<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Ivan,Here are the steps:To in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662306#M73973</link>
    <description>&lt;P&gt;Hi Ivan,&lt;/P&gt;&lt;P&gt;Here are the steps:&lt;/P&gt;&lt;P&gt;To replace the&amp;nbsp;certificate in both server it&amp;nbsp;is better to make each server a stand alone&lt;BR /&gt;unit. In other words breaking the cluster.&lt;/P&gt;&lt;P&gt;To break the cluster you can go under distributed deployment and select from primary&lt;BR /&gt;server your secondary unit and first you need to deregister and then you need to delete&lt;BR /&gt;it.&lt;/P&gt;&lt;P&gt;This will restart services in the secondary server and this may take around 5 minutes.&lt;/P&gt;&lt;P&gt;Once the server is back you can start the process in each server of requesting a new&lt;BR /&gt;certificate from VeriSign.&lt;/P&gt;&lt;P&gt;To do so:&lt;/P&gt;&lt;P&gt;Create a new certificate signing request in each server.&lt;/P&gt;&lt;P&gt;Export the CSR to your CA.&lt;/P&gt;&lt;P&gt;Install the new certificate receive from your CA under local certificates (here select&lt;BR /&gt;that you want to use this certificate for EAP authentication)&lt;/P&gt;&lt;P&gt;Delete the old certificate use for EAP once you are sure that EAP is working fine for&lt;BR /&gt;your clients with the new certificate.&lt;/P&gt;&lt;P&gt;Join both servers as primary/secondary unit under the distributed deployment section&lt;BR /&gt;for your secondary unit.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Mar 2015 01:43:52 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2015-03-19T01:43:52Z</dc:date>
    <item>
      <title>acs in ha with certificate eap expired</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662303#M73970</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi my name is Ivan, I have a question:&lt;/P&gt;&lt;P&gt;I have two cisco acs version 5.4 servers in HA primary and replica 802.1x providing services for users and computers, integrated corporate Active Directory. servers have a certificate to authenticate users and comptadoras by PEAP MSCHPv2. This certificate installed on the acs server has expired. The certificate is obtained by performing the request from the acs server and download it with a CA microsoft server.&lt;BR /&gt;As I can do to re-install the certificate, since the units are in HA, 802.1x and provide the services again?&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Ivan.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662303#M73970</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2019-03-11T05:33:41Z</dc:date>
    </item>
    <item>
      <title>Hi Ivan,I didn't understand</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662304#M73971</link>
      <description>&lt;P&gt;Hi Ivan,&lt;/P&gt;&lt;P&gt;I didn't understand the question? Are you looking for a way to import the new certificates? If yes, then go to System Administration------&amp;gt; Local server certificates---&amp;gt;Local certificates----&amp;gt;and do import server certificate or Bind CA signed certificate. Select the replace certificate option and that is all you need to do. Bind it with EAP and Management interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or you are looking for something else?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 22:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662304#M73971</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-18T22:19:46Z</dc:date>
    </item>
    <item>
      <title>Hi, Thanks for your answerI</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662305#M73972</link>
      <description>&lt;P&gt;Hi, Thanks for your answer&lt;/P&gt;&lt;P&gt;I need to reinstall the certificates because both have expired. But the first thing to I need to do is generate the request.&lt;/P&gt;&lt;P&gt;My question is if exist some steps to do it when i have a deployment in HA primary and replica.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 00:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662305#M73972</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2015-03-19T00:10:16Z</dc:date>
    </item>
    <item>
      <title>Hi Ivan,Here are the steps:To</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662306#M73973</link>
      <description>&lt;P&gt;Hi Ivan,&lt;/P&gt;&lt;P&gt;Here are the steps:&lt;/P&gt;&lt;P&gt;To replace the&amp;nbsp;certificate in both server it&amp;nbsp;is better to make each server a stand alone&lt;BR /&gt;unit. In other words breaking the cluster.&lt;/P&gt;&lt;P&gt;To break the cluster you can go under distributed deployment and select from primary&lt;BR /&gt;server your secondary unit and first you need to deregister and then you need to delete&lt;BR /&gt;it.&lt;/P&gt;&lt;P&gt;This will restart services in the secondary server and this may take around 5 minutes.&lt;/P&gt;&lt;P&gt;Once the server is back you can start the process in each server of requesting a new&lt;BR /&gt;certificate from VeriSign.&lt;/P&gt;&lt;P&gt;To do so:&lt;/P&gt;&lt;P&gt;Create a new certificate signing request in each server.&lt;/P&gt;&lt;P&gt;Export the CSR to your CA.&lt;/P&gt;&lt;P&gt;Install the new certificate receive from your CA under local certificates (here select&lt;BR /&gt;that you want to use this certificate for EAP authentication)&lt;/P&gt;&lt;P&gt;Delete the old certificate use for EAP once you are sure that EAP is working fine for&lt;BR /&gt;your clients with the new certificate.&lt;/P&gt;&lt;P&gt;Join both servers as primary/secondary unit under the distributed deployment section&lt;BR /&gt;for your secondary unit.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 01:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662306#M73973</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-19T01:43:52Z</dc:date>
    </item>
    <item>
      <title>Hi FnuI have a last</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662307#M73974</link>
      <description>&lt;P&gt;Hi Fnu&lt;/P&gt;&lt;P&gt;I have a last question&lt;/P&gt;&lt;P&gt;Can I install the same certificate request from the unit primary into replica unit?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Ivan.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 03:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662307#M73974</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2015-03-19T03:25:49Z</dc:date>
    </item>
    <item>
      <title>Hi Ivan,All configuration is</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662308#M73975</link>
      <description>&lt;P&gt;Hi Ivan,&lt;/P&gt;&lt;P&gt;All configuration is same except licenses and local certificates. So they have to be separate.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 03:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-in-ha-with-certificate-eap-expired/m-p/2662308#M73975</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-03-19T03:29:37Z</dc:date>
    </item>
  </channel>
</rss>

