02-03-2025 04:09 PM
Hello,
We did receive the following alert:
Queue Link Error: Message=From ISE-Node1 to ISE-Node2-ISE-1.mskcc.org; Cause={tls_alert;{unknown_ca;"tls Client:
In State Certify At Ssl_handshake.erl:1887 Generated Client Alert: Fatal - Unknown Ca\n"}
What has been checked so far:
1) Service: Running at both nodes
ISE Messaging Service running 20704
2) Port is open at both nodes: show ports
tcp: 0.0.0.0:15672, 0.0.0.0:8671, 0.0.0.0:8672
3) Cert validity check
Jun 16 2022 - Jun 17 2027
Jun 24 2024 - Jun 25 2029
Version:
Cisco Identity Services Engine
---------------------------------------------
Version : 3.1.0.518
Build Date : Mon Aug 9 16:28:55 2021
Install Date : Fri Jun 17 07:29:59 2022
Cisco Identity Services Engine Patch
---------------------------------------------
Version : 3
Install Date : Fri Jun 17 08:13:40 2022
Any advice is much appreciated.
Solved! Go to Solution.
02-04-2025 04:25 AM
The error you are getting is stating "Unknown CA" which requires regenerating ISE root and ISE messaging service certificates as per the link shared by @marce1000. In addition to the above link please check this video at minute 5:41:
02-04-2025 12:34 AM
- FYI : https://community.cisco.com/t5/security-knowledge-base/ise-queue-link-error/ta-p/4625179
M.
02-04-2025 04:14 AM
02-04-2025 04:25 AM
The error you are getting is stating "Unknown CA" which requires regenerating ISE root and ISE messaging service certificates as per the link shared by @marce1000. In addition to the above link please check this video at minute 5:41:
02-13-2025 10:25 AM
Thank you Aref.
This video worked for me: regenerating ISE root and ISE messaging service certificates fixed the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide