01-28-2023 11:53 AM
We are trying to integrate our Cisco DNA center deployment with ISE and are seeing an error that is stating a CA chain is broken. The error is referring to the chain being broken for issuer "CN=Certificate Services Root CA" this is under "certificate authority certificates". How can we renew this cert so that the chain is no longer broken so that we can get past this error? Do we need to renew the chain for the ISE internal root cert? Any info is appreciated.
Solved! Go to Solution.
02-01-2023 09:15 AM
After re-generating the ISE internal root ca and then messaging cert we were able to get DNAC integrated. Make sure the "use DNA center certificate" in DNAC integration settings is unchecked.
01-28-2023 12:46 PM
You need to provide more information :
DNAC Version ?
ISE Version ?
is this Local Certs of Public Certs ?
Integration guide :
check some thread helpful :
01-29-2023 03:48 PM
Hey @Ciscorocks ,
Just out of interest, in your ISE deployment, do you see ongoing "Queue Link" Alarms ? If so, then the solution is to regenerate the ISE Internal CA. This is quick an easy and does not cause disruption. Of course, if you're using the internal ISE CA then please don't do this - you'll need to make a more comprehensive solution to ensure you don't break your client connectivity.
cheers
01-31-2023 07:46 PM
@Ciscorocks Arne is correct that you would need check whether Cisco internal CA service also used for client authentications. In case it's not used for that, then you may follow the Queue-Link Alarm subsection of
02-01-2023 09:15 AM
After re-generating the ISE internal root ca and then messaging cert we were able to get DNAC integrated. Make sure the "use DNA center certificate" in DNAC integration settings is unchecked.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide