<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CISCO ISE Export local certificate Import ERROR in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501175#M90254</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up a two node deployment and I have exported the local certificate and private key from the primary node and have tried to import it on the secondary node but I get the following error popping up " Key pair import failed: mismatched &amp;nbsp;private &amp;nbsp;key". I have made sure the key password is correct but still no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the current set-up is ;&lt;/P&gt;&lt;P&gt;- sercodnary node has been connected to the primary node&lt;/P&gt;&lt;P&gt;- AD integration has occurred&amp;nbsp;&lt;/P&gt;&lt;P&gt;- the root cert has been imported in the certificate store for the certificate that is trying to be loaded.&lt;/P&gt;&lt;P&gt;Cisco ISE platform: 3415 server&lt;/P&gt;&lt;P&gt;Cisco ISE version: 1.2 latest build&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:45:37 GMT</pubDate>
    <dc:creator>johnattard</dc:creator>
    <dc:date>2019-03-11T04:45:37Z</dc:date>
    <item>
      <title>CISCO ISE Export local certificate Import ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501175#M90254</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up a two node deployment and I have exported the local certificate and private key from the primary node and have tried to import it on the secondary node but I get the following error popping up " Key pair import failed: mismatched &amp;nbsp;private &amp;nbsp;key". I have made sure the key password is correct but still no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the current set-up is ;&lt;/P&gt;&lt;P&gt;- sercodnary node has been connected to the primary node&lt;/P&gt;&lt;P&gt;- AD integration has occurred&amp;nbsp;&lt;/P&gt;&lt;P&gt;- the root cert has been imported in the certificate store for the certificate that is trying to be loaded.&lt;/P&gt;&lt;P&gt;Cisco ISE platform: 3415 server&lt;/P&gt;&lt;P&gt;Cisco ISE version: 1.2 latest build&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501175#M90254</guid>
      <dc:creator>johnattard</dc:creator>
      <dc:date>2019-03-11T04:45:37Z</dc:date>
    </item>
    <item>
      <title>refer this discussionhttps:/</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501176#M90255</link>
      <description>&lt;P&gt;refer this discussion&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/11722981/ise-certificate-and-mismatched-private-key&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 07:25:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501176#M90255</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-06-03T07:25:51Z</dc:date>
    </item>
    <item>
      <title>Hi SalodhThanks for the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501177#M90257</link>
      <description>&lt;P&gt;Hi Salodh&lt;/P&gt;&lt;P&gt;Thanks for the reference, I took the link into consideration and then I tried a different work around and I believe I have an answer to what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the certificate is exported by ISE it also includes the signing CA certificate (either root and/or int), the output of the PEM files puts the certificate in the wrong order and when it tries to match the private key it matches it to the CA or intermediate certificate and not the host certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my case when I exported the certificate from ISE ndoe 1, it produced a pem file with two certificates. I just swaped the order of the certificates in the pem file and it worked straight away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 03:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-export-local-certificate-import-error/m-p/2501177#M90257</guid>
      <dc:creator>johnattard</dc:creator>
      <dc:date>2014-06-04T03:11:17Z</dc:date>
    </item>
  </channel>
</rss>

