<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE OCSP Responder Certificate expiring in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4779615#M579954</link>
    <description>&lt;P&gt;Did they eventually renew? I also did the same and it's been a while not sure how long we are supposed to wait&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 13:29:54 GMT</pubDate>
    <dc:creator>ivan_abibe</dc:creator>
    <dc:date>2023-02-21T13:29:54Z</dc:date>
    <item>
      <title>ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4427030#M568268</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a couple of OCSP responder certificates expiring after 60 days. When I check the 'Issued by' column it has the name of one of the other node on it, which is the PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am at a loss about how do I go further to renew it. There seems to be no basic documentation to cover this, but I am sure it is quite simple.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I go about renewing it?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Friendly Name Status Trusted For Issued To Issued By Valid From Expiration Date&lt;BR /&gt;Certificate Services OCSP Responder - ISE01#00016 Enabled Endpoints,Infrastructure Certificate Services OCSP Responder - ISE01 Certificate Services Root CA - ISE02 Sun, 25 Sep 2016 Sun, 26 Sep 2021&lt;BR /&gt;Certificate Services Endpoint Sub CA - ISE01#00017 Enabled Infrastructure,Endpoints Certificate Services Endpoint Sub CA - ISE01 Certificate Services Root CA - ISE02 Sun, 25 Sep 2016 Sun, 26 Sep 2021&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 02:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4427030#M568268</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2021-07-02T02:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4427824#M568292</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/264736"&gt;@colossus1611&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's kind of hidden&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="renew.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/124383iF3553049B908A36A/image-size/large?v=v2&amp;amp;px=999" role="button" title="renew.png" alt="renew.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 21:53:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4427824#M568292</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-07-04T21:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433464#M568471</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you! I didn't notice your response and was wondering how to go about this. So basically this will renew it same as self-signed certificates it seems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will give it a go sometime today. Correct me if I am wrong but I think business hours should be fine as it shouldn't cause any disruption by the look of it.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 01:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433464#M568471</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2021-07-15T01:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433475#M568472</link>
      <description>&lt;P&gt;It won't cause any outage - the cert's private key is retained, and all that happens is that the new cert has a new start and end date and a new signature (hash). Serial number should also remain as is, as far as I know.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;**Correction: The Serial number is different - this implies that the certificate is actually regenerated. But it's pretty quick - should be done in less than a minute.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 04:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433475#M568472</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-07-15T04:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433486#M568473</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again. I did go through the renewal process which seems to be just a single click with no selection of nodes required. It's been about an hour now and the certificates are still displaying an old expiry date, though it did suggest it may take some time at time of renewal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting that it did not ask for a node name at all and yet all the nodes currently have a different OCSP expiry date.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might have to do this again - don't think the renewal will kick in now, given that it has already been more than an hour of wait.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 03:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4433486#M568473</guid>
      <dc:creator>colossus1611</dc:creator>
      <dc:date>2021-07-15T03:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4779615#M579954</link>
      <description>&lt;P&gt;Did they eventually renew? I also did the same and it's been a while not sure how long we are supposed to wait&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 13:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/4779615#M579954</guid>
      <dc:creator>ivan_abibe</dc:creator>
      <dc:date>2023-02-21T13:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5339098#M598561</link>
      <description>&lt;P&gt;Did this work for any of you?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 10:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5339098#M598561</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2025-10-16T10:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5345036#M598839</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;I have done this several times and it has not worked.&lt;/P&gt;&lt;P&gt;The OSCP responder certificate that has expired is in Admin&amp;gt;Certificates&amp;gt;Certificate Authority&amp;gt;Certificate Authority Certificates.&lt;BR /&gt;&lt;BR /&gt;Does this matter?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 14:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5345036#M598839</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2025-11-06T14:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5345141#M598841</link>
      <description>&lt;P&gt;It can take a little while to display the new OCSP cert - and also, you might not see it immediately, because ISE doesn't delete the old one - keep scrolling to the end and keep an eye on the "#" number - in the past, I have had to manually delete the expired certs in the correct order (reverse order of creation - so, OCSPs first, then Endpoint Sub CAs, then Node CAs and lastly, the Root (there is only one))&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 20:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5345141#M598841</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-11-06T20:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5543824#M600196</link>
      <description>&lt;P&gt;Bumping for the same reason.&amp;nbsp; I went through this process a few weeks ago, and I still have the expired certs showing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 20:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5543824#M600196</guid>
      <dc:creator>MichaelMcCoyOU</dc:creator>
      <dc:date>2026-04-07T20:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE OCSP Responder Certificate expiring</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5543828#M600197</link>
      <description>&lt;P&gt;I eventually opened a TAC case and they were able to help me to get it deleted.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 21:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ocsp-responder-certificate-expiring/m-p/5543828#M600197</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2026-04-07T21:13:18Z</dc:date>
    </item>
  </channel>
</rss>

