02-23-2015 11:07 PM - edited 03-10-2019 10:29 PM
Hi board,
maybe I'm asking a rather dumb question here, but anyway :)
I'm currently thinking about how to renew an admin/EAP certificate on an ISE node and the effect on the endpoint authentication.
Here's the thing I do, when I initially install an ISE node
1.) CSR creation on ISE (PAN) - CN=$FQDN$ and SAN="fqdn as well"
2.) Sign CSR and bind certificate on ISE node - done
Now after 10 month or so (if the certificate is valid for one year) I want to renew the ISE admin/EAP certificate.
CSR creation: I cannot use the $FQDN$ as the CN, because there is still the current certificate (CN must be unique in the store, right?)
So what to do now? Do I really need to create a temporary SSC and make it the admin/EAP certificate, delete the current certificate and then create a new CSR? There must be a better and more important non-disruptive way of doing this.
How do you guys do this in your deployments?
Thanks in advance and sorry again if this is a silly question.
Johannes
Solved! Go to Solution.
02-24-2015 12:43 AM
you can install a new certificate on the ISE before it is active, Cisco recommends that you install the new certificate before the old certificate expires. This overlap period between the old certificate expiration date and the new certificate start date gives you time to renew certificates and plan their installation with little or no downtime. Once the new certificate enters its valid date range, enable the EAP and/or HTTPS protocol. Remember, if you enable HTTPS, there will be a service restart
02-24-2015 12:43 AM
you can install a new certificate on the ISE before it is active, Cisco recommends that you install the new certificate before the old certificate expires. This overlap period between the old certificate expiration date and the new certificate start date gives you time to renew certificates and plan their installation with little or no downtime. Once the new certificate enters its valid date range, enable the EAP and/or HTTPS protocol. Remember, if you enable HTTPS, there will be a service restart
02-24-2015 07:41 AM
Thanks for that! I did something wrong or something weird happended during the CSR generation on the ISE. Of course I can create a new CSR with the same subject as an existing certificate.
Sorry about that...
03-31-2015 01:27 PM
Why do you need SAN="fqdn as well"?
Is there a condition where Subject CN match is not enough?
08-20-2018 06:58 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide