<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 3.0 upgrade 3.2: backup ISE certificate authority / issued certs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-0-upgrade-3-2-backup-ise-certificate-authority-issued/m-p/5034232#M587919</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;We have a HA deployment, ISE are self signed and we have issued about 40 certs for devices.&lt;/P&gt;
&lt;P&gt;See the screenshot.&lt;/P&gt;
&lt;P&gt;What is the best way to upgrade to avoid to reinstall the certs on the devices.&lt;/P&gt;
&lt;P&gt;If I use the CLI "application configure ise":&lt;/P&gt;
&lt;P&gt;S2-AB-SEISE-011-001/admin# application configure ise&lt;/P&gt;
&lt;P&gt;Selection configuration option&lt;BR /&gt;[1]Reset M&amp;amp;T Session Database&lt;BR /&gt;[2]Rebuild M&amp;amp;T Unusable Indexes&lt;BR /&gt;[3]Purge M&amp;amp;T Operational Data&lt;BR /&gt;[4]Reset M&amp;amp;T Database&lt;BR /&gt;[5]Refresh Database Statistics&lt;BR /&gt;[6]Display Profiler Statistics&lt;BR /&gt;[7]Export Internal CA Store&lt;BR /&gt;[8]Import Internal CA Store&lt;/P&gt;
&lt;P&gt;Will it work with&amp;nbsp;[7]Export Internal CA Store ?&lt;/P&gt;
&lt;P&gt;Is it mandatory to export the System Cert by GUI ?&lt;/P&gt;
&lt;P&gt;Or on the new 3.2, can we use a fresh install of system certifcates and import the Internal CA Store ?&lt;/P&gt;
&lt;P&gt;Thanks a lot,&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE CA Cert.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211782i1722D4390D428076/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE CA Cert.png" alt="ISE CA Cert.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE issued certs.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211783i71EFD1C6E0322856/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE issued certs.png" alt="ISE issued certs.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 10:25:24 GMT</pubDate>
    <dc:creator>GERALD LECAILLIER</dc:creator>
    <dc:date>2024-03-05T10:25:24Z</dc:date>
    <item>
      <title>ISE 3.0 upgrade 3.2: backup ISE certificate authority / issued certs</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-upgrade-3-2-backup-ise-certificate-authority-issued/m-p/5034232#M587919</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;We have a HA deployment, ISE are self signed and we have issued about 40 certs for devices.&lt;/P&gt;
&lt;P&gt;See the screenshot.&lt;/P&gt;
&lt;P&gt;What is the best way to upgrade to avoid to reinstall the certs on the devices.&lt;/P&gt;
&lt;P&gt;If I use the CLI "application configure ise":&lt;/P&gt;
&lt;P&gt;S2-AB-SEISE-011-001/admin# application configure ise&lt;/P&gt;
&lt;P&gt;Selection configuration option&lt;BR /&gt;[1]Reset M&amp;amp;T Session Database&lt;BR /&gt;[2]Rebuild M&amp;amp;T Unusable Indexes&lt;BR /&gt;[3]Purge M&amp;amp;T Operational Data&lt;BR /&gt;[4]Reset M&amp;amp;T Database&lt;BR /&gt;[5]Refresh Database Statistics&lt;BR /&gt;[6]Display Profiler Statistics&lt;BR /&gt;[7]Export Internal CA Store&lt;BR /&gt;[8]Import Internal CA Store&lt;/P&gt;
&lt;P&gt;Will it work with&amp;nbsp;[7]Export Internal CA Store ?&lt;/P&gt;
&lt;P&gt;Is it mandatory to export the System Cert by GUI ?&lt;/P&gt;
&lt;P&gt;Or on the new 3.2, can we use a fresh install of system certifcates and import the Internal CA Store ?&lt;/P&gt;
&lt;P&gt;Thanks a lot,&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE CA Cert.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211782i1722D4390D428076/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE CA Cert.png" alt="ISE CA Cert.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE issued certs.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211783i71EFD1C6E0322856/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE issued certs.png" alt="ISE issued certs.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 10:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-upgrade-3-2-backup-ise-certificate-authority-issued/m-p/5034232#M587919</guid>
      <dc:creator>GERALD LECAILLIER</dc:creator>
      <dc:date>2024-03-05T10:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 upgrade 3.2: backup ISE certificate authority / issued cer</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-upgrade-3-2-backup-ise-certificate-authority-issued/m-p/5036239#M587972</link>
      <description>&lt;P&gt;Very good question and one that deserves an answer by someone who has done this - or tested in the lab. I currently don't have a lab to test the Internal CA export / import. But if the end result of your importing your exported CA into a clean ISE 3.2 node, then your internal CA should look the same as your screenshot. In other words, the importing of the CA database will ADD the original Root, Node, Endpoint and OCSP certs. I think the factory ISE 3.2 installed certs will remain in place, but will not be the active ones.&lt;/P&gt;
&lt;P&gt;As for the PSN EAP System Cert, that you must export via the GUI (export the private key too) - and then import that cert+key into your new ISE 3.2 PSN responsible for the EAP role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 01:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-upgrade-3-2-backup-ise-certificate-authority-issued/m-p/5036239#M587972</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-03-08T01:35:40Z</dc:date>
    </item>
  </channel>
</rss>

