<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CISCO ISE error adding third node to deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555208#M600491</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to add a third node to ISE deployment. When i go to PAN to register new node. I introduce FQDN, user, pass but i receive this error:&amp;nbsp;Certificate Signature Verification failed CN= Company1 CAROOT, DC=Company1, DC=com: FQDN&lt;/P&gt;&lt;P&gt;I verified that the CAROOT and CA intermediate are in PAN and new node. How can i fix the issue? any idea?&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2026 07:15:32 GMT</pubDate>
    <dc:creator>SupportAC</dc:creator>
    <dc:date>2026-05-27T07:15:32Z</dc:date>
    <item>
      <title>CISCO ISE error adding third node to deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555208#M600491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to add a third node to ISE deployment. When i go to PAN to register new node. I introduce FQDN, user, pass but i receive this error:&amp;nbsp;Certificate Signature Verification failed CN= Company1 CAROOT, DC=Company1, DC=com: FQDN&lt;/P&gt;&lt;P&gt;I verified that the CAROOT and CA intermediate are in PAN and new node. How can i fix the issue? any idea?&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 07:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555208#M600491</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2026-05-27T07:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE error adding third node to deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555352#M600492</link>
      <description>&lt;P&gt;Is the CAROOT certificate in the trusted certificate store on the current PAN? Double check that the certificate SHA-256 fingerprint matches.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 13:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555352#M600492</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-05-27T13:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE error adding third node to deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555372#M600493</link>
      <description>&lt;P&gt;Yes. I have all chain CAroot and intermediate in PAN,SAN and new node.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The different thing is that the certificates for the PAN and SAN nodes were signed by a different Root CA and using SHA1 (these devices were installed many years ago). The new ISE, however, was signed by another CA using SHA256. Even so, I imported the certificate along with the Root and Intermediate CAs used by the certificates on the previous nodes. I’m not sure whether this could be the issue.&lt;/P&gt;&lt;P&gt;I’m worried that I may need to regenerate the CSR and reissue/sign the certificates for the other two nodes (PAN and SAN) using the same Root CA (SHA-256) as the new node. I don’t like this option because it requires a reboot and deleting/replacing the certificate, which would cause service impact&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 13:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555372#M600493</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2026-05-27T13:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ISE error adding third node to deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555380#M600494</link>
      <description>&lt;P&gt;From what you have described, it sound like buggy behavior. I would open a TAC case for a more detailed investigation (and hopefully resolution).&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 14:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-adding-third-node-to-deployment/m-p/5555380#M600494</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-05-27T14:31:45Z</dc:date>
    </item>
  </channel>
</rss>

