<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 3.1 certificate issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4832074#M581622</link>
    <description>&lt;P&gt;If you are on patch 5+, I believe the reboot should work. without 5 reboot did not fix the issue. The issue is with renewal, so could also maybe regenerate a completely new cert, but not sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suspect all nodes, but we just have a 2 node deployment, so can't verify that myself.&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 17:41:28 GMT</pubDate>
    <dc:creator>Dustin Anderson</dc:creator>
    <dc:date>2023-05-09T17:41:28Z</dc:date>
    <item>
      <title>ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737926#M578810</link>
      <description>&lt;P&gt;I do have a TAC open, but want to see if anyone has an idea while I'm waiting.&lt;/P&gt;&lt;P&gt;So, we use a public COMODO cert for our portals. I just got the renewed cert and went to install it last weekend. With the new cert, all portals load with:&lt;/P&gt;&lt;H1&gt;&lt;SPAN&gt;This site can’t provide a secure connection&lt;/SPAN&gt;&lt;/H1&gt;&lt;P&gt;&lt;STRONG&gt;ise-t.whatever.com&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;uses an unsupported protocol.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I thought maybe the cert, or key was incorrect, so I put the old cert back and the portals worked.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Monday, I spun up a test VM same as production of 3.1 patch 4. I started with the new cert and the portals worked, but then changing to the old cert caused the same error. But, changing back to the new did not correct it, so I'm guessing I got lucky in prod that the old cert took.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I'm currently downloading patch 5 to try on the test, but don't see any bugs related that it could be.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;My thoughts are it could be due to it being a renewal and they both use the same key. Testing this is a pain since it's a public cert and we would have to revoke and do a new CSR to test.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Any suggestions would be appreciated. I have about 10 days until my cert dies.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Dec 2022 15:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737926#M578810</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2022-12-13T15:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737969#M578811</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- What error do you get in Firefox ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737969#M578811</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-12-13T16:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737987#M578812</link>
      <description>&lt;P&gt;basically the same.&lt;/P&gt;&lt;P&gt;Error code: SSL_ERROR_NO_CYPHER_OVERLAP&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737987#M578812</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2022-12-13T16:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737999#M578813</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - FYI :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4737999#M578813</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-12-13T16:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738019#M578815</link>
      <description>&lt;P&gt;Thanks, that seems to be the bug. weird part is I tried rebooting yesterday and still had the issue, but seems to be working today. Only difference is I added patch 5 to the test node.&lt;/P&gt;&lt;P&gt;I'm going to restore it back to patch 4 and see if rebooting still works, will tell me if I have to also install patch 5 on my production before it works or not.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 18:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738019#M578815</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2022-12-13T18:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738063#M578816</link>
      <description>&lt;P&gt;ok, not crazy. On 3.1 patch 4, the reboot workaround does not work. Applying patch 5 and verifying that still works.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 19:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738063#M578816</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2022-12-13T19:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738070#M578817</link>
      <description>&lt;P&gt;Ok, patch 5 kicked in the new cert, so it appears to be the bug, with the caveat of needing patch 5 for the workaround to work. Will have to fix production this weekend.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 19:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4738070#M578817</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2022-12-13T19:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4745452#M578975</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - FYI :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc64480&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Pls confirm how I can download expired certificate from Cisco.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 07:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4745452#M578975</guid>
      <dc:creator>dubeyshivprakash09</dc:creator>
      <dc:date>2022-12-27T07:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4745453#M578976</link>
      <description>&lt;P&gt;Just want to download expired ccie security written exam certificate&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 07:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4745453#M578976</guid>
      <dc:creator>dubeyshivprakash09</dc:creator>
      <dc:date>2022-12-27T07:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4832064#M581620</link>
      <description>&lt;P&gt;Hey Dustin, we're currently hit with the bug but on the report is only mentions we need to "reload ISE server". Do you know if this is all of the nodes? Just the PSNs?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 17:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4832064#M581620</guid>
      <dc:creator>EU UC Support</dc:creator>
      <dc:date>2023-05-09T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4832074#M581622</link>
      <description>&lt;P&gt;If you are on patch 5+, I believe the reboot should work. without 5 reboot did not fix the issue. The issue is with renewal, so could also maybe regenerate a completely new cert, but not sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suspect all nodes, but we just have a 2 node deployment, so can't verify that myself.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 17:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4832074#M581622</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2023-05-09T17:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4846032#M582026</link>
      <description>&lt;P&gt;I had the same issue, moved portal certificate to another cert(admin/default), then deleted old and new portal certs.&lt;BR /&gt;Now reloaded PSN's and then PAN. Now, imported the new certificate back. Then it took the new certificate and is working fine.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 02:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/4846032#M582026</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2023-05-31T02:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/5139993#M590408</link>
      <description>&lt;P&gt;We had the same issue on ISE 3.2 Patch 4&lt;BR /&gt;&lt;BR /&gt;Followed the same procedure as Sri:&lt;BR /&gt;Moved guest portal certificate group to the default&lt;BR /&gt;deleted old (and new) portal certificates&lt;BR /&gt;reboot PSN1 (show application status to check functionality, all running &amp;gt;&amp;gt; OK), reboot PSN2&lt;BR /&gt;Upload new guest portal certificates with a new group&lt;BR /&gt;Link new cert group to guest portal&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 09:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/5139993#M590408</guid>
      <dc:creator>tomhoed</dc:creator>
      <dc:date>2024-07-04T09:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 certificate issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/5261907#M595049</link>
      <description>&lt;P&gt;Got same on ISE 3.2 patch 7. Will have to do it on maintenance window. How long, Cisco, you will be making buggy software?&lt;/P&gt;&lt;P&gt;Because instead of expanding your Department of Inclusivity or so, you'd better hire developers with proper skills.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 12:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-certificate-issue/m-p/5261907#M595049</guid>
      <dc:creator>voidray87</dc:creator>
      <dc:date>2025-02-18T12:58:57Z</dc:date>
    </item>
  </channel>
</rss>

