<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3.1 patch 3 backup failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725263#M578409</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Can you be specific about which line(s) in the /etc/ssh/ssh_config files?&amp;nbsp; Are you referring to these lines below:&lt;/P&gt;&lt;P&gt;# IdentityFile ~/.ssh/identity&lt;BR /&gt;# IdentityFile ~/.ssh/id_rsa&lt;BR /&gt;# IdentityFile ~/.ssh/id_dsa&lt;/P&gt;&lt;P&gt;I checked the /etc/ssh/ssh_config on in the CentOS 7.x and that's what I saw and the CentOS 7.x could ssh into the Ubuntu 22.0.4 LTS without any issues and yet the ISE 3.1 could not.&amp;nbsp; Therefore, I assume these lines are not the main culprit.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2022 13:39:51 GMT</pubDate>
    <dc:creator>adamscottmaster2013</dc:creator>
    <dc:date>2022-11-21T13:39:51Z</dc:date>
    <item>
      <title>ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4723390#M578319</link>
      <description>&lt;P&gt;I have a schedule job to back up the ISE configuration everyday to an external sFTP server, running on Ubuntu server 20.04.5 LTS and it has been working for the past two years.&lt;/P&gt;&lt;P&gt;Yesterday, I upgraded my Ubuntu server to 22.04.1 LTS and after that backup stopped working because the Ubuntu no longer accept the ssh-rsa host key from the ISE server.&amp;nbsp; This is what I see on the Ubuntu server log:&lt;/P&gt;&lt;P&gt;Nov 17 15:40:14 Ubuntu_22_04_1 sshd[145827]: Unable to negotiate with 192.168.1.1 port 17310: no matching host key type found. Their offer: ssh-rsa [preauth]&lt;/P&gt;&lt;P&gt;This is what I see on the ISE:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssh 192.168.1.2 adamscott version 2&lt;BR /&gt;Operating in CiscoSSL FIPS mode&lt;BR /&gt;FIPS mode initialized&lt;BR /&gt;Unable to negotiate with 192.168.1.2 port 22: no matching host key type found. Their offer: rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519&lt;/P&gt;&lt;P&gt;In other words, my ubuntu version 22.0.4.1 does not allow ssh-rsa from the ISE.&amp;nbsp; This option is no longer available in Ubuntu due to security risk.&amp;nbsp; At the same time, there is no option on the Cisco ISE to use the host key type that is acceptable to Ubuntu.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you work around this problem?&amp;nbsp; Cisco ISE is running on CentOS 7.x so I assume that stronger host key type is definitely support.&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 18:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4723390#M578319</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-17T18:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724422#M578381</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt; What you described appears addressed by the fix for &lt;SPAN&gt;CSCwa95889. The fix is to add rsa-sha2-512 and rsa-sha2-256 as HostKeyAlgorithms for SSH outbound from ISE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ISE 3.1 Patch 4 includes this fix. Please try it out.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 01:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724422#M578381</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-20T01:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724447#M578390</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Any fix ISE version 3.0?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 03:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724447#M578390</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-20T03:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724532#M578395</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt; For ISE 3.0, the fix is coming in Patch 7 but that is months away. If you need it sooner, either open a TAC case to apply the workaround via root access or to request for a hot patch.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 13:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724532#M578395</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-20T13:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724694#M578397</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; After upgrading to 3.1 patch-4, backup via sFTP is working again.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 00:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724694#M578397</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-21T00:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724696#M578398</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Do you mind sharing the workaround?&amp;nbsp; Is it as easy as editing the /etc/ssh/ssh_config file on the ISE?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 00:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724696#M578398</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-21T00:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724697#M578399</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005" target="_blank"&gt;@hslai&lt;/A&gt;&lt;SPAN&gt;:&amp;nbsp; Do you mind sharing the workaround?&amp;nbsp; Is it as easy as editing the /etc/ssh/ssh_config file on the ISE?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 00:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4724697#M578399</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-21T00:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725200#M578404</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt; Yes, that is the main part. In case that the known_hosts file(s) not properly updated by "crypto host_key add host &amp;lt;&amp;gt;", manually add the missing entries.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 12:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725200#M578404</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-21T12:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725263#M578409</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Can you be specific about which line(s) in the /etc/ssh/ssh_config files?&amp;nbsp; Are you referring to these lines below:&lt;/P&gt;&lt;P&gt;# IdentityFile ~/.ssh/identity&lt;BR /&gt;# IdentityFile ~/.ssh/id_rsa&lt;BR /&gt;# IdentityFile ~/.ssh/id_dsa&lt;/P&gt;&lt;P&gt;I checked the /etc/ssh/ssh_config on in the CentOS 7.x and that's what I saw and the CentOS 7.x could ssh into the Ubuntu 22.0.4 LTS without any issues and yet the ISE 3.1 could not.&amp;nbsp; Therefore, I assume these lines are not the main culprit.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 13:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725263#M578409</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-21T13:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725325#M578411</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;Sorry for not being clear. The workaround is for Cisco TAC to apply to the affected ISE instances. That is why you would need a TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 15:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725325#M578411</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-21T15:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725344#M578412</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Can you be specific on the workaround?&amp;nbsp; I am trying to understand what is being changed.&amp;nbsp; Be specific.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 16:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725344#M578412</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-11-21T16:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 patch 3 backup failure</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725518#M578413</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp; All the changes for the workaround are on ISE side and need root access.&lt;/P&gt;
&lt;P&gt;If you have no TAC case on this, please open one. If you have one, please ask TAC to contact me if you need additional details. I wrote the internal note for TAC but that was done before our engineering fixed it so that note need some updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 01:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-patch-3-backup-failure/m-p/4725518#M578413</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-22T01:28:30Z</dc:date>
    </item>
  </channel>
</rss>

