<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Renew Self Signed Certificate on ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123104#M589783</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need help renewing a self-signed certificate on a customer's ise.&amp;nbsp;They have a self-signed certificate that is used for admin and EAP authentication, and I've been seeing that there's a Renewal Period option for these types of certificates.&amp;nbsp;My question is if I update this certificate with that option, will all clients who have that certificate also be updated? Or do I need to upgrade by GPO or one by one.&lt;BR /&gt;&lt;BR /&gt;I was looking at changing that certificate to one signed by an external CA like DigiCert, but I'm not sure if this avoids the problem of propagating the certificate.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 04:17:34 GMT</pubDate>
    <dc:creator>NaujEl</dc:creator>
    <dc:date>2024-06-03T04:17:34Z</dc:date>
    <item>
      <title>Renew Self Signed Certificate on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123104#M589783</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need help renewing a self-signed certificate on a customer's ise.&amp;nbsp;They have a self-signed certificate that is used for admin and EAP authentication, and I've been seeing that there's a Renewal Period option for these types of certificates.&amp;nbsp;My question is if I update this certificate with that option, will all clients who have that certificate also be updated? Or do I need to upgrade by GPO or one by one.&lt;BR /&gt;&lt;BR /&gt;I was looking at changing that certificate to one signed by an external CA like DigiCert, but I'm not sure if this avoids the problem of propagating the certificate.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 04:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123104#M589783</guid>
      <dc:creator>NaujEl</dc:creator>
      <dc:date>2024-06-03T04:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Self Signed Certificate on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123151#M589787</link>
      <description>&lt;LI-CODE lang="markup"&gt;do I need to upgrade by GPO or one by one.&lt;/LI-CODE&gt;
&lt;P&gt;If the same CA and clients know about that root CA that should be ok, if you are using new CA then Client should trust that cert also. (so you need to push this certs to client to trust using GPO or any other method) - ISE do not push certs to clients as per i kn0w).&lt;/P&gt;
&lt;P&gt;for EAP if the certificate server is new you need to push all the clients before you update on ISE so client can trust that cert.&lt;/P&gt;
&lt;P&gt;Sure you can use Public Certs, so client do not need to have CA certs on client, since client know publics CA already know.&lt;/P&gt;
&lt;P&gt;check this if you looking to public or own PKI :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/using-let-s-encrypt-certificates-with-cisco-ise/ta-p/5090885" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/using-let-s-encrypt-certificates-with-cisco-ise/ta-p/5090885&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you have more PSN - you can do testing one PSN at a time binding the certs.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 06:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123151#M589787</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-06-03T06:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Self Signed Certificate on ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123166#M589788</link>
      <description>&lt;P&gt;Renewing an ISE self-signed cert does very little to the cert - it changes only the valid from and valid to dates, and then the signature hash is regenerated. Serial number of the cert remains the same.&amp;nbsp; End clients would not know the difference between old and new.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 07:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-self-signed-certificate-on-ise/m-p/5123166#M589788</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-03T07:01:22Z</dc:date>
    </item>
  </channel>
</rss>

