gt;It sounds like ISE is not performing the revocation checks for some reason. I would suggest confirming the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verify that the internal CA/EST/OCSP responder is enabled in &lt;STRONG&gt;&lt;EM&gt;Admin &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Authority &amp;gt; Internal CA Settings&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify that the OCSP validation is enabled and using the internal OCSP responder for all of the internal CA chain certificates in &lt;STRONG&gt;&lt;EM&gt;Admin &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Management &amp;gt; Trusted Certificates&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If both of those are verified, you likely need to open a TAC case to investigate further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 21:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-endpoint-certificate-from-ise-internal-ca/m-p/4715159#M578047</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-11-02T21:34:15Z</dc:date>
    </item>
  </channel>
</rss>

