05-13-2019 01:31 PM
Hi,
Does anyone know if it is mandatory to change the DNAC self-signed certificate with one that us signed by an internal CA that contains the IP and FQDN in the SAN entry? I've read a number of setup guides and the requirement for this is not consistent.
Thanks
05-20-2019 07:30 PM
Hi ,If CA signed,Both ISE & DNA-C certificate should be signed by same CA.Also please share the DNA-C and ISE version.
05-21-2019 09:08 AM
Hi Wills,
Cisco DNA Center uses a number of certificates, such as the certificates generated by Kubernetes and the certificate used by the Kong and Credential Manager services. These certificates are issued with a validity of one year. They expire a year after the cluster is installed.
In Cisco DNA Center 1.2.8 and later versions, these certificates are automatically renewed for another year before they are about to expire. The user need NOT take any manual action on these Cisco DNA Center versions. Users using these versions of Cisco DNA can skip this article.
In Cisco DNA Center 1.2.7 and previous versions, these certificates must be manually renewed by the user. It is recommended to renew the certificates before they expire.
Please contact sac-support@cisco.com for any further queries.
Hope this helps!
Regards,
Vibha Jha
Cisco Sales Acceleration Center
sac-support@cisco.com
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide