<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Renew Default self-signed server certificate Cisco ISE 2.7 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248939#M594286</link>
    <description>&lt;P&gt;Yes you can renew that self-signed certificate by leveraging the "Renewal Period" feature. When you enable that tick box then you will have to define the period in which the certificate should be renewed before its expiry date.&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jan 2025 12:33:52 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2025-01-18T12:33:52Z</dc:date>
    <item>
      <title>Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248828#M594283</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Our Default self-signed server certificates are about to expire, so I need to know if is possible to renew them manually editing them on this way without breaking the cluster.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victormanuelsolis_0-1737156720835.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237832i953D37BD5CEC65D6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victormanuelsolis_0-1737156720835.png" alt="victormanuelsolis_0-1737156720835.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Certificate to renew:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victormanuelsolis_1-1737156844960.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237833i15C09D2B46FDE132/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victormanuelsolis_1-1737156844960.png" alt="victormanuelsolis_1-1737156844960.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Deployment, 1 prim admin, 1 prim monitoring&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victormanuelsolis_2-1737156934508.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237834i457408A88D83C9C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victormanuelsolis_2-1737156934508.png" alt="victormanuelsolis_2-1737156934508.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ISE version 2.7&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 23:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248828#M594283</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2025-01-17T23:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248903#M594284</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-implement-digital-certificates-in-ise/ta-p/3630897&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 07:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248903#M594284</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-01-18T07:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248923#M594285</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/575098"&gt;@iVicMMac&lt;/a&gt; refer to the ISE certificate renewal guide already provided. Bear in mind when you replace the "admin" certificate the ISE services will restart. Ideally you should use your internal CA to sign the certificates. &lt;/P&gt;
&lt;P&gt;FYI, ISE 2.7 is End of Life and End of Support, you should look to upgrade asap. ISE 3.3 patch 4 is the current Cisco recommended version.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 10:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248923#M594285</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-18T10:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248939#M594286</link>
      <description>&lt;P&gt;Yes you can renew that self-signed certificate by leveraging the "Renewal Period" feature. When you enable that tick box then you will have to define the period in which the certificate should be renewed before its expiry date.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 12:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5248939#M594286</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-18T12:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5249245#M594296</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/575098"&gt;@iVicMMac&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-queue-link-error/ta-p/4625179" target="_blank" rel="noopener"&gt;ISE - Queue Link Error&lt;/A&gt;, search for&amp;nbsp;&lt;STRONG&gt;Generate Signing Requests (CSR)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 17:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5249245#M594296</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-19T17:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252261#M594464</link>
      <description>&lt;P&gt;Thank for your answer, should I renew first the primary or secondary? take in count that we have different certificates for each box&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 16:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252261#M594464</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2025-01-24T16:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252569#M594483</link>
      <description>&lt;P&gt;You're welcome. Why different certificates? both nodes are in the same deployment right? when you configure the option to renew the self-signed certs it would configured from the primary PAN and it would apply to the deployment not the individual nodes. So, when you do it from there you should be good to go with both nodes.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 12:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252569#M594483</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-25T12:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252581#M594484</link>
      <description>&lt;P&gt;thanks, I don't know why we have 2 different certificates, I received these boxes in this way, however I'll start with the renewal of the primary admin and hope it apply it to the secondary&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 13:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252581#M594484</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2025-01-25T13:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252637#M594487</link>
      <description>&lt;P&gt;Actually because they are self-signed certs it would make sense to have them different because each node would have generated its own certificate, but anyway, changing the renewal config would apply to both and you should be good with both of them.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 15:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5252637#M594487</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-25T15:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5253255#M594535</link>
      <description>&lt;P&gt;Just FYI,&lt;/P&gt;
&lt;P&gt;Certificates renewed from the primary admin node and it replicated to the secondary, only 5 minutes of downtime due the restart of ISE application for both boxes. Duration for the renewed certificates: 10 years&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 15:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5253255#M594535</guid>
      <dc:creator>iVicMMac</dc:creator>
      <dc:date>2025-01-27T15:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Renew Default self-signed server certificate Cisco ISE 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5253591#M594569</link>
      <description>&lt;P&gt;Thanks for sharing the outcome and glad to hear it worked as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/renew-default-self-signed-server-certificate-cisco-ise-2-7/m-p/5253591#M594569</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-28T09:12:00Z</dc:date>
    </item>
  </channel>
</rss>

